you are viewing a single comment's thread.

view the rest of the comments →

[–]theoracle 4 insightful - 2 fun4 insightful - 1 fun5 insightful - 2 fun -  (2 children)

It has been a rough day for DOSing.

Best protection at the site I think is to force a gateway page with an extremely simple captcha. Like you have on the signup, but maybe simpler. What ever will stop bots but not form an attack vector itself. Use it to deny access to the rest of the site until they pass the captcha. You can limit attempts and also only have the page enable once a certain bandwidth or connection limit is passed, so people usually don't see it.

[–]magnora7[S] 6 insightful - 2 fun6 insightful - 1 fun7 insightful - 2 fun -  (1 child)

Good ideas, but cloudflare actually already does most of those exact things for us.

Even during the DDOS I was having to click pictures of umbrellas and airplanes to get past the Cloudflare wall because I had connected so many times, haha

[–]theoracle 4 insightful - 1 fun4 insightful - 0 fun5 insightful - 1 fun -  (0 children)

Yes you are right they do do that! It didn't come to my mind though when I was suggesting it. I guess if you don't use Cloudflare it's an option.