arrow_upward

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Should Anti-DDoS protection be a included feature?
#1
As the title says, what do you think about anti-DDos protection?
Does your VPS (standard paid plan or sponsored) have it?
Did you ever experience an attack? How did you handle it?

These are simple questions that, if you own a VPS, you will face someday. There is nothing to hide, I have experience it, at least 3 time with different systems.
As for my experience I can say that publishing your RAW IP address on the big internet is very dangerous.
These are a lot of attacks that can target you:
  • HTTP attack
  • SYN attack
  • NTP attack
  • SSH brute force
  • ICMP attack
  • Minecraft's sever attack (I am not joking, they flood the sever with ad-hoc simulated login requests)
  • ect...
The criminals just need your IP address, with simple software such as NMAP they can scan your entire port set and know what are you using.

When it will happen?
Well there isn't a specific moment, as soon as you publish something on the WEB you are in danger. There are services such as CDN that helps you hiding your real IP address but there are some exceptions:
  • To use SSH you need to access via the real IP address, CDN can't forward SSH.
  • When you want to host a game server you need to publish your real ip, CDN can't forward game traffic.
  • Free CDN services are limited, for example they cover only the 3rd level domain, if you need some nested domain you are naked.
  • Service such as mail servers, torrents are ignored by CDN, you are naked.
What you can do to protect yourself?
You can only prevent the leak of your IP address. If it has leaked and an attack is performed there are very few chance that you, as a VPS's provider customer, can handle it. You can shutdown your VPS but the traffic will always reach your provider's network.
Speaking of what action you can do:
  • Shutdown whatever is not necessary at that moment;
  • DON'T REJECT THE TRAFFIC, you let it be dropped with a HUGE timeout, so you can slow down the criminal
  • Be sure to use a CDN service which provides minimal protection
All I have said util now is useful when your own a VPS without a anti-ddos protection, when you have such protection mostly of the attack will be handled by experts and proper hardware thanks to the providers, we are speaking of:
  • Hardware firewall
  • Blackhole where redirect criminals' traffic
  • Proper IP filtering systems
So, let's end this little talk: after reading such things and how easy is to get targeted, what do you think? Should anti-ddos protection be a must-have for every VPS? Should be a paid or included service?

I am just a user, I am not aware of how complex is to setup such protection on providers'end. I am very curious, so if any provider read this, let us know what mean to setup a anti-ddos protection! Smile
Thanks to Post4VPS and Bladenodefor VPS 14
lockThread Closed 



person_pin_circle Users browsing this thread: 1 Guest(s)
Sponsors: VirMach - Host4Fun - CubeData - Evolution-Host - HostDare - Hyper Expert - Shadow Hosting - Bladenode - Hostlease - RackNerd - ReadyDedis - Limitless Hosting