4 ms·
Having an attacker know the public IP of your box almost guarantees that they can take it down. Even if somehow you were able to ignore all the packets from th
by FlyingAvatar 2y ago
Having an attacker know the public IP of your box almost guarantees that they can take it down. Even if somehow you were able to ignore all the packets from the attacker, most capable DDoSers will be easily be able to saturate the bandwidth of pretty much a single VPS easily.
And if it's a cheap VPS, your provider is going to drop you in a blink so that their other customers are not affected.
If you want to be able to withstand a DDoS, you need a WAF who can absorb the amount of bandwidth that the attacker is capable of delivering, while also being capable of filtering enough of it that your service is not overwhelmed anyway.
Also, if you have ever hosted your service directly on the public IP of your VPS, you also probably need to change it. If an attacker sees your service is suddenly behind CloudFlare, they can search sites that keep a history of domain's public IPs and will attack all of them to see if they can skirt around your WAF.
Ideally, you need to keep the IPs of your services completely private and then firewall them such that only your WAF provider can forward traffic to them.
- theanonymousone 2y agoA WAF is something like CloudFlare?
- FlyingAvatar 2y agoYes, CloudFlare or similar.