Sinisterly
Working Anti Ddos Script In Php - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Coding (https://sinister.li/Forum-Coding)
+--- Forum: PHP (https://sinister.li/Forum-PHP)
+--- Thread: Working Anti Ddos Script In Php (/Thread-Working-Anti-Ddos-Script-In-Php)

Pages: 1 2 3


Working Anti Ddos Script In Php - Alien - 01-10-2016

Ddos attack On Your Web Site?

Download The Script And Read Instruction File Readme.txt

You Can use this script.

You can protect your site from ddos.

I Use This Script My Site.

http://psni.us


RE: Working Anti Ddos Script In Php - roger_smith - 01-10-2016

(01-10-2016, 03:49 AM)Alien Wrote: Ddos attack On Your Web Site?

Download The Script And Read Instruction File Readme.txt

You Can use this script.

You can protect your site from ddos.

I Use This Script My Site.

http://psni.us

You have 1 post, and no virustotal or similar associated with this. Do you REALLY think people are going to download it? Nothing personal, but this sounds like a big fat lie.


RE: Working Anti Ddos Script In Php - BreShiE - 01-10-2016

Gonna have a read through, see if I can detect malicious code.

EDIT: This script was written by Gökhan Muharremoðlu.

Quote:Coded by Gökhan Muharremoðlu
License: GNU Library or Lesser General Public License version 3.0 (LGPLv3)
Release Date: 01.10.2012 v.1.8.2

I wouldn't suggest downloading from here, however the script does seem legit and I would trust it myself had it come from the original source.

When I get back home, I'll cross check this version with the original to detect any edits or such. Bare with me.


RE: Working Anti Ddos Script In Php - Rou - 01-10-2016

Code:
$ diff -rq iosec.http.anti.flood.v.1.8.2_with_iptables_bash_script anti-ddos $
It's identical to the one found at SourceForge.

Despite this, I agree with BreShiE; Download it from SourceForge instead.


RE: Working Anti Ddos Script In Php - The Real Slim Shady - 01-10-2016

The idea of an anti-ddos PHP script is fucking hilarious. Best case scenario you've increased the load on your server under normal circumstances. Worst case scenario is you've made a DDoS worse. Unless you've got a really resource heavy PHP application - this script is still using resources to do its job. The net benefit is essentially 0. DDoS attacks should not be mitigated at the application layer. By that point it's already far too late.

(01-10-2016, 03:52 AM)roger_smith Wrote: You have 1 post, and no virustotal or similar associated with this. Do you REALLY think people are going to download it? Nothing personal, but this sounds like a big fat lie.

Sounds like an opportunity to promote his site if you ask me.

As for virus total. don't really think it's necessary for certain file types. I've never seen an infected zip file compromise a system. And the contents are all plaintext - you can check all of them. Virus total won't really tell you if theres a backdoor in the code, so scanning PHP scripts is all but pointless really.


RE: Working Anti Ddos Script In Php - Rou - 01-10-2016

(01-10-2016, 11:02 AM)The Real Slim Shady Wrote: The idea of an anti-ddos PHP script is fucking hilarious. Best case scenario you've increased the load on your server under normal circumstances. Worst case scenario is you've made a DDoS worse. Unless you've got a really resource heavy PHP application - this script is still using resources to do its job. The net benefit is essentially 0. DDoS attacks should not be mitigated at the application layer. By that point it's already far too late.
They do have a cron script to load the banlist into iptables, which isn't too shabby, but it's still a poor man's anti-DDoS technique.
Can't say I'm particularly impressed with the scripts either way. The banlist is all file based and the code quality is that of your typical PHP dev (in other words not all that great).


RE: Working Anti Ddos Script In Php - BreShiE - 01-11-2016

(01-10-2016, 10:42 AM)Rou Wrote:
Code:
$ diff -rq iosec.http.anti.flood.v.1.8.2_with_iptables_bash_script anti-ddos $
It's identical to the one found at SourceForge.

Despite this, I agree with BreShiE; Download it from SourceForge instead.

Thanks haha. I never got around to checking this so I'm glad someone saved me the effort. It's hard doing stuff on Android.


RE: Working Anti Ddos Script In Php - Oni - 01-11-2016

As @Rou said, it's probably better to download it from Sourceforge:
http://sourceforge.net/projects/iosec/files/iosec.http.anti.flood.v.1.8.2_with_iptables_bash_script.zip/download


RE: Working Anti Ddos Script In Php - Angel Beats - 03-03-2016

(01-10-2016, 11:02 AM)The Real Slim Shady Wrote: The idea of an anti-ddos PHP script is fucking hilarious. Best case scenario you've increased the load on your server under normal circumstances. Worst case scenario is you've made a DDoS worse. Unless you've got a really resource heavy PHP application - this script is still using resources to do its job. The net benefit is essentially 0. DDoS attacks should not be mitigated at the application layer. By that point it's already far too late.


Sounds like an opportunity to promote his site if you ask me.

As for virus total. don't really think it's necessary for certain file types. I've never seen an infected zip file compromise a system. And the contents are all plaintext - you can check all of them. Virus total won't really tell you if theres a backdoor in the code, so scanning PHP scripts is all but pointless really.
I agree with your first statement, about PHP not being the right place to mitigate ddos. But your second part "DDoS attacks should not be mitigated at the application layer." How do you mitigate an application layer DDoS attack without application layer protection?


RE: Working Anti Ddos Script In Php - meow - 03-04-2016

(03-03-2016, 09:57 PM)Angel Beats Wrote: I agree with your first statement, about PHP not being the right place to mitigate ddos. But your second part "DDoS attacks should not be mitigated at the application layer." How do you mitigate an application layer DDoS attack without application layer protection?

1. This thread is old and the person you're replying to is banned
2. He was talking about transport layer DDoS attacks.