The real reason for large DDoS attacks? It's IP Spoofing, not memcached
blog.cloudflare.com
The real reason for large DDoS attacks? It's IP Spoofing, not memcached
1–10 of 38 posts
Re: The real reason for large DDoS attacks? It's IP Spoofing, not memcached
#2Because all traffic is treated at face value and not deep filtered and throttled according to some company's whims.
Cloudflare wants to change this. Cloudflare wants centralization. Cloudflare wants blacklists.
Re: The real reason for large DDoS attacks? It's IP Spoofing, not memcached
#3>Let's take a deep breath and discuss why such large DDoS attacks are even possible on the modern internet. Because all traffic is treated at face value and not deep filtered and throttled according to some company's whims. Cloudflare wants to change this. Cloudflare wants centralization. Cloudflare wants blacklists.
Re: The real reason for large DDoS attacks? It's IP Spoofing, not memcached
#4For example, on the server side, BGP hijacking and anycast routing are enabled by the same bug or feature, depending how you look at it.
Re: The real reason for large DDoS attacks? It's IP Spoofing, not memcached
#5>Let's take a deep breath and discuss why such large DDoS attacks are even possible on the modern internet. Because all traffic is treated at face value and not deep filtered and throttled according to some company's whims. Cloudflare wants to change this. Cloudflare wants centralization. Cloudflare wants blacklists.
Re: The real reason for large DDoS attacks? It's IP Spoofing, not memcached
#6>Let's take a deep breath and discuss why such large DDoS attacks are even possible on the modern internet. Because all traffic is treated at face value and not deep filtered and throttled according to some company's whims. Cloudflare wants to change this. Cloudflare wants centralization. Cloudflare wants blacklists.
Re: The real reason for large DDoS attacks? It's IP Spoofing, not memcached
#7>Let's take a deep breath and discuss why such large DDoS attacks are even possible on the modern internet. Because all traffic is treated at face value and not deep filtered and throttled according to some company's whims. Cloudflare wants to change this. Cloudflare wants centralization. Cloudflare wants blacklists.
Is egress filtering really that egregious?
Re: The real reason for large DDoS attacks? It's IP Spoofing, not memcached
#8Are there any valid technical use-cases for IP spoofing? i.e. setting the source address of a UDP packet as one outside the originating network? For example, on the server side, BGP hijacking and anycast routing are enabled by the same bug or feature, depending how you look at it.
Re: The real reason for large DDoS attacks? It's IP Spoofing, not memcached
#9Are there any valid technical use-cases for IP spoofing? i.e. setting the source address of a UDP packet as one outside the originating network? For example, on the server side, BGP hijacking and anycast routing are enabled by the same bug or feature, depending how you look at it.
Testing?
Re: The real reason for large DDoS attacks? It's IP Spoofing, not memcached
#10Earlier quoted context omitted.
Is egress filtering really that egregious?
No, it's not. It's just time consuming. If you're a large ISP with several disconnected IP subnets, then it's hard to get right.
"ip verify unicast source reachable-via rx" in the Cisco world.