<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[刘新修]]></title> 
<link>http://pic1.liuxinxiu.com:80/index.php</link> 
<description><![CDATA[刘新修的个人博客 (Liuxinxiu'S Blog)]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[刘新修]]></copyright>
<item>
<link>http://pic1.liuxinxiu.com:80/DoSDeflate/</link>
<title><![CDATA[CentOS简单配置防御ddos攻击]]></title> 
<author>刘新修 &lt;admin@yourname.com&gt;</author>
<category><![CDATA[Linux/Unix]]></category>
<pubDate>Tue, 01 Sep 2020 00:43:19 +0000</pubDate> 
<guid>http://pic1.liuxinxiu.com:80/DoSDeflate/</guid> 
<description>
<![CDATA[ 
	<p>&nbsp;<span style="color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;">DDOS这种攻击的目的就是在短时间内制造数量巨大的并发连接，从而使用服务器down机或消耗掉网络带宽和系统资源导致正常用户无法正常访问浏览网站。</span><br style="box-sizing: border-box; outline: 0px; margin: 0px; padding: 0px; overflow-wrap: break-word; color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;" /><span style="color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;">DoS Deflate 是一个轻量级阻止拒绝服务攻击的bash shell脚本。我们可以通过安装他并且简单配置来防御DDOS攻击。</span><br style="box-sizing: border-box; outline: 0px; margin: 0px; padding: 0px; overflow-wrap: break-word; color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;" /><span style="color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;">首先安装命令：</span></p><div class="codeText"><div class="codeHead">C#代码</div><ol start="1" class="dp-c"><li class="alt"><span><span>wget&nbsp;http:</span><span class="comment">//www.inetbase.com/scripts/ddos/install.sh</span><span>&nbsp;&nbsp;</span></span></li><li><span>chmod&nbsp;700&nbsp;install.sh&nbsp;&nbsp;</span></li><li class="alt"><span>./install.sh&nbsp;&nbsp;</span></li></ol></div><p><span style="color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;">然后会自动进行安装，完成后会有一段版权提示与说明，按q键退出即可。</span><br style="box-sizing: border-box; outline: 0px; margin: 0px; padding: 0px; overflow-wrap: break-word; color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;" /><span style="color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;">卸载命令：</span></p><div class="codeText"><div class="codeHead">C#代码</div><ol start="1" class="dp-c"><li class="alt"><span><span>wget&nbsp;http:</span><span class="comment">//www.inetbase.com/scripts/ddos/uninstall.ddos</span><span>&nbsp;&nbsp;</span></span></li><li><span>chmod&nbsp;700&nbsp;uninstall.ddos&nbsp;&nbsp;</span></li><li class="alt"><span>./uninstall.ddos&nbsp;&nbsp;</span></li></ol></div><p><span style="color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;">安装完成之后就可以通过简单配置来进行DDOS防御，我是用的是CentOS7操作系统配置文件目录是/usr/local/ddos/ddos.conf</span><br style="box-sizing: border-box; outline: 0px; margin: 0px; padding: 0px; overflow-wrap: break-word; color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;" /><span style="color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;">或者也可以通过命令更改 vi /usr/local/ddos/ddos.conf 编辑完成后：wq保存退出</span><br style="box-sizing: border-box; outline: 0px; margin: 0px; padding: 0px; overflow-wrap: break-word; color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;" /><span style="color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;">下面介绍一下ddos.conf的基本配置#为注释部分不用理会关键配置项有：</span></p><div class="codeText"><div class="codeHead">C#代码</div><ol start="1" class="dp-c"><li