(D)DoS Deflate
netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n
IP addresses with over a pre-configured number of connections are automatically blocked in the server’s firewall, which can be direct iptables or Advanced Policy Firewall (APF). (We highly recommend that you use APF on your server in general, but deflate will work without it.)
Notable Features
- It is possible to whitelist IP addresses, via /usr/local/ddos/ignore.ip.list.
- Simple configuration file: /usr/local/ddos/ddos.conf
- IP addresses are automatically unblocked after a preconfigured time limit (default: 600 seconds)
- The script can run at a chosen frequency via the configuration file (default: 1 minute)
- You can receive email alerts when IP addresses are blocked.
Installation
wget http://www.inetbase.com/scripts/ddos/install.sh
chmod 0700 install.sh
./install.sh
Uninstallation
wget http://www.inetbase.com/scripts/ddos/uninstall.ddos
chmod 0700 uninstall.ddos
./uninstall.ddos
Questions?
Although most things are explained on this page, if you have any further questions, you may contact the original developer of the script, Zaf.