mencegah lebih baik daripada pusing dikemudian hari ^^
Attacks that consume your available Internet-facing bandwidth or overpower your router’s CPU can still take you offline.
Denial of a particular service will come in one of two forms:
- Complete consumption of a resource such as bandwidth, memory, CPU, file handles, or any other finite asset.
- Exploiting a weakness in the service to stop it functioning or causing the service to crash.
Begitu katanya onlamp, so daripada entar pusing², muntah², pucat karena kena DOS kan lebih baik kalau di benchmark dulu aja
. Trik berikut sebenarnya digunakan untuk FreBSD 4.X dan 5.X, tapi skr ta coba juga di 6.X.. ya iseng² berhadiah.. [berhadiah komplain kalo ngga berhasil
]
net.inet.tcp.msl=7500efines the Maximum Segment Life. This is themaximum amount of time to wait for an ACK in reply to a SYN-ACK or FIN-ACK, inmilliseconds. If the computer does not receive an ACK in this time, itconsiders the segment lost and frees the network connection.
net.inet.tcp.blackhole=2defines what happens when the systemreceives a TCP packet on a closed port. When set to1, SYN packetsarriving on a closed port will be dropped without a RST packet being sent back.When set to2, all packets arriving on a closed port are droppedwithout an RST being sent back. This saves CPU time, because packets don't needas much processing, and outbound bandwidth, by not sending outpackets.
net.inet.udp.blackhole=1the system will drop all UDP packets that arrive on a closed port.
net.inet.icmp.icmplim=50This controls the maximum number of ICMP "Unreachables" and also TCP RST packets toreturn every second. It helps curb the effects of attacks that generate a lotof reply packets.
kern.ipc.somaxconn=32768limits the maximum number of concurrently open sockets.open sockets.
http://www.onlamp.com/pub/a/bsd/2004/06/24/anti_dos.html
Read original post at http://runia2001.blogspot.com/2008/03/mencegah-lebih-baik-daripada-pusing.html
Related posts:
Categories: Alumnus Blog
Wikusama (noun) : nick community alumni [1] widyaloka kusuma samekta makarya [2] tempat mencari ilmu yang bersinar, harum, mewangi, yang mendidik dan menyiapkan sumber daya manusia agar siap terjun ke dunia kerja [3] ikatan alumni smk telekomunikasi sandhy putra malang [4] tidak mengenal batas generasi dan umur; mailing-list [1] wikusama@wikusama.com
Latest Comments