Reply

Thread: benedelman.org DDoS'ed offline; suggestions?

 
Tools Search
  #1  
Old February 8th, 2005, 03:50 PM
bedelman bedelman is offline
Full Member
Join Date: January 18th, 2005
Posts: 471
My main site, www.benedelman.org, is offline due to a DDoS attack from bad actors yet to be identified. My web host, Globat, says this is the worst DDoS they've ever faced, and they're apparently in no position to get my site back online. I'm working to find a new hosting company. Any suggestions?
  #2  
Old February 8th, 2005, 04:07 PM
ecomcity ecomcity is offline
ecomcity's Avatar
2005 Linkshare Golden Link Award Winner 
Join Date: January 18th, 2005
Location: St Clair Shores MI.
Posts: 17,406
Host on the same service as FBI.org and FTC.org. Get some States Attorney Generals to install cybercrime sniffers or even the Carnivore system to identify the Adwhore perps.
__________________
Webmaster's... Mike and Charlie

"What have you done today to put real value into a referral click...from a shoppers viewpoint!"
  #3  
Old February 8th, 2005, 08:39 PM
Jorge - JRami Jorge - JRami is offline
Jorge - JRami's Avatar
Outsourced Program Manager
Join Date: January 18th, 2005
Location: Florida
Posts: 3,417
Many choices, but I have used powweb.com for few years with one site with no problems, even though they have lots of users, etc.

Now, if your site does not really need any PHP or all those bells and wistles, try godaddy.com, 3.95 a month.

You can also try, autica.com, good for reseller accounts too.
__________________
Jorge Ramirez - JRrami.com
Outsourced Affiliate Program Management & Marketing
Get more sales and leads with SHOPiMAR.com
Join our featured merchants SHOPiMARnetwork.com
Subscribe to SHOPiMAR.net for updates

Join Our Featured Managed Programs: Christiangear.com / DesignForYourWine / EverythingFurniture / EverythingOfficeFurniture / GearForGoldens / GreekGear / GuidoGear / JustIrishStuff / KelleyFurniture / MilitaryGearUSA / NationalityShop / TheFurnitureParadise / TShirtHub
Join ABW to remove this sponsored message.
  #4  
Old February 8th, 2005, 08:46 PM
bedelman bedelman is offline
Full Member
Join Date: January 18th, 2005
Posts: 471
Those are the kind of companies I'd usually look to. Indeed, that's about how I found my old host, Globat.

But now that I'm seeing hundreds of megabytes per second of DDoS traffic (600MB/sec, to be precise!), I don't think these folks are up to the task. I'm going to need an ISP with a savvy fraud department, with a great relationship with its upstream connectivity providers. I don't get the sense that these cheap folks fit the bill.

Anyone have any experience recovering from DDoS?
  #5  
Old February 8th, 2005, 09:03 PM
Kellie aka Ms. B Kellie aka Ms. B is offline
Kellie aka Ms. B's Avatar
Defender of Truth, Justice and the Affiliate Way
Join Date: January 18th, 2005
Location: The Swamp
Posts: 7,385
Send a message via AIM to Kellie aka Ms. B Send a message via MSN to Kellie aka Ms. B Send a message via Yahoo to Kellie aka Ms. B
For the welfare of the other sites that would be on a shared server, you may want to consider a dedicated server plan. Check the hosting forum, there have been many suggestions/experiences/etc posted there.
__________________
Kellie
Protect Your Revenue AffiliateFairPlay
  #6  
Old February 8th, 2005, 09:17 PM
Kellie aka Ms. B Kellie aka Ms. B is offline
Kellie aka Ms. B's Avatar
Defender of Truth, Justice and the Affiliate Way
Join Date: January 18th, 2005
Location: The Swamp
Posts: 7,385
Send a message via AIM to Kellie aka Ms. B Send a message via MSN to Kellie aka Ms. B Send a message via Yahoo to Kellie aka Ms. B
Ben,

I'm not certain if you may want to be posting publicly that you are currently hosted somewhere that can't or isn't dealing with a DDoS. Know what I mean?
__________________
Kellie
Protect Your Revenue AffiliateFairPlay
Join ABW to remove this sponsored message.
  #7  
Old February 8th, 2005, 09:36 PM
bedelman bedelman is offline
Full Member
Join Date: January 18th, 2005
Posts: 471
I have nothing to hide. The folks who are doing this to me know perfectly well that they're doing it and that, for now, they're succeeding. The extent to which Globat can handle DDoS is also perfectly well known -- they (like others) can handle most DDoS most of the time, but some DDoS is just too intense. 600MB/s is a lot to ask!

