[Full-disclosure] IOSEC HTTP Anti Flood/DoS Security Gateway Module (PHP Script)



http://sourceforge.net/projects/iosec/

This module provides security enhancements against (HTTP) Flood & Brute
Force Attacks for native PHP or .NET scripts at web application level.
Massive crawling/scanning tools, HTTP flood tools can be detected and
blocked by this module via htaccess or iptables, etc.

You can use this module by including "iosec.php" to any PHP file which wants
to be protected.

You can test module here: http://www.iosec.org/test.php (demo)

Wordpress Plugin
http://wordpress.org/extend/plugins/iosec-anti-flood-security-gateway-module

CHANGES v.1.7
- Request Cache Size Option
- Improved Implicit Deny Mode
- Excluded Files Support
- Admin GUI Removed
- Config File Removed
- Connection Limit Support
- Whitelist Support
- Reverse Proxy Support
- reCAPTCHA Support

This is a unique project and it is the world's first web application flood
guard script.
At web application (scripting) level you can,
- Block proxies. (only via HTTP header)
- Detect flooding IP addresses.
- Slow down or restrict access for automated tools (HTTP flood, brute force
tools, vulnerability scanners, etc.)
- Save your server resources (database, cpu, ram, etc.) under an attack.
- Restrict access permanently or temporarily for listed IP addresses in
"banlist" file.
- Notify yourself via email alerts when attacks begin.
- Implicit deny for DDoS attacks

You can use IOSEC under .NET see. http://phalanger.codeplex.com/

Gokhan Muharremoglu

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: DDoS attacks ... identifying destination ...
    ... "DoSDetector analyzes and detects suspicious IP traffic and alerts about it. ... It can detect worm traffic, SYN flood, icmp flood, udp flood attacks and more. ... Confidentiality Notice: This e-mail message (including any attached or ...
    (freebsd-net)
  • Re: New newsgroup problem
    ... and secondarily wants to flood newsgroups who ... Hipcrime vandalized ... Periodic waves of attacks, each growing more ...
    (rec.arts.sf.written)
  • Re: RV: Monitor program execution
    ... I would like to know if exist another program to control and monitor any ... kind of execution of a program with access to full instalation: ... What communications generate: ftp, telnet, http, https, ... Cross site scripting and other web attacks before hackers do! ...
    (Pen-Test)
  • RE: detecting network crowd surges
    ... HTTP library for Delphi used by the bot developer. ... Bots are very noisy and non-friendly entities online. ... The difference you notice is the mass "popular" attacks becoming less ... with real-world attacks from CORE IMPACT. ...
    (Focus-IDS)
  • RV: Monitor program execution
    ... kind of execution of a program with access to full instalation: ... ftp, telnet, http, https, ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
    (Pen-Test)