for the techs @ therx

Search
TheGeneral+

TheGeneral+

Another Day, Another Dollar
Joined
Mar 1, 2002
Messages
42,730
Reaction score
0
philosurfer

philosurfer

social engineer
Joined
Feb 8, 2005
Messages
576
Reaction score
0
RRDNS...problem solved.
been in the spam industry for a long time... DDOS.. is for rookies.
 
AdamSelene

AdamSelene

Programmer
Joined
Sep 21, 2004
Messages
3,441
Reaction score
0
Why does Round Robin DNS (?) solve DDOS?

Indeed many attacks I've seen are so poorly orchestrated as to only attack a single IP address and a single TCP port (80). Block port 80 and your site is still accessible by SSL, dev null route the IP address being attacked and update DNS and the attack disappears.

But that's only a solution to extremely poor attack parameters. I wouldn't assume that bot networks will remain so stupid.

Extremely big pipes and a vaste web server farm generally manage to survive attacks.

The honeynet project claims to have tracked 1 million bot infected computers, and witnessed DDOS bot hoards of up to 50,000.

http://www.honeynet.org/

The largest botnet tracked (by iDefense in 2003) was 120,000 infected computers.

It's easy to see how DDOS works. A typical individual web server can only handle about 10,000 requests per second (rps) for static content -- and expoentially worse for server script pages and database-driven content (e.g. ASP, which most sportsbook software uses maxes out at 300-500 rps).
 
wolfie_cr

wolfie_cr

New member
Joined
Sep 20, 2004
Messages
6,066
Reaction score
3
"is for rookies." LOL, thats why it STILL keeps causing big headaches to everyone in the world as well as loses of billions

tell that to the guys of prolexic :p
 
philosurfer

philosurfer

social engineer
Joined
Feb 8, 2005
Messages
576
Reaction score
0
the techs in the sports book industry are not the top of the food chain as many of them would like to believe.

the people writing those botnets just so happen to be friends. and lets say i have a little expierence working with them myself.

every ip packet has a header. that header has a string with an originating location.
now... you say.. well that dont mean **** with a bot net... wrong.
Ip packets can vary in size. Usually DDoS attacks are made from a very generic pattern. With a deccent RRdns (maybe 10 clustered dns servers, its up to you.) program you should be able to read all traffic and if you recieve more than x amount of packets in 3 seconds all with this packet size... well... you get the idea.. its not perfect... But... i keep AOL's DDoS attacks at bay on a daily basis... but still allow their users to view my sites.

And they have a little bit more money, and more staff than my russian friends.

RRdns works.
 
wolfie_cr

wolfie_cr

New member
Joined
Sep 20, 2004
Messages
6,066
Reaction score
3
let me address your comments one by one

"the techs in the sports book industry are not the top of the food chain as many of them would like to believe."

perhaps not, but DDoS STILL cripple sites ALL OVER the world and in developed countries as well

"every ip packet has a header. that header has a string with an originating location." so what? it doesn't matter if the IP number is spoofed or not, with 50000 bots all trying to bring down the site who cares if they are real or not? the router is equally swamped both in processing (CPU) and bandwidth, these people have 100 Mbps and more, that is a very significant % of bandwidth compared to the total that either RACSA or ICE have


so let's see......I write a both with random packet size, perfectly shaped as a normal http get request and its going to be a nice bot so it will spoof the IP so that each bot can use 100 random IPs, so I have say 1000 bots bombarding you with 1000000 IP numbers that I will rotate every minute. now how exactly do you defend against that?
 
wolfie_cr

wolfie_cr

New member
Joined
Sep 20, 2004
Messages
6,066
Reaction score
3
btw in my opinion the problem wouldn't be as bad if every single ISP would implement egress filtering but sadly a lot don't
 

Forum statistics

Threads
1,142,146
Messages
13,929,055
Members
104,842
Latest member
izzy623
The RX is the sports betting industry's leading information portal for bonuses, picks, and sportsbook reviews. Find the best deals offered by a sportsbook in your state and browse our free picks section.FacebookTwitterInstagramContact Usforum@therx.com