I will check out the hosting forum. Thanks for the pointer.
  #8  
Old February 8th, 2005, 10:15 PM
Kellie aka Ms. B Kellie aka Ms. B is offline
Kellie aka Ms. B's Avatar
Defender of Truth, Justice and the Affiliate Way
Join Date: January 18th, 2005
Location: The Swamp
Posts: 7,385
Send a message via AIM to Kellie aka Ms. B Send a message via MSN to Kellie aka Ms. B Send a message via Yahoo to Kellie aka Ms. B
I meant others. Hope you can get things resolved.
__________________
Kellie
Protect Your Revenue AffiliateFairPlay
  #9  
Old February 8th, 2005, 10:42 PM
Fer Fer is offline
ABW Ambassador
Join Date: January 18th, 2005
Location: Argentina
Posts: 513
What about a blog at google at least as a secondary source?
__________________
Fer(nando) - US & EU Marketing
Join ABW to remove this sponsored message.
  #10  
Old February 8th, 2005, 10:46 PM
Dynamoo Dynamoo is offline
Dynamoo's Avatar
SlimeWare Outer & Mooderator
Join Date: January 18th, 2005
Location: Elstow, UK
Posts: 5,462
Ouch.. that's tough. I've been on a shared server under DDOS and it was not a pleasant experience.

At least it proves the point - the people who distribute the spyware on your site are criminal gangs who recruit armies of zombie PCs, despite their own protests of innocence.

I've seen similar things happen to Andrew Clover's site with large-scale joe jobs from zombie PCs.
__________________
_________________________________________________

Innovative advertising with Slimeware Corporation and Telephore. Mail-order fuel with Petrol Direct.
  #11  
Old February 9th, 2005, 12:18 AM
chrisk chrisk is offline
ABW Ambassador
Join Date: January 18th, 2005
Posts: 683
If you are running on IIS, i might try http://www.easy-guard.com/en/

I have been considering loading it on a few of my primary boxes as a just in case.. I have no idea if similar things are available on Linux or even if this product works well. I just had it bookmarked...
  #12  
Old February 9th, 2005, 01:40 AM
Drewbert Drewbert is offline
Tree Hugging Liberal Hippy Realist
Join Date: January 18th, 2005
Posts: 2,971
Ben,

Go ask your question on slashdot. Very few mum&pop type hosting operations could handle what you're experiencing, both bandwidth wise and how to fight it.
Join ABW to remove this sponsored message.
  #13  
Old February 9th, 2005, 01:45 AM
Chocolate_Chicken Chocolate_Chicken is offline
Chocolate_Chicken's Avatar
Member
Join Date: January 19th, 2005
Location: The Hen House
Posts: 1,235
Want stealth?

Try Tripod.

No joke.
  #14  
Old February 9th, 2005, 10:58 AM
bedelman bedelman is offline
Full Member
Join Date: January 18th, 2005
Posts: 471
I'm back online. For those interested in who helped, see paragraph three of today's update to my site. I consider myself quite fortunate.
  #15  
Old February 9th, 2005, 11:11 AM
Zeus Zeus is offline
15 years and counting
Join Date: January 18th, 2005
Posts: 5,905
Glad to see you back online. Hope you'll find who's behind the DDoS attack.
Join ABW to remove this sponsored message.
  #16  
Old February 9th, 2005, 11:28 AM
Haiko de Poel, Jr. Haiko de Poel, Jr. is offline
Haiko de Poel, Jr.'s Avatar
ABW Founder
Join Date: January 18th, 2005
Location: New York
Posts: 21,554
Send a message via AIM to Haiko de Poel, Jr.
Can you please explain to me your rationale for the Globat affiliate link when you preface it with "My prior web host"?

Is that a new way of pre-selling via a negative testimonial?

I am no longer amazed or shocked at any of this, only appalled.
__________________
Continued Success,

Haiko
The secret of success is constancy of purpose ~ Disraeli

Last edited by Haiko de Poel, Jr.; February 9th, 2005 at 01:11 PM. Reason: Spelling edit (see below)
  #17  
Old February 9th, 2005, 12:09 PM
Drewbert Drewbert is offline
Tree Hugging Liberal Hippy Realist
Join Date: January 18th, 2005
Posts: 2,971
I'm getting a 404 for http://www.benedelman.org/news/020905-1.html and the main page goes to a GoDaddy advert - did you do a deal with Bob Parsons, or the girl with the broken spaghetti string strap? :^)
  #18  
Old February 9th, 2005, 12:13 PM
Zeus Zeus is offline
15 years and counting
Join Date: January 18th, 2005
Posts: 5,905
Drewbert must be under a DDoS attack. http://www.benedelman.org/news/020905-1.html is up for me.
Join ABW to remove this sponsored message.
  #19  
Old February 9th, 2005, 12:42 PM
bedelman bedelman is offline
Full Member
Join Date: January 18th, 2005
Posts: 471
Globat remains a good choice for most folks. They're not right for someone receiving a major DDoS attack. But in the $10-and-under (per month) department, they're about as good as it gets, in my view.

