Using Facebook Notes to DDoS any website
1–10 of 79 posts
Re: Using Facebook Notes to DDoS any website
#2Re: Using Facebook Notes to DDoS any website
#3Re: Using Facebook Notes to DDoS any website
#4Why not just limit the number of request per site and per user? Ie. John Smith can only make X request (let say 1000) to www.google.com.
Doesn't seem too hard.
Re: Using Facebook Notes to DDoS any website
#5If enough people start using technique they will have no choice but to create a fix for this.
Re: Using Facebook Notes to DDoS any website
#6> In the end, the conclusion is that there’s no real way to us fix this that would stop “attacks” against small consumer grade sites without also significantly degrading the overall functionality. Why not just limit the number of request per site and per user? Ie. John Smith can only make X request (let say 1000) to www.google.com. Doesn't seem too hard.
Re: Using Facebook Notes to DDoS any website
#7Nonsense. Every web crawler should have some form of rate limiting. That's just good etiquette. I can control the number of requests that the Google search indexer sends to my site via webmaster tools. I don't see a good reason why Facebook can't be a good net citizen and do the same.
Re: Using Facebook Notes to DDoS any website
#8> In the end, the conclusion is that there’s no real way to us fix this that would stop “attacks” against small consumer grade sites without also significantly degrading the overall functionality. Nonsense. Every web crawler should have some form of rate limiting. That's just good etiquette. I can control the number of requests that the Google search indexer sends to my site via webmaster tools. I don't see a good re…
Re: Using Facebook Notes to DDoS any website
#9I'm surprised they aren't going to give him a bounty for this. I also assume they realize that most reporters will post their rejected findings soon after they get denied. If enough people start using technique they will have no choice but to create a fix for this.
Exclusions
The following bugs are not eligible for a bounty (and we do not recommend testing for these):
...
Denial of Service Vulnerabilities
...
That said, they do appear to be quite hypocritical when it comes to enforcing this, as at least one user on the /r/netsec thread claimed that Facebook paid them for a mail bombing vulnerability.I guess you have to use this to attack high-profile targets (or Facebook themselves) until they notice.
Re: Using Facebook Notes to DDoS any website
#10I'm surprised they aren't going to give him a bounty for this. I also assume they realize that most reporters will post their rejected findings soon after they get denied. If enough people start using technique they will have no choice but to create a fix for this.