РУССКИЙ ВОЕННЫЙ КОРАБЛЬ, ИДИ НА ХУЙМИ ПРАЦЮЄМО ДЛЯ УКРАЇНИ

Khmelnitsky, Zarichanska Street, 3/1,
floor 2, office 207

Installing CloudFlare for the OTM GROUP website

Installing CloudFlare for the OTM GROUP website

Client information

OTM GROUP is a professional company providing a wide range of services and engineering solutions in the field of ventilation, air conditioning and heating.

CLIENT REQUEST

A client contacted us with the fact that his advertising account stopped working and the pages of the site where advertising was conducted became unavailable. He asked us to understand the problem and solve it. Our first task is to conduct diagnostics to find out the root cause. This will allow us to quickly determine the further plan of action and resume the work of advertising campaigns.

Вводные данные Input data

Market:

Ukraine

Niche:

Engineering solutions in the field of ventilation, air conditioning and heating.

Какие проводились работы Progress of work

So, after the client’s request, we immediately checked the website and found that it was loading endlessly and sometimes wouldn’t open at all. Subsequently, the client received an email from the hosting provider notifying them of a temporary access restriction due to an excessive number of requests. This was the first alarming signal.

Diagnosis: Identifying a DDoS Attack

We immediately analyzed the situation. Access to the server logs was difficult, but we managed to get some data through the hosting control panel. This is what we found:

DDoS attack

  • Anomalous number of requests: Under normal conditions, the website had 100-200 unique visitors per hour. At the time of the attack, the number of requests reached over 1000 requests per second.
  • Distributed nature: The requests came from thousands of different IP addresses worldwide. This ruled out the possibility of blocking one or a few addresses and confirmed that it was a DDoS attack.
  • Attack type: Most requests were directed to static pages, which indicated an HTTP flood (overloading the server with simple GET/POST requests). This is a simple but effective method of DDoS attack that does not require much power from the attackers.

The hosting capacity purchased by the client was simply not enough to handle such a load. As a result, to protect their servers, the hosting provider was forced to limit access to the website, which led to its complete downtime.

Solution Implementation: Phased Deployment of Cloudflare

To solve the problem, we chose Cloudflare as the main protection tool. This service acts as an intermediate layer between the user and the server, allowing malicious traffic to be filtered out before it even reaches the hosting.

Cloudflare protection

Step 1: Changing DNS records. We changed the domain’s NS records (Name Server) to those provided by Cloudflare. This redirects all traffic through their global network. At this stage, the client’s site remained inaccessible, but we were already laying the groundwork for protection.

Step 2: Configuring basic DDoS protection. After changing the DNS records, we activated the «I’m Under Attack Mode» in Cloudflare. This is a temporary but powerful solution that includes additional checks for all visitors (e.g., showing a CAPTCHA or a JavaScript check) to filter out bots.

Step 3: Implementing Web Application Firewall (WAF) rules. We created special Web Application Firewall (WAF) rules that blocked requests matching the characteristic patterns of a DDoS attack. For example, we set a limit on the number of requests from a single IP address to 1 request per 60 seconds. This effectively stopped the flood without harming legitimate users.

Step 4: Optimization and adaptation. After the DDoS attack was repelled, we turned off the «I’m Under Attack» mode and moved to a more flexible configuration. We set the “Security Level” to “High,” which allowed Cloudflare to automatically block suspicious visitors based on their behavior and history. If Cloudflare notices an anomalous surge in traffic, it automatically activates additional checks, protecting the site from new attacks.

Полученный результат Result obtained

Following the phased implementation of protective measures, we not only solved the problem but also significantly strengthened OTM GRUP’s online presence. Just a few hours after changing the DNS records and configuring the WAF, we recorded the first positive changes:

  1. Immediate DDoS attack mitigation. The Cloudflare system intercepted and effectively filtered out all malicious traffic that had previously overloaded the server. More than 99% of requests coming from bots were blocked before they even reached the hosting. This instantly reduced the server load and allowed the hosting provider to lift the restrictions.
  2. Full website availability restored. After the restrictions were lifted, the website returned to normal operation. All pages, including those that were unavailable for advertising campaigns, began to load quickly and stably.
  3. Advertising campaigns resumed. Since the landing pages became available, we were able to resume advertising campaigns in Google Ads and other systems. This allowed us to restore the flow of targeted traffic and conversions that were lost during the downtime.
  4. Increased loading speed. As an added bonus, Cloudflare sped up the website’s loading. Using their global Content Delivery Network (CDN) allowed static files (images, CSS, JavaScript) to be cached and delivered to users from the nearest server. As a result, the website’s loading speed metrics significantly improved.
  5. Long-term protection. The most important result was that the client received not a one-time solution, but a permanent, reliable protection. Now, if someone tries to repeat the attack, Cloudflare will automatically repel it. The system monitors traffic in real-time and responds to any anomalies, ensuring stable website operation 24/7.

Thus, the DDoS attack incident became an opportunity to strengthen the technical infrastructure and ensure the uninterrupted operation of OTM GRUP’s online business for the future.

Are you facing a similar problem or want to prevent it in the future?

Don’t let DDoS attacks stop your sales and damage your reputation. If your website is under threat or you want to protect it from future attacks, contact us. We have the experience and the necessary tools to ensure its reliable operation.

Has your site been attacked by DDoS? Or do you want to avoid it in the future? Contact us for help!