If someone happens to click through my link, then sign up with Globat, why shouldn't I get a commission? I don't intend to be "selling" Globat in the new post, so this is a little different from most affiliate links. But it's certainly not "appalling." (Incidentally there's no "u" in "appalled.")


Drewbert, the DNS propagation can take a bit of time. I changed my DNS at 2am Eastern last night, and my TTL is 1 hour, so officially you should see the change as of many hours ago. But the fact is many DNS servers cache records for longer than the TTL permits. Sit tight and the site will come back for you eventually. Sorry...
  #20  
Old February 9th, 2005, 01:09 PM
Haiko de Poel, Jr. Haiko de Poel, Jr. is offline
Haiko de Poel, Jr.'s Avatar
ABW Founder
Join Date: January 18th, 2005
Location: New York
Posts: 21,554
Send a message via AIM to Haiko de Poel, Jr.
I've never seen a negative presell... and wanted your rationale because your article didn't explain it.

The link wasn't appalling *thank your the spell check*, far from it! Oh and shoot yeah, if someone does click on your link and buys, you should be re-numerated! Hosting isn't free, much less when DDoSed.

The appalling part was the DDos, but like I said, I'm no longer amazed or shocked.
__________________
Continued Success,

Haiko
The secret of success is constancy of purpose ~ Disraeli
  #21  
Old February 9th, 2005, 01:43 PM
Catwoman Catwoman is offline
Full Member
Join Date: January 18th, 2005
Posts: 441
Ben,

A few years ago, grc.com was also the victim of DDOS attacks. His site was hit several times within the same week. You can read about it here http://grc.com/dos/grcdos.htm if you haven't seen it already.

It took a while but eventually he found out who did it, it's all described on his site and he even posted his conversations with the hackers. Since the two of you kinda deal along the same lines on the internet, he might be willing to give you a few tips on how to get to the culprits or even provide some help. Worth a try. What a great lawsuit that would be if you caught them!

I'm glad to see that they didn't scare you away! Good job and keep at it, you have a lot of people behind you. The work you do benefits ALL honest affiliates and companies.

Catwoman
Join ABW to remove this sponsored message.
  #22  
Old February 9th, 2005, 01:54 PM
bedelman bedelman is offline
Full Member
Join Date: January 18th, 2005
Posts: 471
Catwoman, Thanks for the link. I had seen that page, but not recently. It's all the more chilling now that it's so timely for me. Highly recommended reading.
  #23  
Old February 9th, 2005, 05:05 PM
SSanf SSanf is offline
SSanf's Avatar
Super Sh!t Stirrer
Join Date: January 18th, 2005
Posts: 10,036
Still down here, too.
__________________
Comments are opinion unless otherwise noted. Remember, pillage first. Then burn. Half of all people in the world have IQs under 100. You best learn to trust ol' SSanf!
  #24  
Old February 10th, 2005, 06:22 AM
RadarCat RadarCat is offline
ABW Ambassador
Join Date: January 18th, 2005
Location: Texas, USA
Posts: 582


Hi, bedelman

You might want to get web host suggestions from Steve Gibson at:

http://www.grc.com/support.htm

My best guess is that this is not the last time you will be a DDOS target.
Your work has obviously gotten some crooks worried.

RadarCat, Webmaster
http://www.os2warplinks.com
Join ABW to remove this sponsored message.
  #25  
Old February 10th, 2005, 12:31 PM
ecomcity ecomcity is offline
ecomcity's Avatar
2005 Linkshare Golden Link Award Winner 
Join Date: January 18th, 2005
Location: St Clair Shores MI.
Posts: 17,406
I see you site is back up now Ben. Hope you catch the perps.
__________________
Webmaster's... Mike and Charlie

"What have you done today to put real value into a referral click...from a shoppers viewpoint!"
Reply

Tools Search
Search:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Temporarily Offline Merchants MichaelColey ShareASale 7 January 9th, 2005 02:35 AM
Temporary Offline Redirect - PHP Version Brian - ShareASale ShareASale 3 August 28th, 2004 12:01 PM
YourStay - High EPC + Offline Fer ShareASale 2 August 11th, 2004 10:30 AM
Merchants Going Offline Ray ShareASale 3 September 1st, 2003 09:54 PM
Temporarily Offline qball0213 ShareASale 6 August 7th, 2002 01:32 AM