<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ddos karşılama | M. Şahin KURU</title>
	<atom:link href="https://www.sahinkuru.com.tr/tag/ddos-karsilama/feed" rel="self" type="application/rss+xml" />
	<link>https://www.sahinkuru.com.tr</link>
	<description>Senior System Architect • Linux &#38; Microsoft Core Infra • Cloud &#38; DC &#38; Network Consultant • Cybersecurity &#38; Digital Forensics • Enterprise Backup &#38; Disaster Recovery</description>
	<lastBuildDate>Sat, 23 Nov 2013 14:40:57 +0000</lastBuildDate>
	<language>tr</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
<site xmlns="com-wordpress:feed-additions:1">117096499</site>	<item>
		<title>HTTP GET/POST DDoS Security</title>
		<link>https://www.sahinkuru.com.tr/2013/11/22/http-getpost-ddos-security.html</link>
					<comments>https://www.sahinkuru.com.tr/2013/11/22/http-getpost-ddos-security.html#respond</comments>
		
		<dc:creator><![CDATA[M. Şahin KURU]]></dc:creator>
		<pubDate>Fri, 22 Nov 2013 08:30:18 +0000</pubDate>
				<category><![CDATA[Cloud (Bulut Bilişim)]]></category>
		<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[İnformation Technology]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Server Systems]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[ddos attack]]></category>
		<category><![CDATA[ddos karşılama]]></category>
		<category><![CDATA[ddos korunma]]></category>
		<category><![CDATA[ddos önleme]]></category>
		<category><![CDATA[ddos security]]></category>
		<category><![CDATA[get attack]]></category>
		<category><![CDATA[get saldırısı]]></category>
		<guid isPermaLink="false">http://www.sahinkuru.com.tr/?p=558</guid>

					<description><![CDATA[<p>&#160; &#160; Bu dökümanda &#8220;HTTP GET/POST DDoS Saldirilarini&#8221; inceleme altina alinmistir. DDoS saldirilarinin bir türü olan HTTP GET saldirilari bir ip&#8217;den yada birden çok ip&#8217;den&#8230;</p>
The post <a href="https://www.sahinkuru.com.tr/2013/11/22/http-getpost-ddos-security.html">HTTP GET/POST DDoS Security</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="http://www.sahinkuru.com.tr/wp-content/uploads/ddos2-1.jpg"><img fetchpriority="high" decoding="async" data-attachment-id="559" data-permalink="https://www.sahinkuru.com.tr/2013/11/22/http-getpost-ddos-security.html/ddos2-1" data-orig-file="https://www.sahinkuru.com.tr/wp-content/uploads/ddos2-1.jpg" data-orig-size="469,359" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}" data-image-title="ddos2-1" data-image-description="" data-image-caption="" data-large-file="https://www.sahinkuru.com.tr/wp-content/uploads/ddos2-1.jpg" class="size-medium wp-image-559 alignleft" alt="ddos2-1" src="http://www.sahinkuru.com.tr/wp-content/uploads/ddos2-1-300x229.jpg" width="300" height="229" srcset="https://www.sahinkuru.com.tr/wp-content/uploads/ddos2-1-300x229.jpg 300w, https://www.sahinkuru.com.tr/wp-content/uploads/ddos2-1.jpg 469w" sizes="(max-width: 300px) 100vw, 300px" /></a>Bu dökümanda &#8220;HTTP GET/POST DDoS Saldirilarini&#8221; inceleme altina alinmistir.</p>
<p>DDoS saldirilarinin bir türü olan HTTP GET saldirilari bir ip&#8217;den yada birden çok ip&#8217;den belli bir web sayfasina yapilan GET talepleriyle olusur.<br />
Özellikle veritabani sorgusu yapan sayfalara yapilan GET istekleri hem apache servisini hemde apache ve php&#8217;nin arkasinda çalisan mysql servisine<br />
is yükü yapacaktir. Bu durumda hedef isletim sisteminin load&#8217;ini yükselterek sistem sorgulara geç cevap vermesi saglanacaktir. Ardindan ise sunucu down<br />
olacaktir.</p>
<p>Ne apache nede arkada ki mysql &#8220;aa bu talep daha önce gelmisti aynisini cevap olarak göndereyim&#8221; mantigini güdmezler. Her talebi isleme alirlar ve her islemin<br />
cevabini döndürmeye ugrasirlar.</p>
<p>Asagida ki komut netstat çiktisini alip üzerinde incelemeler yapmakta.</p>
<p>netstat -nt | grep -i &#8220;:80&#8243; kismi linux serverinizin 80. portuna talep gönderen ip&#8217;leri uniq olmadan listeler.<br />
awk &#8216;{print $5}&#8217;|awk -F&#8221;:&#8221; &#8216;{if ($3 != ffff)print $4;else print $1}&#8217; kismi üstte ki komutun output&#8217;unu alir ve IPv4 ve IPv6 a göre inceler.<br />
sort -n |uniq -c|sort -nr kismi bir üstteki komutun output&#8217;unu alir ve uniq siralama olarak döndürür.<br />
En sonda ki awk komutu ise hangi ip&#8217;den kaç adet talep geldigini size : ayiraci ile gösterir.</p>
<p>netstat -nt|grep -i &#8220;:80&#8243;|awk &#8216;{print $5}&#8217;|awk -F&#8221;:&#8221; &#8216;{if ($3 != ffff)print $4;else print $1}&#8217;|sort -n |uniq -c|sort -nr|awk &#8216;{print $1&#8243;:&#8221;$2}&#8217;</p>
<p>Sunucunuza gelen GET taleplerini min to max a göre order by ederek saldiri aninda gerekli ip&#8217;leri iptables üzerinden banlayabilirsiniz!</p>
<p>iptables -A INPUT -p tcp -s 10.10.10.10 &#8211;dport 80 -j DROP</p>
<p>üstte ki iptables komutu ile netstat çiktisina göre sisteme saldiran ip&#8217;leri banlayabilirsiniz. -10.10.10.10 örnek ip&#8217;dir.-</p>The post <a href="https://www.sahinkuru.com.tr/2013/11/22/http-getpost-ddos-security.html">HTTP GET/POST DDoS Security</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.sahinkuru.com.tr/2013/11/22/http-getpost-ddos-security.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">558</post-id>	</item>
	</channel>
</rss>
