|
You last visited: Today at 19:15
Advertisement
Using a reverse proxy as DDoS protection?
Discussion on Using a reverse proxy as DDoS protection? within the SRO Private Server forum part of the Silkroad Online category.
07/01/2013, 13:44
|
#1
|
elite*gold: 0
Join Date: Sep 2012
Posts: 753
Received Thanks: 711
|
Using a reverse proxy as DDoS protection?
Would that work with a SRO server? And how do I have to set it up? Like do I need to put the proxy's IP in cert config or wut?
|
|
|
07/01/2013, 13:55
|
#2
|
elite*gold: 0
Join Date: Mar 2009
Posts: 2,748
Received Thanks: 2,010
|
hyperfilter is a reverse proxy, and yes, it will obviously work.
However you'll need to spoof the IP that your modules send out (as the silkroad files use a sharded networking system)
You'll need to find out how to spoof them yourself though, or if you use hyperfilter just ask their modified modules
|
|
|
07/01/2013, 13:59
|
#3
|
elite*gold: 0
Join Date: Sep 2012
Posts: 753
Received Thanks: 711
|
Quote:
Originally Posted by Nezekan
hyperfilter is a reverse proxy, and yes, it will obviously work.
However you'll need to spoof the IP that your modules send out (as the silkroad files use a sharded networking system)
You'll need to find out how to spoof them yourself though, or if you use hyperfilter just ask their modified modules
|
I guess this tool should work to spoof the IPs in all modules:  gezone.com/f722/certification-ip-addr-spoofer-generic-913944/
I found cheaper solutions than Hyperfilter, for example Javapipe: 
100$/month for 10gbps/4m pps protection, 200gb clean bw
Hyperfilter offers 10gbps/2m pps 1tb bw for 300$
|
|
|
07/01/2013, 14:03
|
#4
|
elite*gold: 0
Join Date: Mar 2009
Posts: 2,748
Received Thanks: 2,010
|
Quote:
Originally Posted by A new hope
I guess this tool should work to spoof the IPs in all modules:  gezone.com/f722/certification-ip-addr-spoofer-generic-913944/
I found cheaper solutions than Hyperfilter, for example Javapipe: 
100$/month for 10gbps/4m pps protection, 200gb clean bw
Hyperfilter offers 10gbps/2m pps 1tb bw for 300$
|
javapipe has high ip ranges, so you'll need to see if it will actually work with your original IP (unless somebody has fixed that bug already)
Also, they use the voxility network in Romania, it's not the ideal location for an sro server (as it will have a relatively high latency for western european/north african players and the voxility network is not as good as they advertise).
|
|
|
07/01/2013, 14:04
|
#5
|
elite*gold: 273
Join Date: Aug 2012
Posts: 4,451
Received Thanks: 2,429
|
You don't say?
Actually, This method won't work after someone gets your real IP beside, proxies are ***** when they aren't paid. paid VPN should get the job done. 'read about the difference between vpn and proxies'
|
|
|
07/01/2013, 14:06
|
#6
|
elite*gold: 0
Join Date: Sep 2012
Posts: 753
Received Thanks: 711
|
Quote:
Originally Posted by Nezekan
javapipe has high ip ranges, so you'll need to see if it will actually work with your original IP (unless somebody has fixed that bug already)
|
I have a fix for that bug. Pretty lame, but it works.
|
|
|
07/01/2013, 14:08
|
#7
|
elite*gold: 0
Join Date: Mar 2009
Posts: 2,748
Received Thanks: 2,010
|
Quote:
Originally Posted by Phoenix 1337
You don't say?
Actually, This method won't work after someone gets your real IP beside, proxies are ***** when they aren't paid. paid VPN should get the job done. 'read about the difference between vpn and proxies'
|
VPN and reverse proxies act completely the same in this case. A reverse proxy however is technically superior due to less overhead (as it is more close to raw networking, no need for the extra security overhead VPNs bring). Even if you use a vpn, if they get your main IP you're ****** either way, that's why you spoof the IP your modules send out and don't let a ****** code your website.
Also, he's talking about professional reverse proxies like hyperfilter, not some ****** socks proxy you use to enable facebook at work
Quote:
Originally Posted by A new hope
I have a fix for that bug. Pretty lame, but it works. 
|
Great, try if it works and tell me how you did it if it works
|
|
|
07/01/2013, 14:11
|
#8
|
elite*gold: 273
Join Date: Aug 2012
Posts: 4,451
Received Thanks: 2,429
|
Quote:
Originally Posted by Nezekan
VPN and reverse proxies act completely the same in this case. A reverse proxy however is technically superior due to less overhead (as it is more close to raw networking, no need for the extra security overhead VPNs bring). Even if you use a vpn, if they get your main IP you're ****** either way, that's why you spoof the IP your modules send out and don't let a ****** code your website.
|
I would create a registration panel in c# instead of php code. At least when its protected by any encryption, no one will be able to decrypt it unless he gets the mid point. (must be kral in ollydbg) <- Opps, released the new way.
