Yesterday I noticed some suspicous activity when running
netstat | grep http on my Azure Ubuntu VM:
There were over 60 lines like this:
tcp 0 0 ser:http hosted-by.blazing:29248 SYN_RECV tcp 0 0 ser:http hosted-by.blazingf:59438 SYN_RECV tcp 0 0 ser:http 18.104.22.168:7057 SYN_RECV # [SNIP]
I am guessing this is a SYN flood attack, and given the presense of
22.214.171.124 possibly some IP Spoofing? I don’t have any DDOS protection from Azure, just a standard Ubuntu VM. I tried a few things:
Uncommented the line
/etc/sysctl.conf and ran
sysctl -p but the above packets continued.
I already have my own iptables script in place, to lock the server down a bit. Whilst checking over this script, I noticed some unrelated lines in
INFO Exception processing GoalState-related files: [ProtocolError] [Wireserver Exception] [HttpError] [HTTP Failed] GET http://126.96.36.199/machine/?comp=goalstate -- IOError timed out -- 6 attempts made
Some investigation into this IP, shows that it’s part of Azure’s infastructure, so I went ahead and added this to my firewall script, to allow outgoing traffic to this IP on port 80.
Suddenly the earlier SYN traffic stopped.
Is this just chance, or would allowing traffic out to
188.8.131.52 somehow start providing some protection against this attack, even without any DDOS protection enabled through Azure portal?
✓ Extra quality
ExtraProxies brings the best proxy quality for you with our private and reliable proxies
✓ Extra anonymity
Top level of anonymity and 100% safe proxies – this is what you get with every proxy package
✓ Extra speed
1,ooo mb/s proxy servers speed – we are way better than others – just enjoy our proxies!
USA proxy location
We offer premium quality USA private proxies – the most essential proxies you can ever want from USA
Our proxies have TOP level of anonymity + Elite quality, so you are always safe and secure with your proxies
Use your proxies as much as you want – we have no limits for data transfer and bandwidth, unlimited usage!
Superb fast proxy servers with 1,000 mb/s speed – sit back and enjoy your lightning fast private proxies!
99,9% servers uptime
Alive and working proxies all the time – we are taking care of our servers so you can use them without any problems
No usage restrictions
You have freedom to use your proxies with every software, browser or website you want without restrictions
Perfect for SEO
We are 100% friendly with all SEO tasks as well as internet marketing – feel the power with our proxies
Buy more proxies and get better price – we offer various proxy packages with great deals and discounts
We are working 24/7 to bring the best proxy experience for you – we are glad to help and assist you!