 knightmbEverybody Lies join:2003-12-01 Franklin, TN | reply to patcat88
Re: should have seen it coming... said by patcat88:said by knightmb:Another easy way to prevent this, don't allow unlimited connection sessions from a single IP What about ISPs in countries that weren't well endowed with IPs where the major ISPs all NAT 1000s or 10000s of users behind 1 IP? what about AOL users behind the AOL proxy? Tough love I'm afraid. The key word is no "unlimited" sessions, even allowing 1,000 would allow all of these people to use it and still keep your web server from drowning in slow connections.
The worst that would happen is people from that ISP would be unable to connect, at least then the firewall logs would reveal where the attack is coming from.  -- Fight Insight Ready (Was NebuAD) and the like: Click Here to pollute their data |