RE: getting DDoSed 08-05-2018, 11:08 PM
#40
(07-06-2018, 11:44 AM)mothered Wrote: I haven't sifted through each and every post, but have you performed a factory reset on your router? Also, If your router has a built-In firewall, you can define security rules and filter Incoming traffic to block the attack.
If you're running a dynamic IP, It's strange that multiple reboots didn't assign a new one.
(08-05-2018, 10:16 PM)Cryogenica Wrote:(08-05-2018, 09:54 PM)l33t Wrote:(08-05-2018, 03:51 PM)mothered Wrote: That's what I meant, your AP- modem/router whatever gateway you access the net.
I'm at a loss as to why your ISP cannot handle It on their end. The traffic (DDoS) Is obviously going through them, yet they're refusing to take responsibility and provide you the service that you signed up for. I'm sure you didn't agree to a DDoS as part of your monthly quota. I'd be speaking to senior management and "demand" they wake up to themselves and get their act together.
I will demand to speak to a manager the next time I call them, last time I asked to speak to a higher up the lady hung up on me so I hope it'll go better the next time around.
(08-05-2018, 05:21 PM)M00N66 Wrote: @l33t Download Wireshark, look for packets coming in at an unrealistic rate, SOMETIMES they will have a message including but not limited to "A cat is fine too", click one of the packets and look for the IP it's coming from. Then report it to the Cable Company or something.
Don't most booters have thousands of different bots that send packets, if 1 gets blocked I'm sure it won't achieve a lot.
Yes, most use many different bots. That's actually the difference between DDoS and DoS (DDoS uses multiple bots, while DoS uses only one).
If, though, you limit them to 3 connections / munite (like I said above), you will notice an initial drop in network speed (assuming the bots come online at exactly the same time, but after a sizable amount of bots get blocked, all you need to do is hold off any new ones that come online to replace the old ones. No bot will send more than 3 connections worth of data, which isn't actually much even for a large botnet, since they get disconnected almost immediately. This basically reduces it from at any given moment a large DDoS attack to maybe a few DoS attacks. And DoS attacks are pretty easy to block.
Yes sadly my ISP doesn't allow for that much customisation with my modem.

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)