class="alt"><span><span>PROGDIR=</span><span class="string">&quot;/usr/local/ddos&quot;</span><span>&nbsp;#文件存放目录&nbsp;&nbsp;</span></span></li><li><span>PROG=<span class="string">&quot;/usr/local/ddos/ddos.sh&quot;</span><span>&nbsp;#主要功能脚本&nbsp;&nbsp;</span></span></li><li class="alt"><span>IGNORE_IP_LIST=<span class="string">&quot;/usr/local/ddos/ignore.ip.list&quot;</span><span>&nbsp;#可以设置IP白名单&nbsp;&nbsp;</span></span></li><li><span>CRON=<span class="string">&quot;/etc/cron.d/ddos.cron&quot;</span><span>&nbsp;#crond定时任务脚本&nbsp;&nbsp;</span></span></li><li class="alt"><span>APF=<span class="string">&quot;/etc/apf/apf&quot;</span><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;#这两项应该分别对应使用APF或者iptables配置目录不过笔者&nbsp;&nbsp;</span></span></li><li><span>IPT=<span class="string">&quot;/sbin/iptables&quot;</span><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;#尝试打开文件里边是乱码，有哪位大牛知道是干嘛的欢迎留言&nbsp;&nbsp;</span></span></li><li class="alt"><span>&nbsp;&nbsp;</span></li><li><span>FREQ=1&nbsp;#间隔多久检查一次，默认1分钟&nbsp;&nbsp;</span></li><li class="alt"><span>&nbsp;&nbsp;</span></li><li><span>NO_OF_CONNECTIONS=150&nbsp;#最大连接数设置，超过这个数字的IP就会被屏蔽&nbsp;&nbsp;</span></li><li class="alt"><span>&nbsp;&nbsp;</span></li><li><span>APF_BAN=0&nbsp;#1：使用APF，0：使用iptables，推荐使用iptables&nbsp;&nbsp;</span></li><li class="alt"><span>&nbsp;&nbsp;</span></li><li><span>KILL=1&nbsp;&nbsp;&nbsp;&nbsp;#是否屏蔽IP&nbsp;1：屏蔽，0：不屏蔽&nbsp;&nbsp;</span></li><li class="alt"><span>&nbsp;&nbsp;</span></li><li><span>EMAIL_TO=<span class="string">&quot;root&quot;</span><span>&nbsp;#发送电子邮件报警的邮箱地址，换成自己使用的邮箱&nbsp;&nbsp;</span></span></li><li class="alt"><span>&nbsp;&nbsp;</span></li><li><span>BAN_PERIOD=600&nbsp;&nbsp;#禁用IP时间，可根据情况调整，默认单位：秒&nbsp;&nbsp;</span></li></ol></div><p>如果/usr/local/ddos/ddos.sh 统计不正确,可能是启用ipv6的缘故</p><p>vi /usr/local/ddos/ddos.sh&nbsp;&nbsp;<span style="color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;">修改/usr/local/ddos/ddos.sh</span></p><p>117行的内容是这样的netstat -ntu &#124; awk '&#123;print $5&#125;' &#124; cut -d: -f1 &#124; sort &#124; uniq -c &#124; sort -nr &gt; $BAD_IP_LIST</p><p><span style="color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;">修改为以下代码即可！</span></p><div class="codeText"><div class="codeHead">C#代码</div><ol start="1" class="dp-c"><li class="alt"><span><span>netstat&nbsp;-ntu&nbsp;&#124;&nbsp;awk&nbsp;</span><span class="string">'&#123;print&nbsp;$5&#125;'</span><span>&nbsp;&#124;&nbsp;cut&nbsp;-d:&nbsp;-f1&nbsp;&#124;&nbsp;sed&nbsp;-n&nbsp;</span><span class="string">'/[0-9]/p'</span><span>&nbsp;&#124;&nbsp;sort&nbsp;&#124;&nbsp;uniq&nbsp;-c&nbsp;&#124;&nbsp;sort&nbsp;-nr&nbsp;&gt;&nbsp;$BAD_IP_LIST&nbsp;&nbsp;</span></span></li></ol></div><p><span style="color: rgb(77, 77, 77); font-family: &quot;Microsoft YaHei&quot;, &quot;SF Pro Display&quot;, Roboto, Noto, Arial, &quot;PingFang SC&quot;, sans-serif; font-size: 18px; font-variant-ligatures: common-ligatures;">CentOS7默认为Firewall为了配合使用DoS Deflate建议停用Firewall启用iptables，不会用iptables的朋友，百度一下有很多</span></p>
]]>
</description>
</item><item>
<link>http://pic1.liuxinxiu.com:80/DoSDeflate/#blogcomment</link>
<title><![CDATA[[评论] CentOS简单配置防御ddos攻击]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://pic1.liuxinxiu.com:80/DoSDeflate/#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>