Finally it came up to an end!
I have found one of the best anti-ddos.
The "DoS Deflate"!
(D)DoS Deflate is a lightweight bash shell script designed to assist in the process of blocking a dos. It utilizes the command below to create a list of IP addresses connected to the server, along with their total number of CONNECTIONS. It is one of the simplest and easiest to install solutions at the software level.
1
netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n
IP addresses with over a pre-configured number of CONNECTIONS are automatically blocked in the server's firewall, which can be direct iptables.
Notable Features
It is possible to whitelist IP addresses, via /usr/local/ddos/ignore.ip.list.
Simple configuration file: /usr/local/ddos/ddos.conf
IP addresses are automatically unblocked after a preconfigured time limit (default: 600 seconds)
The script can run at a chosen frequency via the configuration file (default: 1 minute)
You can receive email alerts when IP addresses are blocked.
Installation
1
2
3
4
5
2
3
4
5
wget http://www.inetbase.com/scripts/ddos/install.sh chmod 0700 install.sh ./install.sh
Uninstallation
1
2
3
2
3
wget http://www.inetbase.com/scripts/ddos/uninstall.ddos chmod 0700 uninstall.ddos ./uninstall.ddos