4 ms·
and no one accountable :-)
by pt_PT_guy 5y ago
and no one accountable :-)
- lucb1e 5y agoYeah this is the part I don't get. Ok the source IP is spoofed, so you need to use another technique. The packets come in on some physical line, so you can ask the person on the other end which line they're getting it from and so forth. Relatively labor-intensive (I imagine a few hours' worth of time from each network hop), but you get there. Next, you find that it's coming from across some border, so you hand it off to the local authority. As I understand it, this is where people drop the ball. The local authorities can't be arsed, so the criminals there just keeps doing it. Why then not block that connection? If the provider in that country wants to be able to continue to operate their services, they'll need to fix this problem or customers around the world just won't be able to receive responses from their network. Same with the DNS resolvers: if someone has an open DNS resolver that is constantly being abused, as all of them are, just cut them off right? You don't need that on your IP ranges. Or blackhole that source IP on the edge of your network if you see abuse coming from that resolver. It's not rocket science to figure out which part of DNS traffic is abuse if you see a constant volume of responses to queries that the client in your network never actually asked for. Neither of these things seem to happen. Why can you be an ass on the internet and never be held accountable?
- TobTobXX 5y agoPossible for DoS attacks. Practically impossible for DDoS attacks.
- lucb1e 5y agoHuh? I wrote this: > Same with the DNS resolvers: if someone has an open DNS resolver that is constantly being abused, as all of them are, just cut them off right? [etc.] That's what I'm not understanding why it is not being applied to easily solve those reflective DDoS attacks.