#I'm getting DDOSed.

32 messages · Page 1 of 1 (latest)

glad fern
#

?ddos

dreamy glacierBOT
glad fern
#

but they're already being mitigated?

#

not sure what kind of "ideas" you want

grand quest
#

These posts are a little outdated and I can't seem to find the things they're refrencing.

glad fern
#

and what kind of ideas do you want

grand quest
#

I really don't know. I'm new to this.

glad fern
#

it's all being blocked

#

you don't need to do anything

grand quest
#

Could you explain what that means? I mean, I see something that says "25.77M Total," what does "served by origin mean?"

#

Are they really all being blocked?

paper meteor
#

your origin is whatever server you're running

#

this means out of the > 25 million requests, only 63 actually made it to your server

grand quest
#

Wow!

#

Makes me a lot less worried... But still, I'm scared. My server still isn't functioning well even after only being hit by 105. What steps should I take moving forward?

paper meteor
#

check your server if it's actually only receiving 105 requests. If the attacker got hold of your origins IP then they can completely circumvent cloudflare (...)

if however your origin indeed only received 105 requests and is still struggling then i have to say this seems more like a server issue than a ddos issue

grand quest
#

I see. How does the attacker affect my server? Are they requesting information? Do you know how I can check, and limit that amount of data thats being requested?

paper meteor
#

you are the only person who can answer those questions

#

i know nothing about your infrastructure and the traffic you usually work with

grand quest
grand quest
#

What do I do about the ones that did get served by the origin?

dense lodge
grand quest
dense lodge
grand quest
#

This is what I see when going to the site.

dense lodge
#

I would recommend you to create a rate limit rule.
I don't know what amount of requests is considered normal for your domain but for example:
Create a rule that blocks any IP address that tries to send you more than 700 requests in 10 seconds.

#

Additionally, I would consider blocking "definitely automated" bots through the super bot fight mode.

signal gladeBOT
#
DNS over Discord: WHOIS
138.197.83.198
-------------+------------------------------
Name         | DIGITALOCEAN-138-197-0-0     
Registrant   | DigitalOcean, LLC            
ASN          | 14061                        
Registration | Tue, 26 Jan 2016 13:51:21 GMT
CIDR         | 138.197.0.0/16