Türkce » WHM cPanel

Apache mod_qos ile Dos-dDos koruma

http://forum.whmdestek.com/

Go Back   WHM/cPanel Support Platform » Türkce » WHM cPanel
 

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 30.07.08, 02:29
Ni-Osman's Avatar
Linux HelpDesk
 
Join Date: Feb 2008
Location: Denizli
Posts: 282
Rep Power: 7014
Ni-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond repute
Send a message via MSN to Ni-Osman Send a message via Yahoo to Ni-Osman Send a message via Skype™ to Ni-Osman
Apache mod_qos ile Dos-dDos koruma

Webhosting firmalarinin en büyük problemlerinden birisi rasgele kaynakli saldirilardir. Dos ve dDos su anda web hosting firmalarinin oldugu gibi internetin de cok büyük bir sorunu bu aralar. Soruna kesin cözüm getirmeyen ama en azindan “lamer” tabir edilen saldirganlara karsi gecici bir cözüm olabilecek yazilimlardan birisi de mod_qos dir. Unutmayin, daha iyi korunma daha profesyonel cözümler gerektirir. Bu yazilim simdilik cok yeni ve daha cok yol kat edecek ancak ise yaradigi kanaatine vardik yapitigimiz testlerde. Daha detayli testler ile perfomansini ölcecegiz ve sizinle paylasacagiz Eger siz de kurup denemek isterseniz iste size kisaca bir “howto” Sakin test sonuclarinizi bize de yazmayi unutmayin. Bu kurulum Centos5 , WHM 11.23.2 ve Apache 2.2.8 kurulu bir sunucuda test edilmistir.

Öncelikler cPanel sunucularda genelde bulunmayan ve bu yazilimin ihtiyac duydugu pcre paketlerini kuruyoruz.


yum -y install pcre pcre-devel


Kaynak kodumuzu indiriyoruz, arsivi acip dizine giriyoruz


wget http://garr.dl.sourceforge.net/sourc...7.4-src.tar.gz
tar zxvf mod_qos-7.4-src.tar.gz
cd mod_qos-7.4/apache2/


Modülleri apxs ile derleyip Apache konfigürasyonuna ekliyoruz.


/usr/local/apache/bin/apxs -I/usr/include/pcre/ -iac mod_qos.c
/usr/local/apache/bin/apxs -I/usr/include/pcre/ -iac mod_qos_control.c


simdi mod_qos in kullandigi araclarin derlenmesine geldi. Bunlardan birisi qslog, digeri qsfilter2. Qslog , apache access_log lari inceleyerek istatistik olusturuyor. Kullanmadim ama ilgilenenler icin linki . Qsfilter2 ise yine access loglarini iceleyip , süpheli istekleri engelleyecek kurallari olusturan bir yazilim. cPanel de loglar her virtualhost icin ayri tutuldugu icin sanirim bunu sunucu genelinde kullanmak icin log ayarlarini degistirmek gerekebilir. Umarim bu araclari ileride test edebilir ve sizi bilgilendirebiliriz. simdi kaldigimiz yerden devam edelim.


cd ../tools/
make
cp qslog /usr/local/bin/
cd qsfilter/
nano Makefile


Bu kisimda Makefile iceriginde degisklik yapmamiz gerekmekte. Varsayilan apache kaynak kodlari yolu cPanel sunculardaklinden farkli. O nedenle Makefile icinde gecen tüm “../../httpd” yollarini “/home/cpeasyapache/src/httpd-2.2.8/” olacak sekilde degistiriyoruz. Bu sizin kurulumunuza göre degisiklik gösterebilir.


make
cp qsfilter2 /usr/local/bin
cd /usr/local/apache/conf
nano qos.conf


Olusturdugumuz qos.conf dosyasi mod_qos ayarlarinin yapildigi dosya olacak. cokca ayar secenegi var ancak biz en basitce bu ayarlari kullanacagiz. Kisaca bir kaynak ip adresinden en fazla 10 baglanti kabul edecegiz ve toplam istek limitini virtual host basina 100 ile sinirliyoruz. Unutmayin, her sunucunun konfigürasyonu hit profiline göre degisecektir. En iyi ayarlari kendini bulabilirsiniz.


QSC_WorkingDirectory /var/tmp/qosc
QSC_Filter2Binary /usr/local/bin/qsfilter2
QS_SrvMaxConnPerIP 10
QS_LocRequestLimitDefault 100
<Location /qos>
SetHandler qos-viewer
</Location>


Kaydedip cikiyoruz ve mod_qos gecici dosyalarinin kaydedilecegi klasörü olusturuyoruz.


mkdir -p /var/tmp/qosc
chown nobody:nobody /var/tmp/qosc

Son olarak qos.conf u ayar dosyamiza Include ile ekliyoruz ve servisi yeniden baslatiyoruz.
nano httpd.conf
su satiri Include direktiflerinden birinin oldugu kisman yazin

Include "/usr/local/apache/conf/qos.conf"
service httpd restart


http://ip_adresiniz/qos linki ile mod_qos calismasi ile ilgili bilgi alabileceginiz bir sayfaya ulasabilirsiniz. Bunu sadece test ortaminda acik tutmanizi öneririm. isiniz bitince qos.conf icindeki <Location /qos> direktiflerini kaldirin.
Umarim isinizi görecektir. Bu en basit ayarlari ile kurulmus halidir. Daha ayrintili ayarlari mod_qos dan bulabilirsiniz.

Unutmadan yazayim. “Caution! Use it on your own risk!”



