How to launch and defend against a DDoS attack [pdf]
secure.edu.pl
secure.edu.pl
If you are hit with a DDOS and want to direct traffic through a DDOS mitigation service you will often need to point your domain at their servers. If your DNS TTL is 48 hours then you will be up a creek for quite a while.
This hasn't been a significant problem in years. When I execute a DNS change on a record with a 30 second TTL, I expect to see 95+% of the traffic move within a couple of minutes. The things that tend to get it wrong these days are applications that don't honor the TTL instead of resolvers, but browsers generally get it right.
http://www.youtube.com/watch?feature=player_embedded&v=LQ_6o...
He covers DDoS in detail. Warning, possibly NSFW for many f-bombs.
Okay, routers are supposed to get a packet and just route it to the next point by blindly following the instructions ("0.0.0.1 wants to UDP 124.40.28.9 on port 80"), but whatever the route taken, once my route leaves my home router, my first stop will ALWAYS be my provider's routers, the very company that gives me an IP.
So why can't these companies check on their client-to-outside-world routers that the request is coming from my IP and not something otherworldly?
Get Ecatel's upstreams to cut their ports and you'll get rid of 80% of it.
What is the reason Dreamhost servers are comprised? Are those the old server accounts?
I am also amazed by the durability of our infrastructure able to sustain this huge flow everyday. But good work, CF.
Nothing within your power can protect you from a multi-gigabit DDoS attack except bandwidth or a black hole route.
If you're getting smaller attacks you can try Fail2ban, some Nginx rules, or an edge cache.
TL;DR: "Today, all CloudFlare routers were being DDoS'ed by 127.0.0.1. CloudFlare is now investigating its employees."