forumNew topic

Your site is under heavy attack — DDoS. Access is down, customers are upset. What should I do?

HHasan Ö***MemberCommunity member
Joined
Dec 2025
Message
50
#1

Can't access the site — connection timeout error, speed is super slow. Network admin said 'there's a DDoS attack'. What is this? How many minutes/hours does it last?

What can I do against DDoS? Firewall, CDN... what helps? Any immediate steps to take?

Does the police handle DDoS? Can they find the attacker? Does insurance cover it?

HHakan Ö***MemberCommunity member
Joined
Feb 2025
Message
375
Most Helpful#2

DDoS (Distributed Denial of Service): Traffic bombardment (overload) on a single server from thousands of bots/machines. Duration: minutes — weeks (typically 4-48 hours). Mitigation: 1) ISP notification (report to hosting provider, ISP-level filtering), 2) Firewall rate limiting (syn floods → threshold, connection limits), 3) CDN (Cloudflare, Akamai): anycast network, traffic scrubbing (legitimate traffic passes, bot traffic dropped), 4) DDoS mitigation service (subscription: $300-5000/month), 5) Application-level: CAPTCHA (filter bots), API rate limiting, geographic blocking (attack source). Diagnosis: NetFlow data (traffic pattern), sudden bandwidth spike, asymmetric response (connection fails but server is normal). Types: Volume-based (bandwidth consumption: UDP flood, DNS amplification), Protocol-based (TCP/IP vulnerability: SYN flood, fragmented packets), Application-based (HTTP flood, Slowloris). Insurance: integrate cyber insurance — business interruption coverage, ransom coverage (if extortion), DDoS mitigation service cost reimbursement. Police: can file a complaint (Turkish Penal Code article 207 — attack on system integrity), but attribution (who the attacker is) is very difficult, requires ISP IP logs (wait for weeks).

MMehmet Ç***MemberCommunity member
Joined
Apr 2023
Message
277
#3

if its a ddos attack, the server is normal, network is congested. set up cdn (start with cloudflare free tier), enable rate limiting file a police complaint. attribution is hard but insurance covers mitigation costs...

PPolat G***Member
Job title
Graphic Designer
Sector
Law
Organization type
workshop
Joined
Nov 2023
Message
29

Doki · SEO consulting · 2023

#4

DDoS detection: Monitoring (bandwidth spike detection — MRTG, Grafana alerts), NetFlow analysis (traffic pattern: UDP flood = high packets/low bytes), Log analysis (sudden spike in access.log, low unique IPs). Mitigation tools: UFW rate limiting (ufw limit 80/tcp), Fail2ban (auto IP blocking after threshold), iptables (syn-flood protection: tcp-syn-cookies), Cloudflare WAF (app-level bot detection), AWS Shield (network-level mitigation). DDoS-as-a-Service detection: attack pattern (botnet signature), command-and-control infrastructure, ransom email (if extortion exists). Response procedure: 1) Detection (alert trigger), 2) Enable CDN/mitigation service, 3) Notification (customer comms: under attack, service restoration ETA), 4) Investigation (forensics: attack vector, attacker motivation), 5) Hardening (future prevention), 6) Recovery (service restoration, business continuity).

DDilanNew member
Job title
Boutique store
Joined
Oct 2024
Message
32
#5

Set up CDN immediately, start Cloudflare. Enable firewall rate limiting. Once the DDoS is over, send an email to customers — notifying them that you were under attack and things are back to normal. File a claim with insurance requesting mitigation costs. Also start a police report...

edit: I wrote something wrong above, sorry about that.

