DDoS attack: what it is and how we fought hackers


How we repelled the attack
It all started when, on the morning of October 21st, we noticed unusually high activity on one of our client's websites. Thousands of search engine crawlers began accessing the interior design studio's website. This caused all websites hosted on the same server as the one being attacked to load slowly. It became clear that the attackers were masquerading as search engine crawlers—we were under a DDoS attack

 

Blocking the crawlers is easy, but it worked for about an hour. The attackers realized something was wrong and changed their tactics. We began receiving requests masquerading as users: they contained browser information and couldn't be blocked. So, we tried blocking IP addresses directly—the unique addresses of the computers sending the suspicious requests. But our opponents quickly changed them and sent even more requests from all over the world.

The war continued until evening. Despite the might of the "enemy artillery," the hackers were unable to completely shut down the server. But the load on it was colossal, causing websites to take a very long time to open.

By eight o'clock in the evening, the number of blocked addresses had exceeded a thousand. Our own resources were no longer sufficient. So, we decided to integrate a third-party service, CloudFlare, to filter requests. The service acts as a sieve: all traffic passes through their centers and is filtered—bots and suspicious accounts are blocked, while ordinary users can easily access the server where the website is hosted. This way, the attacked website will have less impact on the operation of other websites on the server.

Fortunately, the client whose website was being attacked had purchased a domain from us and delegated management rights to our platform. Therefore, we were able to quickly make changes to the settings and create a CloudFlare account.

We saw fewer and fewer requests reaching our server. The websites began to recover, and the main battle was now on CloudFlare's side.

The attacks continued until 5 a.m., peaking at 2 a.m. Moscow time. CloudFlare recorded 124.5 million requests. However, we didn't enable it immediately, so the actual scale of the attack is approximately twice as large!

At 6:00 AM, our opponents made another attempt: approximately 1.3 million bots visited the site. But compared to yesterday's battle, this attempt pales in comparison.

During the attack, CloudFlare processed over 1 TB of traffic. That's a lot:

In Conclusion
Unfortunately, hacker attacks have become a modern reality: competition is fierce, and not all companies use honest methods. Most attacks go unnoticed. We successfully combat them almost every day—it's the mundane, routine work of our technical specialists. But this time, the attack was on a completely different scale.

Unfortunately, no one is immune to such attacks, and even the largest websites sometimes become completely disabled. Otherwise, giants like Google or Amazon wouldn't periodically announce vulnerability search contests with millions in prizes.


Go back
19-09-2025, 06:08