Project 1999

Go Back   Project 1999 > General Community > Technical Discussion

Reply
 
Thread Tools Display Modes
  #1  
Old 11-21-2013, 09:27 AM
myxomatosii myxomatosii is offline
Fire Giant

myxomatosii's Avatar

Join Date: May 2011
Location: FoB
Posts: 955
Question DDoS Has Me Curious About Network Stuff

Referencing http://www.project1999.org/forums/sh...d.php?t=128723

I read through that thread and found myself wanting to understand, any suggestion on a book or books that an electrical engineer would find accessible enough to dig through?

This is a vague question but my knowledge is vague.

Any suggestions are welcome, thanks.

Also, what sort of jobs do people with this sort of knowledge work in? Always probing for new opportunities.
__________________
Blue : Bookmedder, Unkiller, Being, Useful, Stembolt, Computer
Green : Pending
Reply With Quote
  #2  
Old 11-21-2013, 09:45 AM
blondeattk blondeattk is offline
Planar Protector

blondeattk's Avatar

Join Date: Oct 2013
Location: UK
Posts: 1,130
Default

just fillout the application form on the anonymous website, they can offer you hands on training....you have to pay for your own mask ofcourse!!
__________________
"I have been freed from the shackles of pixel lust."

Are YOU Cleansed from the chains of digital desire?
Reply With Quote
  #3  
Old 11-21-2013, 09:52 AM
Iliilliill Iliilliill is offline
Aviak

Iliilliill's Avatar

Join Date: Sep 2013
Posts: 73
Default

i'm a mechanical engineer and i read through the ddos wiki. still does not make cents.
Reply With Quote
  #4  
Old 11-21-2013, 10:07 AM
nagus69 nagus69 is offline
Aviak


Join Date: Oct 2010
Posts: 56
Default

DDoS for Dummies
__________________
Reply With Quote
  #5  
Old 11-21-2013, 11:33 AM
Exmo Exmo is offline
Kobold


Join Date: Apr 2011
Posts: 194
Default

Quote:
Originally Posted by Iliilliill [You must be logged in to view images. Log in or Register.]
i'm a mechanical engineer and i read through the ddos wiki. still does not make cents.
There's a ton of stuff on the Wikipedia article that isn't what's happening here.

This is just someone sending a ton of packets of some kind, be it pings, ICMP, etc from a bunch of different IPs. Could be a compromised network somewhere (in which case this becomes a SMURF) or just a bunch of compromised PCs (a Botnet).

Would be cool to take the whole P99 Project into a VPN, so Rogan could easily just ban users when they started to flood the network. But that would create issues for new players joining us as it would add a level of complication to an already complicated process.
Reply With Quote
  #6  
Old 11-21-2013, 04:34 PM
BillyCranston BillyCranston is offline
Banned


Join Date: Jul 2013
Posts: 58
Default

Quote:
Originally Posted by Exmo [You must be logged in to view images. Log in or Register.]
There's a ton of stuff on the Wikipedia article that isn't what's happening here.

This is just someone sending a ton of packets of some kind, be it pings, ICMP, etc from a bunch of different IPs. Could be a compromised network somewhere (in which case this becomes a SMURF) or just a bunch of compromised PCs (a Botnet).

Would be cool to take the whole P99 Project into a VPN, so Rogan could easily just ban users when they started to flood the network. But that would create issues for new players joining us as it would add a level of complication to an already complicated process.
Why do you think P99 would have to use a VPN to do exactly that?
Reply With Quote
  #7  
Old 11-21-2013, 04:46 PM
Rogean Rogean is offline
¯\_(ツ)_/¯

Rogean's Avatar

Join Date: Oct 2009
Location: Massachusetts
Posts: 5,393
Default

There are lots of different kinds of DDoS attacks. If you want specific information regarding the one hitting us, look up DNS Amplification, Chargen Amplification. They are saturation type attacks. You can learn more information about how these attacks work by looking up the difference between UDP and TCP. DNS and Chargen are both UDP protocols. UDP is stateless, where as TCP requires a handshake. This means UDP packets can be sent with Spoofed source addresses (Typically the victim) in order to solicit response floods to that victim.

There's several layers to this. Typically starts with the attacker on his local pc. Now he may be behind something to mask his own IP, be it a VPN or what have you. He will send a signal from there to a botnet command and control server (or multiple servers). These servers will then in turn send out attack commands to thousands of computers that are compromised to start the attack. These thousands of botnet attacks will each contain a list of IP Addresses of servers around the world that have a vulnerability, such as open DNS resolvers (For DNS Amplificiation) or exposed Chargen ports. The botnet computers flood multiple servers at a time with packets saying "Hi, I'm <Victim's IP Address>, Please send me your DNS Repository". This is of course in the form of a very small packet. The response to that request is typically 10 times larger than the original request, or bigger. But because of the spoofed packet, the response gets sent to the victim IP address, not the real computer that requested it.

So we have a Botnet C&C sending out an attack command to thousands of computers who in turn send out requests to thousands of servers who in turn send all their responses to the victim server, all at once.

It's ouch.
__________________
Sean "Rogean" Norton
Project 1999 Co-Manager

Project 1999 Setup Guide
Last edited by Rogean; 11-21-2013 at 04:52 PM..
Reply With Quote
  #8  
Old 11-21-2013, 07:50 PM
Exmo Exmo is offline
Kobold


Join Date: Apr 2011
Posts: 194
Default

Quote:
Originally Posted by BillyCranston [You must be logged in to view images. Log in or Register.]
Why do you think P99 would have to use a VPN to do exactly that?
Because then you would need credentials to even be able to Ping the P99 Server. So it couldn't hit by external traffic. Only the gateway would.
Reply With Quote
  #9  
Old 11-21-2013, 10:10 PM
Bamz4l Bamz4l is offline
Sarnak

Bamz4l's Avatar

Join Date: Oct 2013
Posts: 490
Default

Quote:
Originally Posted by Exmo [You must be logged in to view images. Log in or Register.]
Because then you would need credentials to even be able to Ping the P99 Server. So it couldn't hit by external traffic. Only the gateway would.
pretty sure the bottleneck is the gateway and therefore a VPN would do F all. The gateways being flooded
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 03:06 AM.


Everquest is a registered trademark of Daybreak Game Company LLC.
Project 1999 is not associated or affiliated in any way with Daybreak Game Company LLC.
Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.