|
|
|
07/01/2013, 14:14
|
#9
|
elite*gold: 0
Join Date: Mar 2009
Posts: 2,748
Received Thanks: 2,010
|
php is run server sided, there is no way for anybody to 'decrypt' it using the html code they get, nor will it send out the server IP if you don't tell it to do that
|
|
|
07/01/2013, 14:16
|
#10
|
elite*gold: 273
Join Date: Aug 2012
Posts: 4,451
Received Thanks: 2,429
|
Quote:
Originally Posted by Nezekan
php is run server sided, there is no way for anybody to 'decrypt' it using the html code they get, nor will it send out the server IP if you don't tell it to do that
|
@Holy helper, no one was able to get the connection by this method. I may release it soon. so no one can really get the real ip OR use sql injection. but the site will be ONLY html/css .. no login/registration panel balblabla etc.
Edit: the mssql side of the program database was totally unsecured.
|
|
|
07/01/2013, 23:21
|
#11
|
elite*gold: 94
Join Date: Mar 2007
Posts: 569
Received Thanks: 1,496
|
Quote:
Originally Posted by Phoenix 1337
I would create a registration panel in c# instead of php code. At least when its protected by any encryption, no one will be able to decrypt it unless he gets the mid point. (must be kral in ollydbg) <- Opps, released the new way. 
|
What the heck are you talking about?
first of all, there's no such thing as "registration panel in C#", it's ASP.NET.
the language (and mostly the syntax as all .NET languages are alike) is C#.
if you speak Italian and you now teach science, you don't really teach Italian, right? these are two different things.
and decrypt what? an HTML source? OllyDbg? really man? really?
About your VPN post.
if you take into consideration that both the VPN and the DDoS Mitigation (proxy) have the same network liability,
and I'm talking about speed, uptime, location, latency and such - the proxy will always be better.
why? because every VPN has some sort of a security layer bound to the protocol.
even if you take out the PAP or even the IPsec, you will still have the "base security" of your VPN protocol, whether it's L2TP, PPTP or others.
obviously it is not needed and it will slow down the network as every packet will be encrypted and decrypted. also it's tons of extra headers.
where a DDoS Mitigation if done well will simply be tunneling the connections and that's it, no extra stuff. pure network tunneling.
I'm not sure if you simply have no idea what you're talking about or you're just trolling.
I hope it's the latter.
|
|
|
07/01/2013, 23:34
|
#12
|
elite*gold: 0
Join Date: Jan 2013
Posts: 480
Received Thanks: 95
|
He says this because, there are companies offering tunneling over GRE or IPIP, it works, but slower than a proxy.
Also there are guys that think that using a proxy for linux or BSD (software proxy) will be the same as 'Hardware Proxying', it is a whole different matter, but still these wannabe companies will have to learn this  .
There are even the cases, when they use iptables rules, to perform some kind of NAT-Proxying, which ends the same as the other examples, full of overheads  .
|
|
|
07/02/2013, 02:25
|
#13
|
elite*gold: 273
Join Date: Aug 2012
Posts: 4,451
Received Thanks: 2,429
|
Quote:
Originally Posted by Oriya9
What the heck are you talking about?
first of all, there's no such thing as "registration panel in C#", it's ASP.NET.
the language (and mostly the syntax as all .NET languages are alike) is C#.
if you speak Italian and you now teach science, you don't really teach Italian, right? these are two different things.
and decrypt what? an HTML source? OllyDbg? really man? really?
About your VPN post.
if you take into consideration that both the VPN and the DDoS Mitigation (proxy) have the same network liability,
and I'm talking about speed, uptime, location, latency and such - the proxy will always be better.
why? because every VPN has some sort of a security layer bound to the protocol.
even if you take out the PAP or even the IPsec, you will still have the "base security" of your VPN protocol, whether it's L2TP, PPTP or others.
obviously it is not needed and it will slow down the network as every packet will be encrypted and decrypted. also it's tons of extra headers.
where a DDoS Mitigation if done well will simply be tunneling the connections and that's it, no extra stuff. pure network tunneling.
I'm not sure if you simply have no idea what you're talking about or you're just trolling.
I hope it's the latter.
|
Have you finished yet? I did it. as I said, It worked. Unless you have 0 knowledge in this shit, don't even quote then. AAAAAND, you did not noticed that MSSQL part? Have you downloaded holy helper before I stopped the project? Have you played grindroad ? "They had this idea bec. they were running under an emulator"
Ignorance. Ignorance everywhere!
Edit: My method ONLY for hiding your real IP. So, no one will be able to DDoS you nor using SQLi . And @ Nezekan 's quote, HTML has nothing to do with this
|
|
|
07/02/2013, 16:21
|
#14
|
elite*gold: 0
Join Date: Mar 2009
Posts: 2,748
Received Thanks: 2,010
|
Quote:
Originally Posted by Phoenix 1337
Have you finished yet? I did it. as I said, It worked. Unless you have 0 knowledge in this ****, don't even quote then. AAAAAND, you did not noticed that MSSQL part? Have you downloaded holy helper before I stopped the project? Have you played grindroad ? "They had this idea bec. they were running under an emulator"
Ignorance. Ignorance everywhere!
