DDoS Protection With IPtables
javapipe.com
javapipe.com
Most attacks are usually small(<10 Gbps) and effective iptables rules can go a long way, both against unwanted application traffic and packet floods.
Iptables is there to ensure you can handle as many packets as possible per second, not bandwidth.
Please stop this non-sense, there are too many ICMP blackholes already.
don't be lazy, don't drop ICMP and just do proper filtering.
Would this hit a sweet spot between a grandma's blog with straight HTML and massively trafficked sites like Wikipedia?
Resource exhaustion seems like a useful feature of _some_ kind of system. What does that system look like?
It is not useful for straight HTML - volumetric DDoS will take it out (not l7), it's not even going to make it to your machine. It does not mitigate well against any real major l7 flood either, just by virtue of "your pipe is smaller". A formal l7 attack would at least do basic recon to find a high resource consumption page (like search.php?q=%20 or something)
I guess this would come in maybe slightly useful with someone running ab or jmeter from a single machine toward you? But I don't know a single instance of that happening in the last decade..
I'm not saying iptables is bad per se, but this article in particular is just some overpriced hosting provider's blog that tells you to set things like kernel.panic in sysctl. The article also claims all of this to be a defense against DDoS, which really will probably just eat through your pipe completely most of the time, not single-person DoS.
Just as real as anything else...
You want to drop unwanted traffic before you start spending more cycles on it.
Sure they have bigger "tubes" as well
https://www.esecurityplanet.com/products/top-ddos-vendors.ht...
"Cloudflare WAF supports the OWASP ModSecurity Core Rule Set by default" https://www.cloudflare.com/waf/
Iptables definetly can help with real ddos attacks.
Maybe we have different definitions of real DDoS attacks. What you mean is probably DoS attack, not DDoS (distributed).
If you have 1 gigabit pipe I can DoS (from one machine) you with 10 gigabit machine with ease and iptables will not help you at all.
These typically use PHP scripts/perl scripts/whatever and fork off in the background to do some mix of sshing into some machines legitimately purchased or with stolen cards at crappy "offshore" providers that allow spoofing or otherwise to launch reflected DNS/NTP attacks, hitting upstream APIs that do the same (as a reseller of attacks), hitting uploaded webshells to do `fsockopen('udp://'...` on a ton of cheap shared hosting machines or hacked sites, usually old PHP CMS type stuff.
Comes complete with fake "terms of service" like how it's only meant to be used for legal testing of your own servers, but in practice that's effectively there as a joke.
There's a huge market of these, "step by step" guides on youtube with affiliate links to these services, like https://www.youtube.com/watch?v=tHKBZr00IOA for example.
Reflection attacks of 50-70 Gbps are easily blocked by the firewall as the port is likely blocked.
Your server would be dead in any large scale attack anyway, iptables is fine and works well