Re: [Koha] any recommended best practises for handling DoS / DDoS attacks on Koha?

2016-02-08 Thread Karam Qubsi
Hi , A free account on CloudFlare ( https://www.cloudflare.com/ ) , can protect your domain , I didn't try it before, but someone advised me to use it for such cases . You may try it as it is free . Best wishes . On Mon, Feb 8, 2016 at 8:33 PM, Indranil Das Gupta wrote: > Hi all, > > Last

Re: [Koha] any recommended best practises for handling DoS / DDoS attacks on Koha?

2016-02-08 Thread Scott Owen
Not really Koha specific, but, as a rule Work upstream, not down. Make sure you have your Internet providers Network Operations Center (NOC) telephone number, and know exactly who to talk to. If you have piles of spare cash sitting around, you could always make some sort of deal with a second

Re: [Koha] any recommended best practises for handling DoS / DDoS attacks on Koha?

2016-02-08 Thread Chris Cormack
The easiest way, to stop the machine getting overwhelmed and running out of RAM, is to restrict the max connections Apache allows to a level that you can cope with. This of course won't stop the DOS, because they can still use all available connections, it will stop the machine crashing though. The

[Koha] any recommended best practises for handling DoS / DDoS attacks on Koha?

2016-02-08 Thread Indranil Das Gupta
Hi all, Last night I managed to DoS someone's Koha box accidentally, Of course I called up to inform them that they need to restart the services. But this set me thinking. Anyone running a crawler against the export options in the OPAC can DoS down a stock Koha install running on a VPS, by floodin