View Single Post
  #3   (View Single Post)  
Old 6th November 2015
jggimi's Avatar
jggimi jggimi is offline
More noise than signal
 
Join Date: May 2008
Location: USA
Posts: 7,984
Default

The wordpress page states that this began as an attack against a single server, but continued against the upstream infrastructure.

Without knowing anything more than this, it's impossible to provide any useful advice. So I'll reply in the same vague terms.

There are three steps:
  1. Determine the nature of an attack, and how it differs from valid, desired traffic.
  2. Block the bad traffic, and the bad traffic only.
  3. Go to Step 1, for the next attack.
Can tools like PF help? Sure. Stateful Tracking Options are an easy fix for certain types of DOS attacks. But not for all.

And any sort of PF rule won't help until you reach Step 2. Getting there requires completing Step 1. And that's the hard part.
Reply With Quote