Can anyone shed some light on why someone would go out of their way to conduct an attack like this? Is DoSing production web applications just a hobby for black hat jackasses with nothing better to do?
Jerks on the Internet: what my first DDoS taught me
61–70 of 95 posts
Re: Jerks on the Internet: what my first DDoS taught me
#62 curl -k https://134.209.46.107/products/ -H "Host: api.getmakerlog.com"Re: Jerks on the Internet: what my first DDoS taught me
#63Can anyone shed some light on why someone would go out of their way to conduct an attack like this? Is DoSing production web applications just a hobby for black hat jackasses with nothing better to do?
I guess humans are closer to monkeys than we like to believe and still like throwing poop at each other.
Re: Jerks on the Internet: what my first DDoS taught me
#64Earlier quoted context omitted.
It’s not used because any serious attack is going to come from multiple unrelated sources, think a botnet full of compromised IoT devices hitting your server with 20TB a second worth of requests. So you might as well plan for that scenario instead.
That's an entirely different kind of attack. If your server is being flooded with 20TB/s of traffic, there's nothing you can do on the box itself to fix things. Whatever you do, the legitimate requests won't be able to get through. If however your DOS attack is an attacker making lower-volume CPU-expensive requests on your site, there's plenty of things to help mitigate the assault.
Re: Jerks on the Internet: what my first DDoS taught me
#65Earlier quoted context omitted.
Those requests seldom get far enough to start significant server activity. It's the ones that look like legit requests that are the problem.
Seldom isn’t good enough. When it comes to security you have to be right 100% of the time. An attacker only has to be right once. Good luck.
Re: Jerks on the Internet: what my first DDoS taught me
#66Re: Jerks on the Internet: what my first DDoS taught me
#67Earlier quoted context omitted.
That's an entirely different kind of attack. If your server is being flooded with 20TB/s of traffic, there's nothing you can do on the box itself to fix things. Whatever you do, the legitimate requests won't be able to get through. If however your DOS attack is an attacker making lower-volume CPU-expensive requests on your site, there's plenty of things to help mitigate the assault.
That's the key difference between a DOS and a DDOS, yes. Since I can't load the OP article on this machine for some reason, I can't review the symptoms described. The title of the article does say DDOS, however, which is focused more on saturating bandwidth, not CPU.
Sadly DDoS has at times been used as a blanket term that also includes DoS.
Re: Jerks on the Internet: what my first DDoS taught me
#68Can anyone shed some light on why someone would go out of their way to conduct an attack like this? Is DoSing production web applications just a hobby for black hat jackasses with nothing better to do?
It's fun. Or maybe you are angry. Or maybe you just want to test to break it down. Or maybe you just want the programmers to feel sad, maybe because they were boring
Re: Jerks on the Internet: what my first DDoS taught me
#69Can anyone shed some light on why someone would go out of their way to conduct an attack like this? Is DoSing production web applications just a hobby for black hat jackasses with nothing better to do?
Re: Jerks on the Internet: what my first DDoS taught me
#70Earlier quoted context omitted.
>we spell it psych and not sike. I have been informed by someone a generation younger than me that "the kids" are intentionally spelling it "sike" these days. Wikionary lists it as a variant of "psych." https://en.wiktionary.org/wiki/sike
I guess that depends on who is doing the spelling. Seems to me that the 80's spelling of it was "sike". This website seems to agree: http://www.inthe80s.com/glossary.shtml