New RDDOS Attack

Discuss anything not covered in another forum (life, the universe etc.)... Please keep it PG-13 and avoid spam.
Post Reply
User avatar
ColdFusion
Posts: 3542
Joined: Mon Oct 30, 2000 12:00 am
Location: Vancouver, BC

New RDDOS Attack

Post by ColdFusion »

Heh just reading on a new denial of service attack called "RDDOS".

For those of you that are unframiliar with what a "DDOS" attack is, it is an attack directed at a specifc host, from many computer sending as much possible data to a host. usually what happens, is the ammount of data being generated and sent to a host is more than the host can handle, therefor it can no longer accept any more "important" packets, and you have a denial of service.

Now a RDDOS attack is quite interesting. Every packet that you send has a header. And in that header contains some info including your ip address. This way, lets say when you send a request to yahoo.com, yahoo.com reads the header, and sends the data back to the ip address in the header, and then you see the webpage. But! With windows XP (not sure about NT, or 2k) it allows you to send raw packets. Which means you can change the ip in the header. Now this can all be done with one user allone. What he does, it sends out requests to major fast websites, and spoofs the ip address, to the ip of his victim. Now that can hold them down for not too long, but long enough. Next what he does, is he gets all his bots to do this. So you got 400 bots sending a request to yahoo.com, microsoft.com ... ect up to lets say 1000, and then repeating ... well im sure you can hold down a website with that kynda data!

Interesing eh! you can find more info ! grc.com
User avatar
ghost
SG VIP
Posts: 11599
Joined: Wed Oct 20, 1999 12:00 am
Location: Virginia

Post by ghost »

Yeah, Steve's site is a good one. I remember when he got attacked.
User avatar
Juggernaut
Senior Member
Posts: 1645
Joined: Fri Aug 11, 2000 12:00 am
Location: Parts Unknown

Post by Juggernaut »

ya XP deals with raw packets....so does Linux tho
Image
It can't rain all the time...
User avatar
Bouncer
Senior Member
Posts: 4834
Joined: Thu Oct 14, 1999 12:00 pm
Location: OCONUS

Post by Bouncer »

Oh no, we have the assurances of microsoft and ythe reporter from The register that not only can this not happen, but that Gibson just makes up everything.

:/

Scuse me while I go check for yet another MS security hole fix.

Regards,
-Bouncer-
CiscoKid
Posts: 10031
Joined: Tue Jan 09, 2001 12:00 am
Location: Stockton, CA

Post by CiscoKid »

I've always said ?I wonder if..." then do a search only to discover my concerns were justified...
Three Rivers Designs wrote:America! Love it or give it back!
Post Reply