3 ms·
Is there a legitimate reason why any ISP / hosting provider etc allows traffic to exit with an IP that doesn't belong to them? Surely enforcing this would prev
by theknown99 13y ago
Is there a legitimate reason why any ISP / hosting provider etc allows traffic to exit with an IP that doesn't belong to them?
Surely enforcing this would prevent any IP spoofing, which would cut down on these types of attacks?
(As far as I'm aware in this type of attack you send packets purporting to be from your target, to anything on the internet that will blindly send back a reply. Hopefully the reply will be bigger/more packets than your request was, thus amplifying the bandwidth).
If I'm mistaken please explain why...
- dsl 13y agoWhat you suggest is actually the default behavior of most major carriers. Its codified here: http://tools.ietf.org/html/bcp38 http://tools.ietf.org/html/bcp38 That said, source address spoofing is needed for some one-way satellite internet providers. There are also some really cool advanced load balancing tricks you can do with it. It even comes in handy (ironically) when doing DDoS mitigation.
- theknown99 13y agoIs it the default behavior of major carriers in Russia/China/Africa/etc as well as in Europe/America? My experience has been that the majority of the countries where attacks come from do not really care.
- Nyr 13y agoYes, it is. But DDoS attacks to EU or the US aren't launched from China/Africa anyway. You need relatively low capacity to start an amplification attack, so a server at some ISP which doesn't care is enough. There are some ISPs which knowingly allow this, like Ecatel in The Netherlands which is probably the most notorious example.
- nmc 13y agoAs dsl pointed out, this filtering is already enforced, but it presents caveats and limitations: http://tools.ietf.org/search/rfc3013#section-4.3 http://tools.ietf.org/search/rfc3013#section-4.3