4 ms·
You can get people to participate in DDoS attacks with a malicious website though. Just use some JS to create image elements, script tags, iframes etc all with
by axod 16y ago
You can get people to participate in DDoS attacks with a malicious website though.
Just use some JS to create image elements, script tags, iframes etc all with sources pointing at the target, should be able to do a few hundred a second at least.
Even trivial to get people to participate without using javascript. Just pop in a hidden iframe with a million <img> tags in the source.
As things move on, I don't think individuals who happen to fire off a few hundred requests at a website should be investigated/prosecuted/etc. Website owners just need to get better at protecting their systems.
- abstractbill 16y agoJust pop in a hidden iframe with a million <img> tags in the source. Mostly agree, but thought it worth pointing out that no browser will respond to this by parallelizing the million requests - most browsers don't ever open more than a dozen or so concurrent connections to one site. So this wouldn't do as much as you might think, unless you could get lots of users to stay on your page for a long time.
- maqr 16y agoHow about Flash? I'm pretty sure you can have as many open connections as you want that way.
- cft 16y agonot only that, in Flash you can write a for {} loop that will bombard the target with requests, as long as the movie is running. The ultimate example would be compromising Youtube's SWF player, and using it as a DDOS bot.
- axod 16y agoTrue, although you can probably find all subdomains for the target, or if you're lucky find someone who has setup a DNS wildcard then you'll be able to have a bit more fun and run lots of the requests concurrently. Maybe my 'few hundred a second' was a bit off, idk There is a javascript version of the tool (LOIC), so presumably it's effective enough to be useful.
- forensic 16y agoI guarantee the FBI did further surveillance before sending the raids. They didn't just pick a random IP and then send a team. They picked the IP, sniffed their traffic, monitored their internet behaviour, read their forum posts, and then finally selected them to be an example. By performing surveillance like this you can be 99% sure who is a real voluntary participant and who is just a stooge. A voluntary participant will talk about it on forums for example, brag on IRC, etc etc. These will be the ones selected by the FBI for dramatic home visits.
- derefr 16y ago> A voluntary participant will talk about it on forums for example, brag on IRC, etc etc. So it's like assassination, then: all you have to do to get away clean is to execute only on others' commands, making no plans of your own, and not discussing, bragging, or asking questions. Historically, this leads quickly to a two-level military structure: officers to point, and enlistedmen to shoot. The only question is whether any sort of hierarchy is possible within a completely decentralized system of mutually non-trusting agents, who are nonetheless driven by either status or belonging. That sounds like it should have a mathematical answer...
- ZachPruckowski 16y agoWell, if they're snooping your net traffic, then you don't have to say anything on those forums or sites, simply hitting them on port 80 more than a handful of times is probably sufficient. They're trying to differentiate "guy who got botted" from "guy who's doing this manually", and even visiting those sites is probably differentiation enough to establish the probable cause or reasonable suspicion they need for a search warrant.