Live data from Hacker News

Jerks on the Internet: what my first DDoS taught me

sergiomattei.com

61–70 of 95 posts

Re: Jerks on the Internet: what my first DDoS taught me

#61
post #53

Can anyone shed some light on why someone would go out of their way to conduct an attack like this? Is DoSing production web applications just a hobby for black hat jackasses with nothing better to do?

It's fun. Or maybe you are angry. Or maybe you just want to test to break it down. Or maybe you just want the programmers to feel sad, maybe because they were boring

Re: Jerks on the Internet: what my first DDoS taught me

#63
post #53

Can anyone shed some light on why someone would go out of their way to conduct an attack like this? Is DoSing production web applications just a hobby for black hat jackasses with nothing better to do?

its a rush. its why some people with money still shoplift.

I guess humans are closer to monkeys than we like to believe and still like throwing poop at each other.

Re: Jerks on the Internet: what my first DDoS taught me

#64

Earlier quoted context omitted.

It’s not used because any serious attack is going to come from multiple unrelated sources, think a botnet full of compromised IoT devices hitting your server with 20TB a second worth of requests. So you might as well plan for that scenario instead.

That's an entirely different kind of attack. If your server is being flooded with 20TB/s of traffic, there's nothing you can do on the box itself to fix things. Whatever you do, the legitimate requests won't be able to get through. If however your DOS attack is an attacker making lower-volume CPU-expensive requests on your site, there's plenty of things to help mitigate the assault.

That's the key difference between a DOS and a DDOS, yes. Since I can't load the OP article on this machine for some reason, I can't review the symptoms described. The title of the article does say DDOS, however, which is focused more on saturating bandwidth, not CPU.

Re: Jerks on the Internet: what my first DDoS taught me

#65
post #46

Earlier quoted context omitted.

Those requests seldom get far enough to start significant server activity. It's the ones that look like legit requests that are the problem.

Seldom isn’t good enough. When it comes to security you have to be right 100% of the time. An attacker only has to be right once. Good luck.

its about layers which includes real security and sometimes trickery. the statement is true though about 100% and the attacker only once but some tack maybe would be in order. there are procedures that can reduce vectors and so minimizing damage and minimizing successes.

Re: Jerks on the Internet: what my first DDoS taught me

#67

Earlier quoted context omitted.

That's an entirely different kind of attack. If your server is being flooded with 20TB/s of traffic, there's nothing you can do on the box itself to fix things. Whatever you do, the legitimate requests won't be able to get through. If however your DOS attack is an attacker making lower-volume CPU-expensive requests on your site, there's plenty of things to help mitigate the assault.

That's the key difference between a DOS and a DDOS, yes. Since I can't load the OP article on this machine for some reason, I can't review the symptoms described. The title of the article does say DDOS, however, which is focused more on saturating bandwidth, not CPU.

> The title of the article does say DDOS, however, which is focused more on saturating bandwidth, not CPU.

Sadly DDoS has at times been used as a blanket term that also includes DoS.

Re: Jerks on the Internet: what my first DDoS taught me

#68
post #53

Can anyone shed some light on why someone would go out of their way to conduct an attack like this? Is DoSing production web applications just a hobby for black hat jackasses with nothing better to do?

It's fun. Or maybe you are angry. Or maybe you just want to test to break it down. Or maybe you just want the programmers to feel sad, maybe because they were boring

Fun in a same way as trashing your neighbor's car just because you like to see sparks and glass shards flying all around. Rather an indication of a sad frustrated life

Re: Jerks on the Internet: what my first DDoS taught me

#69
post #53

Can anyone shed some light on why someone would go out of their way to conduct an attack like this? Is DoSing production web applications just a hobby for black hat jackasses with nothing better to do?

I've seen people with substantial IT skills who simply have destructive instincts. This one guy I know was hyperactive and made clearings in forested areas to hang out in with his spare time.

Re: Jerks on the Internet: what my first DDoS taught me

#70
post #21
post #15

Earlier quoted context omitted.

>we spell it psych and not sike. I have been informed by someone a generation younger than me that "the kids" are intentionally spelling it "sike" these days. Wikionary lists it as a variant of "psych." https://en.wiktionary.org/wiki/sike

I guess that depends on who is doing the spelling. Seems to me that the 80's spelling of it was "sike". This website seems to agree: http://www.inthe80s.com/glossary.shtml

[deleted]
Post reply on HN