4 ms·
The source for one version of LOIC can be found on GitHub: https://github.com/NewEraCracker/LOIC/ https://github.com/NewEraCracker/LOIC/ A quick skim-read of
by dredge 16y ago
The source for one version of LOIC can be found on GitHub:
https://github.com/NewEraCracker/LOIC/ https://github.com/NewEraCracker/LOIC/
A quick skim-read of the code mentioned in the post shows that this version seems to be different, specifically:
https://github.com/NewEraCracker/LOIC/blob/master/HTTPFlooder.cs#L70 https://github.com/NewEraCracker/LOIC/blob/master/HTTPFloode...
if (random == true)
buf = System.Text.Encoding.ASCII.GetBytes(
String.Format("GET {0}{1} HTTP/1.1{2}Host: {3}{2}{2}{2}",
Subsite, new Functions().RandomString(), Environment.NewLine, Host));
else
buf = System.Text.Encoding.ASCII.GetBytes(
String.Format("GET {0} HTTP/1.1{1}Host: {2}{1}{1}{1}",
Subsite, Environment.NewLine, Host));
(botched indentation is my own)
The Host header mentioned in the blog post is present, the protocol is now HTTP/1.1 and random string appears to be an attempt to defeat a simple packet matching algorithm.
I doubt many legitimate requests these days come without a User-Agent header, though...
- tptacek 16y agoThe queries this generates look nothing like real requests; equally importantly, it's not actually implementing HTTP. Also, the concurrency mechanism is naive; you could write an evented proxy that writes 1 byte back and hangs, gumming up a thread. These problems are really easy to fix, so I'm not sure whether it's worth discussing them; most people on HN aren't in a position to actually implement countermeasures to this tool, and there's nothing conceptually interesting about it to learn from.
- contextfree 16y agoPretty surprised to see that it's WinForms based. .NET: not just for cubicle dwellers anymore!