ZZehra A***Expert
Job title
Hotel owner
Organization type
regional distributor
Joined
May 2023
Message
184

Doki · E-commerce infrastructure · 2025

#6

DDoS response playbook: 1) Detection & verification (confirm attack ensure it's not a legit traffic spike) 2) Incident escalation (notify ISP, enable DDoS service), 3) Communication (customer notification, status page updates, social media), 4) Mitigation (enable CDN rate limiting, geo-blocking), 5) Investigation (attack pattern analysis, attacker motivation) 6) Resolution (attack stopped services restored) 7) Post-incident review (lessons learned, prevention upgrades). Prevention: DDoS-resistant architecture (distributed servers, load balancing), redundancy (multiple ISPs backup infrastructure), insurance (DDoS coverage $2M+ depending on policy).

ZZeynep K***Expert
Job title
Marketing manager
Sector
Textile
Organization type
two-branch business
Joined
Nov 2023
Message
330
#7

I didn't know that. If 2FA is on, a stolen password alone is useless.

Good luck with that.

OOya Ç***Member
Job title
Quality control inspector
Sector
Media and publishing
Organization type
regional distributor
Joined
Oct 2023
Message
248
#8

i think it's hard to be that definitive about i'm uder a ddos attack and hasty decisions become decisions you have to fix six months later.

that's all sorry if I went on too long.

GGamze S***Member
Job title
Production Manager
Sector
Advertising and promotion
Organization type
300-person organization
Joined
May 2024
Message
5

Doki · Vulnerability scanning · 2025

#9

The most overlooked point about i'm under a ddos attack is this: Having backups accessible on the same network and with the same identity makes them part of the target.

Im also curious if anyone does it differently.

OOya O***Member
Job title
Accounting clerk
Sector
Media and publishing
Organization type
two-branch business
Joined
Dec 2024
Message
113
#10

I can't fully agree with this. Payment information changes are never verified through the channel they came from.

If I were you, I'd go this route.

TTanerMember
Job title
Construction company
Joined
Oct 2023
Message
68
#11

Same here.

UUfuk G***New member
Job title
General coordinator
Sector
IT services
Organization type
regional distributor
Joined
Jun 2026
Message
188

Doki · Backup setup · 2026

#12

i'm writing this so you don't make the same mistake. the biggest time-waster for us was not knowing who had the final say.

GGülMember
Job title
Fashion brand
Organization type
40-person manufacturing company
Joined
Nov 2023
Message
128
#13

i can't fully agree with this. taking measures without an inventory leaves doors you haven't seen open.

the harder it is to reverse a decision, the slower you should make it and this is my opinion Im not claiming its absolute truth.

SSelin C***Member
Job title
Secretary
Sector
Law
Organization type
40-person manufacturing company
Joined
Jul 2025
Message
6
#14

Let me write how it's done in practice. Everything goes well for the first three months; problems arise in the fourth.

Hasty decisions become decisions you have to fix six months later. This is my opinion, I'm not claiming it's absolute truth.

ZZafer Y***Expert
Job title
Software team lead
Sector
Jewelry
Organization type
8-person team
Joined
Jun 2023
Message
214
#15

Noted, thanks.

KKoray B***ExpertCommunity member
Joined
Jan 2023
Message
235
#16

Great work. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

If you have questions, write them; I'll answer as best I can.

AAlper Ç***Member
Job title
Customer service representative
Sector
Freight
Organization type
120-person company
Joined
Jul 2024
Message
41
#17

Correct in theory, but it doesn't work that way in practice. Your time to detect an issue directly determines its cost.

That's all, sorry if I went on too long.

MMetin D***Veteran
Job title
Marketing director
Sector
Software
Organization type
20-person company
Joined
Aug 2023
Message
22

Doki · Infrastructure migration · 2026

#18

The discussion got scattered let me summarize. If 2FA is on, a stolen password alone is useless.

If I were you, Id go this route.

YYiğit Y***New member
Job title
Secretary
Sector
Logistics
Organization type
chain store
Joined
May 2026
Message
17
#19

I feel the same way. When we decide without measuring, we always end up in the same place.

Good luck with that.

RRamazan K***MemberCommunity member
Joined
Jul 2023
Message
102
#20

I went through the same thing two years ago. Don't rely on a single measure; go layer by layer.

Reply