3 ms·
That doesn't really prevent anyone from attacking a hosting service like GitHub Pages or Netlify, though.
by yepguy 8y ago
That doesn't really prevent anyone from attacking a hosting service like GitHub Pages or Netlify, though.
- giancarlostoro 8y agoYou could check the existing DNS of a domain, if they're GitHub or Netlify's DNS addresses / IP's then you don't stress those.
- lelandbatey 8y agoThe idea is that the stress testing site dictates where the file must go, not the user. So for them to run the test, they may need to see a specific file at "subjectsite.com/secretguid" The idea being that unless you have total domain control, you can't get that file where they want you to put it.
- msmith 8y agoI was a lead on Blitz. You’re right that there are ways to get around this domain ownership check, but in practice it was enough of a hurdle to avoid bad actors. Also, I’m pretty sure that these stressors were way more cost effective if your only goal is to DDoS a site.