Edit: My method ONLY for hiding your real IP. So, no one will be able to DDoS you nor using SQLi . And @ Nezekan 's quote, HTML has nothing to do with this 
|
I think you are the one who doesn't know what you are talking about.
We're talking about reverse proxies, and you start about some kind of 'holy helper' (what the f*ck is that?), you think php is parsed client side and you have obviously no idea how the internet protocol works
And then you call us ignorant, you are either the world's worst troll or the world's dumbest person, I hope it's the first
|
|
|
07/02/2013, 16:24
|
#15
|
elite*gold: 273
Join Date: Aug 2012
Posts: 4,451
Received Thanks: 2,429
|
Quote:
Originally Posted by Nezekan
I think you are the one who doesn't know what you are talking about.
We're talking about reverse proxies, and you start about some kind of 'holy helper' (what the f*ck is that?), you think php is parsed client side and you have obviously no idea how the internet protocol works
And then you call us ignorant, you are either the world's worst troll or the world's dumbest person, I hope it's the first 
|
Was giving an example. What you don't understand, that if you were hiding your ip 100%, using a method that isn't SQLi-able or being hacked, you're totally safe then. <- for those who can't pay for decent coded-website.
Now I think you should understand the story.
|
|
|
 |
Similar Threads
|
[DDOS PROTECTED] Dedicated Servers with Free Proprietary DDoS Protection up to 10 Gbs
03/14/2014 - WoW Private Server - 7 Replies
INCLOUDIBLY - http://incloudibly.com is a Zurich-based web hosting company offering DDoS Protected Dedicated Servers, DDoS Protected Cloud Hosting, DDoS Protected Colocation in Europe, DDoS Protected Camfrog room hosting and professional DDoS Protection service from all types of DDoS attacks.
★ Order a Dedicated Server and get 10 Gb/s (4 Mpps) lifetime DDoS protection free-of-charge. This level of protection is enough to mitigate against 90% of DDoS attacks known. ★
What you get with...
|
Suchen Hilfe bei Reverse Proxy Einrichtung
06/20/2013 - Technical Support - 13 Replies
Hallo,
wir suchen aktuell jmd. der sich bei der Einrichtung eines Reverse Proxy auf Linux Betriebssystemen (ggf. mit nginx) auskennt.
Wer uns weiterhelfen kann / sich in dieser Sache auskennt möge uns bitte einfach via Skype adden, natürlich gibt es bei erfolgreicher Einrichtung des Reverse Proxy auch eine Entlohnung.
Kontaktiere uns:
Skype: mmo.sky
per PN
|
Need DDoS Protection for your gameserver? Protection in US and EU from $39.99/mo!
05/11/2013 - Private Server Advertising - 0 Replies
SolveDDoS is the leading provider in Remote DDoS protection . Our advanced protection system protects against Layer 4 and Layer 7 attacks!
Protection up to 10Gb/s
Protection against UDP, TCP, HTTP, Slowloris, ...
Remote Protection, stay at your host!
SolveDDoS Anti-Bot (Block automated SQLi, XSS, SPAM)
Layer 7 DDoS Protection
Flatrate 100Mbit bandwidth
SolveDDoS Attack Monitoring Panel
24/7 Support by DDoS Specialists
|
[Biete]Reverse Proxy's (Schutz gegen DDoS + Location verschleierung + Traffic sparen)
06/25/2012 - Trading - 0 Replies
Hallo liebe Elitepvpers Community,
neben meinem 1. Webhosting Thema möchte ich euch seperat Reverse Proxy's anbieten.
Aber erstmal, was sind Reverse Proxy's ?
Reverse Proxy's sind wie der Name schon sagt Proxy's aber nicht wie gewohnt auf dem Computer um Annonym zu surfen, sondern diesmal für unsere Webspace's oder Server.
Ein Reverse Proxy basiert auf dem Webserver Nginx.
Nginx ist ein starker Webserver der bei guter Konfiguration gleichzeitig eine Firewall gegen DDoS Angriffe ist.
...
|
:: Reverse Proxy Server ::
06/15/2011 - Trading - 2 Replies
Hallo elitepvper,
ich biete euch hier Reverse Proxy Server.
Mit diesen Proxy Servern, könnt ihr euren Serverstandort verschleiern.
Das heißt: Wenn eine Domain über den Proxy Server läuft, weiß niemand (außer der Besitzer) wo sich der eigentliche Server befindet.
http://upload.wikimedia.org/wikipedia/commons/thu mb/6/67/Reverse_proxy_h2g2bob.svg/400px-Reverse_pr oxy_h2g2bob.svg.png
Diese Proxy Server funktionieren mit Root Server/vServer und Webhosting.
Die jeweligen IP-Adressen sind...
|
All times are GMT +1. The time now is 19:16.
|
|