Apache mod_qos ile Dos-dDos koruma | linux10.net
__________________
Netinternet'i sosyal paylaşım ağlarından takip edin kampanyalardan ilk haberi siz alın!!
Facebook | twitter | friendfeed
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2  
Old 30.07.08, 04:25
HoST13's Avatar
Athlon Dual Core
 
Join Date: Jan 2008
Location: Trabzon
Age: 20
Posts: 335
Rep Power: 3
HoST13 will become famous soon enough
Send a message via MSN to HoST13
osman abi o kadar dedim sana gel su linux sitesine forum kuralim ama yok
istersen hala kurabilirim.
__________________
WHMCS Destek | MyBB Destek
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3  
Old 30.07.08, 12:16
Ni-Osman's Avatar
Linux HelpDesk
 
Join Date: Feb 2008
Location: Denizli
Posts: 282
Rep Power: 7014
Ni-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond repute
Send a message via MSN to Ni-Osman Send a message via Yahoo to Ni-Osman Send a message via Skype™ to Ni-Osman
Forumumuz var iste burasi
__________________
Netinternet'i sosyal paylaşım ağlarından takip edin kampanyalardan ilk haberi siz alın!!
Facebook | twitter | friendfeed
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #4  
Old 30.07.08, 13:30
CaLViN's Avatar
Sevgi güctür.
 
Join Date: Apr 2007
Location: Outta nation
Age: 28
Posts: 2,070
Rep Power: 100000
CaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond repute
burasi hepimizin forumu
__________________
1.)Lütfen destek talebinde bulunmak icin özel mesaj ile iletisime gecmeyiniz.
2.)Ücretsiz destek almak icin forum sayfalarimizi kullanmaniz ayni sorunu yasayan diger üyelerin cevaplara en kisa sürede ulasabilmesi ve sizlere yardimci olmak isteyen bizlerin ve diger üyelerimizin zaman kazanmalari acisindan cok önemlidir.
3.)Forumlarimizda sorunlarinizi anlatirken mümkün oldugunca cok detay vermeniz en kisa sürede sorununuza cözüm bulmaniz acisindan mühimdir.

Daha cok ögrenmek ve ögretmek dilegiyle..
Sevgiler..
The Platform.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5  
Old 30.07.08, 14:40
Onur's Avatar
Peynir
 
Join Date: Jun 2007
Location: Karaman
Age: 21
Posts: 1,587
Rep Power: 100000
Onur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond repute
Quote:
Originally Posted by HoST13 View Post
osman abi o kadar dedim sana gel su linux sitesine forum kuralim ama yok
istersen hala kurabilirim.
Forum vardi zaten uzun zamandir o sitede
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6  
Old 30.07.08, 15:51
SeLeNa's Avatar
Celeron
 
Join Date: Jul 2008
Posts: 77
Rep Power: 2
SeLeNa is on a distinguished road
apache serv restart attiktan sonra acilmaz oldu siteler yardim pls
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #7  
Old 30.07.08, 16:02
SeLeNa's Avatar
Celeron
 
Join Date: Jul 2008
Posts: 77
Rep Power: 2
SeLeNa is on a distinguished road
bu kurdugumuz sey apache acilirken hata verdirtiyor nasil sile bilirim bunu yardim eder misiniz sitelerin hic biri acilmiyor apache server acilmiyor
__________________
Linux irc systems
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #8  
Old 30.07.08, 21:07
Onur's Avatar
Peynir
 
Join Date: Jun 2007
Location: Karaman
Age: 21
Posts: 1,587
Rep Power: 100000
Onur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond reputeOnur has a reputation beyond repute
service httpd restart

deyince cikan hatayi buraya yazabilirmisiniz ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #9  
Old 31.07.08, 01:14
Media Servers Projector
 
Join Date: Oct 2007
Location: istanbul
Posts: 1,035
Rep Power: 2014
HalidAltuner has a reputation beyond reputeHalidAltuner has a reputation beyond reputeHalidAltuner has a reputation beyond reputeHalidAltuner has a reputation beyond reputeHalidAltuner has a reputation beyond reputeHalidAltuner has a reputation beyond reputeHalidAltuner has a reputation beyond reputeHalidAltuner has a reputation beyond reputeHalidAltuner has a reputation beyond reputeHalidAltuner has a reputation beyond reputeHalidAltuner has a reputation beyond repute
Send a message via MSN to HalidAltuner Send a message via Yahoo to HalidAltuner
Muhahaha osman abiyi mahkemeye verecekler
__________________
Linux System Administrator
[via]
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #10  
Old 31.07.08, 01:17
HoST13's Avatar
Athlon Dual Core
 
Join Date: Jan 2008
Location: Trabzon
Age: 20
Posts: 335
Rep Power: 3
HoST13 will become famous soon enough
Send a message via MSN to HoST13
yok bi ara r10da bi konu vardi o yüzden söyledim
__________________
WHMCS Destek | MyBB Destek
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
inetbase ddos koruma (Kurulum) Onursal WHM cPanel 27 19.04.09 12:42
Flood Koruma djmakay WHM cPanel 2 23.07.08 20:52
DDoS Protected - DDoS korumali Sunucu - Hosting nereden alinir ? CaLViN WHM cPanel 25 17.05.08 05:18
ddos korumasi KORAL WHM cPanel 2 14.04.08 18:53
SYN Saldirilar : Engelleme ve Koruma CaLViN WHM cPanel 5 24.08.07 00:26



netinternet

Navigasyon
Menü