I was.
One of my main websites was hacked two weeks ago. It got attacked by a denial of service attack. Let’s just say it wasn’t good week. The attack took my site down for almost a week. At the end I had to get all sort of new services, move my hosting account, and spend a good amount of money to get it back.
Here is what I did, in case you are under attack right now:
Hosting Provider
Your most powerful weapon is your hosting account provider. They are responsible for stopping the denial of service attacks through their switches, routers, and software that they have installed on their servers.
The attack on my site was pretty sophisticated. It was from all spoofed IP address and they all actually looked legitimate IP addresses. The amount of the attack was huge too. That being said I was not happy when my old hosting provider told me I just have to wait it out and they can’t do anything. My new hosting provide (HostGator) wasn’t successful at stopping the attack right away but they tried and tried and kept me in the loop on what they were doing. At the end they did stop it.
I had two hosting accounts with HostGator before I was already very happy with them, just never got around movingt this other website. Now I have a my third account which is VPS hosting at about $80 a month and I am very happy with it.
Block IP Addresses
When browsing IP addresses of the flood of traffic there were a lot of them from Middle East and South East Asia. So I blocked bunch of countries IP addresses in that area. It helped a little bit. You can’t block too many countries because the IP block list can get fairly long and actually considerably slow down your site.
Use CloudFlare Service
Have your hosting provider set you up with CloudFlare. Your traffic would be re-routed through CloudFlare and only “good” traffic will be able to pass through to your website. This didn’t stop the attack for me but helped a lot. (and they are cheap comparing to the other services online).
User Other (Expensive) DDOS Protection Services
There are other DDOS protection services that can cost you $1000 to $15000 a month. Some of them are VeriSign, Prolexic, and DDOS Arrest,
File a Report with FBI
Do report the incident to FBI Cyber Crime Investigation Unit. Most of the time they won’t reply since your case might be small but at least if it happens again there is a record that you reported it the time before.
Don’t Worry About Ranking
If you have a good website and has great ranking in search engines (like mine), don’t worry about getting your ranking back. Once your site is back online you’ll get your rankings back. My site was actually completely dropped out of search engines during the week of attack and now I have my full ranking back.
I just finished listening to Crucial Confrontations by Kerry Patterson, Joseph Grenny, Ron McMillan, and Al Switzler. It was a great book and definitely on my re-listen list. Book talks about how to battle tough conversations.





