Site has been under a massive DDOS attack for 5 weeks now

The people who track down DDoS attackers tend to hang out on mailing lists, so your best bet is to search/google for a mailing list using some DDoS related keywords. The reason that the attack is highly distributed is because the attack traffic is coming from a botnet.

There are people who spend a lot of time investigating these botnets and figuring out where the control channel is. If they can crack the control channel, then they can shut the whole thing down. Unfortunately, some attackers just buy a new botnet, or build up their own, and continue attacking.

If you are lucky, you will be able to find a security expert who is interested in collecting your attack data and able to do something about it. They will be interested in a list of every IP address that sends attack, some sample packet captures of different attack modes, and any stats on the attacks.

Try looking at Securiteam particularly on the blogs. Or Google for "Gadi Evron" and see where he hangs out. If you were in the USA I would suggest reporting it to CERT but you are in Canada so try CanCERT.


If your costs are increasing do to the DDOS attack you can try contacting the FBI (assuming you or your website are US based). It's costing you money to deal with this which makes it something that they can look into if they feel inclined. It probably won't be an easy road. If you aren't in the US check with local law enforcement to see if they can assist in any way.