logo level
SME
Agency
Large enterprise
contactOperationalControl Panel
newshackers-and-attacks

Hackers and attacks

In the eleventh episode of Hotline27, Thomas explains what to do if your website is attacked.

Large enterpriseAgency‎‎ㅤ06/05/2021
Hackers and attacks image

MY WEBSITE IS DOWN, WHAT NOW?

First, we need to understand the type of attack. Perhaps it is not a cyberattack, but your website is suddenly trending? In that case, a lot of crawlers will visit your website to collect information for search engines.

WHERE TO START?

First, we will investigate whether there is a pattern. For example, are they only IP addresses from China, does the user agent appear normal, and are the pages being visited genuine? Non-existent (old) pages are particularly interesting because they are not cached and therefore use more CPU.

You can also study the user agents. These are a kind of fingerprint, allowing you to assume that something strange is going on when you receive many identical requests, even if they come from different IP addresses.

UNIQUE IP ADDRESSES

Unfortunately, the era of unique IP addresses is over. They have become so rare that some operators are no longer able to assign unique IP addresses, especially on mobile networks. They have solved this problem by using “carrier grade NAT”, which assigns the same IP address to different users, for example in larger companies.

A DDOS ATTACK

A DDOS attack is the most well-known type of cyberattack used to take your services offline. It involves combining forces from a large network so that the source of the attack is difficult to detect. This results in a flood of data traffic, filling the provider's servers with useless traffic. Hackers use a technique whereby the response sent back is much longer than the request, and together with the various request locations, this ultimately crashes the network.

WHAT CAN YOU DO ABOUT IT?

Fortunately, DDOS attacks are easy to detect, as they involve a high volume of data coming in through certain ports, which does not go unnoticed for long. Your hosting provider has no choice but to blackhole your server and quickly inform other operators that you are no longer available.

CAN A DDOS ATTACK BE RESOLVED QUICKLY?

How quickly a DDOS attack is resolved depends on how desirable the target is. If the attack is purely intended to make a statement, it is usually resolved within an hour. However, if it is a case of extortion, it can take several days.

Fortunately, your provider is quickly aware of the attack and will start looking for the cause within five minutes. Fifteen minutes later, the solution has usually been found. A DDOS attack typically decreases in strength over time, because the network that is being abused also notices that something is wrong. It will then investigate and restrict its traffic.

DOES IT HAPPEN OFTEN?

DDOS attacks are frequently used by groups of hackers who see them as a means of pressure to make quick money. The target group mainly consists of e-commerce companies that earn money through their websites, otherwise a company would not consider paying.

OTHER TYPES OF CYBER ATTACKS

Another method of attacking a website is at the protocol level (TCP). The best known of these is a SYN flood. This is a disruption of communication in which the attacker keeps the server busy by sending packets, to which the server then responds that they have been received correctly.

After a while, there are so many connections and open connections that cannot be answered that the memory fills up. This means that new, genuine users can no longer connect because the server no longer responds.

HOW CAN A FIREWALL HELP?

The firewall checks whether the handshake procedure between the server and client is correct and, if not, the connection is terminated. The firewall also blocks if it detects that one client has many thousands of connections open without any data traffic. It will then terminate these connections, giving the server breathing space for real connections again.

But does that also mean blocking traffic from China?

That is a possibility, but we choose to block traffic from specific countries on the server itself. You can then simply display a page stating that the site is not available from that country.

ANY OTHER POSSIBILITIES

Another option is to look at the application itself (WordPress, Drupal, etc.) and apply rate limiting to it, such as a WP login. This is done with a web-level firewall that blocks brute-force attacks that make non-stop requests. You can also apply rate limits to the hostname when you are on a server that hosts multiple sites.

Crawlers

You can also tell whether it is a crawler from the user agent mentioned above. One crawler you don't want to block is the Google bot. It is intelligent and notices when it has entered a search loop. But not all crawlers are equally smart and transparent. Some even falsify their user agent. This is often done by competitors who use these crawlers to request your prices and view discounts.

It is not easy to determine which crawlers to block. Lists are available, even on Wikipedia, and by combining them, you can arrive at a suitable mix. Be sure to consider your target audience, as what works in one country may not be applicable in another. Consider, for example, the hotel sector for business bookings.

WHAT CAN YOU DO YOURSELF?

The hosting provider works well for basic protection at a general level. If you want to maintain control yourself or are frequently affected by DDOS attacks, you can make specific adjustments at website level via an intermediary such as CloudFlare.

Would you like to know more about how to secure your website specifically? Be sure to read our blog about how to stop hackers!

Better to prevent than to cure!

So now you know what to expect from hackers and cyber attacks. The conclusion is clear: prevention is better than cure! A good hosting provider will therefore do everything possible to protect your website or webshop against hackers, but unfortunately it is impossible to be completely watertight.

Stay informed

Subscribe to our newsletter and receive the latest updates on our products and services.

By subscribing, you agree to our privacy policy