shockli
Contributor
- Jan 29, 2016
- 243
- 194
- 111
This is being released in the VIP section because I will be using it for IT projects at uni, and will need to be able to verify the authenticity of my papers.
Introduction:
Firstly, let’s start with what a DDoS attack is. It's a Distributed Denial of Service attack. This is a lot different than a DoS attack, which is a Denial of Service attack. The main difference between these two is that a DoS attack is run with a single, usually powerful device, while a DDoS attack is run by many (sometimes very powerful) devices.
Sometimes a DoS or DDoS attack isn't the way to go. To quote the J35T3R while speaking to him on IRC, “I don't really have any powerful resources, I prefer exploits”. You can read up on this guy, there are some questions about if he really did all the attacks he claimed to, but that didn't stop him from becoming Time’s Most Influential Man on the Internet. Please if you do not have the resources to perform an attack do not even try.
Different Types of DDoS & DoS attacks:
What is the most effective for TeamSpeak:
Environment:
Each command (except the slowloris) was run on 25x Throwaway VPS’s each running a 100mbit/s line.
Targets:
TeamSpeak 3.0.11.4 servers on other throwaway VPS’s running 100mbit/s lines.
ICMP:
Program: hping3
Results: Down within seconds.
UDP:
Program: hping3
Results: Slight increase in ping, by 50ms per person.
TCP/HTTP:
Program: hping3
Results: None whatsoever to teamspeak.
SYN:
Program: hping3
Results: None whatsoever to teamspeak.
SlowLoris:
Note: This was only run from one server and not from 25 as the others.
Program: slowhttptest
Results: Extreme resource usage, but not affecting teamspeak due to teamspeak is efficient on resources.
PoD:
Program: hping3
Results: Network usage increase, but not enough to do any proper damage.
Conclusion:
The most efficient attack vector is ICMP. It seems like most servers cannot withstand this kind of attack at all. To protect your server I would recommend disabling ICMP requests if you have problems with people attacking you via ICMP.
I would also recommend using a slowloris attack for if you need to do any website DOS’ing. It is extremely efficient and uses barely any resources on the attacker's side.
Note/Edit: It seems I should not have posted the commands on how to do that. It has been added to the R4P3 forum rules, as R4P3 does not encourage attacking anyone. If you would like to know how to do this please contact me on IRC and we can discuss it further to give you access to an uncensored report.
Cool Websites to View:
http://map.norsecorp.com/
https://cloudflare.com/
http://shock.ml/
Introduction:
Firstly, let’s start with what a DDoS attack is. It's a Distributed Denial of Service attack. This is a lot different than a DoS attack, which is a Denial of Service attack. The main difference between these two is that a DoS attack is run with a single, usually powerful device, while a DDoS attack is run by many (sometimes very powerful) devices.
Sometimes a DoS or DDoS attack isn't the way to go. To quote the J35T3R while speaking to him on IRC, “I don't really have any powerful resources, I prefer exploits”. You can read up on this guy, there are some questions about if he really did all the attacks he claimed to, but that didn't stop him from becoming Time’s Most Influential Man on the Internet. Please if you do not have the resources to perform an attack do not even try.
Different Types of DDoS & DoS attacks:
What is the most effective for TeamSpeak:
Environment:
Each command (except the slowloris) was run on 25x Throwaway VPS’s each running a 100mbit/s line.
Targets:
TeamSpeak 3.0.11.4 servers on other throwaway VPS’s running 100mbit/s lines.
ICMP:
Program: hping3
Results: Down within seconds.
UDP:
Program: hping3
Results: Slight increase in ping, by 50ms per person.
TCP/HTTP:
Program: hping3
Results: None whatsoever to teamspeak.
SYN:
Program: hping3
Results: None whatsoever to teamspeak.
SlowLoris:
Note: This was only run from one server and not from 25 as the others.
Program: slowhttptest
Results: Extreme resource usage, but not affecting teamspeak due to teamspeak is efficient on resources.
PoD:
Program: hping3
Results: Network usage increase, but not enough to do any proper damage.
Conclusion:
The most efficient attack vector is ICMP. It seems like most servers cannot withstand this kind of attack at all. To protect your server I would recommend disabling ICMP requests if you have problems with people attacking you via ICMP.
I would also recommend using a slowloris attack for if you need to do any website DOS’ing. It is extremely efficient and uses barely any resources on the attacker's side.
Note/Edit: It seems I should not have posted the commands on how to do that. It has been added to the R4P3 forum rules, as R4P3 does not encourage attacking anyone. If you would like to know how to do this please contact me on IRC and we can discuss it further to give you access to an uncensored report.
Teaser: I might release a tool that can work very well soon.
Cool Websites to View:
http://map.norsecorp.com/
https://cloudflare.com/
http://shock.ml/
Last edited: