RE: Working Anti Ddos Script In Php 03-12-2016, 12:11 AM
#16
(03-11-2016, 08:34 PM)Angel Beats Wrote: Erm actually most Layer 7 attacks are NOT the fault of the developers. As long as your packets look like a real users packets you will still use a lot of valuable resources.
*Developers and system administrators fault.*
I assume you are talking about a Layer 7 attack where a button is pressed repeatedly and so on. Thus; Completely legitimate packet that is repeated over and over again. It is quite simple to mitigate those with a simple iptables rules set. Just limit how many connections each IP address can make to your server per X seconds, if the IP address sends say 600 requests per second (hypothetical) and your limit is 500 per second he will be banned from making further requests for the next hour or so. As soon as these packets aren't reaching the web page, it doesn't do much more harm than trying, badly, to fill up your bandwidth.
That is just one example of a mitigation that works.


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)