ok, so i have finally got my server up at home and now i want to try and perform DoS attack on it, so you guys have any tips/software i could use?
also what is the difference between a DoS and a DDoS attack? i know that DDoS means Dedicated DoS attack but not exactly what that means..
also i will do it from another computer inh my LAN, cause i heard you get in troubly with your ISP?
DoS attack
- Jontebullen
- On the way to fame!
- Posts: 48
- Joined: 03 Apr 2007, 16:00
- 17
- Location: south of the northpole
- Contact:
- CommonStray
- Forum Assassin
- Posts: 1215
- Joined: 20 Aug 2005, 16:00
- 18
- bad_brain
- Site Owner
- Posts: 11636
- Joined: 06 Apr 2005, 16:00
- 19
- Location: In your eye floaters.
- Contact:
DDoS means distributed denial of service... this means the attack is coming from multiple sources. while a DoS attack is based on sending "malicious" traffic to the server a DDoS attack can bring a server down by simply sending such a huge amount of (normal) requests that the bandwidth is exceeded and the service become non-responsive (flooding).
what you do inside your LAN isn't the business of your ISP and because there is no traffic to the outside (which would go to the network of your ISP) the ISP will not even notice it.
software for a DoS attack are depending on the service you want to attack, so simply look for exploits on the usual sites like packetstormsecurity or milw0rm.
tools for DDoS attacks are Stacheldraht or Trinoo for example, but actually these tools are just for controlling the botnet....without a botnet no DDoS.
what you do inside your LAN isn't the business of your ISP and because there is no traffic to the outside (which would go to the network of your ISP) the ISP will not even notice it.
software for a DoS attack are depending on the service you want to attack, so simply look for exploits on the usual sites like packetstormsecurity or milw0rm.
tools for DDoS attacks are Stacheldraht or Trinoo for example, but actually these tools are just for controlling the botnet....without a botnet no DDoS.
- Jontebullen
- On the way to fame!
- Posts: 48
- Joined: 03 Apr 2007, 16:00
- 17
- Location: south of the northpole
- Contact:
Putting it up simple.Jontebullen wrote:so if i have got this right, i have to choose a program to attack, i mean i can't just attack any program that runs on a certatin port (80 in this case)?
i'm a bit confused...
oh, and to perform a DDoS attack i actually have to hack other computer right?
1: The target computer/server has a webserver (let's say apache) on port 80
2: You have infected 100 computers with a program that requests info from the site really fast a lot of times (let's say 10 requests every second).
3: You activate all the programs on all of the infected computers at the same time.
4: The target server can only handle 500 connections at a time
5: The infected computers request 10x100 all together filling the server up and causing a "Denial of service"
Well, that is only one example, there are other ways to do it.
"The best place to hide a tree, is in a forest"
- Jontebullen
- On the way to fame!
- Posts: 48
- Joined: 03 Apr 2007, 16:00
- 17
- Location: south of the northpole
- Contact:
Jontebullen wrote:ok, so i'm not interested in a DDoS attack i guess. But when i perform a DoS attack, do you need to find exploits for different servers or ports or what? i thought i only needed one program and i would be able to DoS anything?
naaah a vulnerability isn't needed, in some cases it is, but in most cases not. Some smaller servers can be DoSed from your own computer alone, but it would be like a freaking attention seeker "hey look at me wooooOoOOoOO". So in my opinion an attack using "Zombie computers" (the infected ones) would be the wisest.
"The best place to hide a tree, is in a forest"
- Jontebullen
- On the way to fame!
- Posts: 48
- Joined: 03 Apr 2007, 16:00
- 17
- Location: south of the northpole
- Contact:
- bad_brain
- Site Owner
- Posts: 11636
- Joined: 06 Apr 2005, 16:00
- 19
- Location: In your eye floaters.
- Contact:
http://httpd.apache.org/docs/2.0/programs/ab.html
can be found on almost any Linux distro, can be used remotely too...
can be found on almost any Linux distro, can be used remotely too...
lol thanks ^^Jontebullen wrote:ok. Can you link me to any specific software that you can DoS with?
btw, congrats on 500 posts ^^
Well i can't link you to any Ddos program (don't remember where to find any ready to use, and i am not interested in searching atm =P ). Taking down a site effectively would be to add a "ddos able" code into a site with A LOT of users, like a code that downloads an image from the target site all the time (hidden of course), so that all the users visiting the site would dos the target. If you get enough people to use the site (thereby ddosing your target) you might succeed in taking it down although just for a while. Ddosed targets doesn't (often) stay down very long. So taking a large site down would demand a lot of resources and even if you succeed you might get caught.
So my tip on a large scale Ddosing is
1: Getting a worm that spreads fast and can't be tracked from your computer (like setting it of at a library computer or something more anonymous) that ddoses a target at a specific time.
2: Using a really good proxy and inject a hidden ddosing script in a large site with many users that isn't yours.
But hey...thats just me ^^
"The best place to hide a tree, is in a forest"
- Lyecdevf
- cyber Idi Amin
- Posts: 1222
- Joined: 16 Mar 2006, 17:00
- 18
- Location: In between life and death.
- Contact:
Some thing similar has been posted on this forum. You may want to take a look at it!Jontebullen wrote:ok. Can you link me to any specific software that you can DoS with?
http://www.suck-o.com/modules.php?name= ... dos+attack
Try using google as well. Here is the link!
http://www.google.com/search?hl=en&q=DOS&btnG
We will either find a way, or make one.
- Hannibal
- Hannibal