5 ms·
You can deny access only from your IP, not for anyone else.
by codedokode 3y ago
You can deny access only from your IP, not for anyone else.
- iforgotpassword 3y agoHow do you verify the source address of the packet is legit?
- codedokode 3y agoThe router can send back a confirmation code and you must send it back to confirm that request comes from your IP. Also, on a well-behaved networks that do not allow spoofing IP addresses, this check can be omitted.
- iforgotpassword 3y ago> The router can send back a confirmation code and you must send it back to confirm that request comes from your IP. Ideally with the token packet being larger than the initial packet, so it can easily be abused for a reflection attack... ;-) > Also, on a well-behaved networks that do not allow spoofing IP addresses, this check can be omitted. This is already not true for most networks, and in your case would've to be true for all intermediate networks which is just impossible. In another post you suggest this should also allow blocking entire networks; how do you prevent abuse of that? Your suggestion is anything but well-thought, it's a pipe dream for a perfect world, but if we'd live in one, we wouldn't have ddos attacks in the first place.
- hnlmorg 3y agoIP addresses can be spoofed. So you’d need some kind of handshake to verify you are the owner of that IP. Which is going to be tough to complete if your network is completely saturated from the DDoS in progress. I do think your idea has merit though. But it’s still a long way from being a well thought-out solution.