Added: 8 months ago
From: systemerror11
Views: 1,253
Sort by time | Sort by thread (beta)

Link to this comment:

Share to:

All Comments (16)

Sign In or Sign Up now to post a comment!
  • great lesson!! thx so much!!

  • Hou could you know If that is traffic generated by a common users or someone trying to make a DOS attack?

  • @ferperoro with this method, usually its a matter of noticing a pattern in traffic within the logs or a lot of traffic from a single source - the same page being visited every X time by the same IP address usually means something is automated, and likely an attack.

  • So you just want to find a XSS vulnerable site, make a few (or a lot) of these iframes and every user visiting the vulnerable site will help you DDOS some other website? That's crazy! I don't think there are to many high trafficked websites out there any more with XSS vluns, but that would be BAD!

  • The only time I find this to be a practical attack is when the victim gets charged extra by the host for using too much bandwidth.

  • Good point. Remember theoretically speaking if this is distributed enough u could push a lot data concurrently - presumably enough to overwhelm the upstream of a server - 10 or 100 mbps or more, considering that each page probably isnt going to load at precisely the same time, that 'could' be measured in mbps...

    If not its like wave after wave of being overwhelmed.

  • ahaha time to mess with my schools website XD

  • @The009975 play nice!

  • wait so if i visit youtube lets say 2000 times i'll get in trouble? :O

  • @12169413

    if you visit youtube 2000 times in 1 sec or less,yes you will be in trouble.They will see the request of the page came from the same ip and they can trace you

  • @12169413 no, youtube doesn't have a bandwidth limitation.

    if your isp catches you doing this, you could get put on a watch list

  • @bmw2go11 Just wanted to point out that youtube DOES have bandwidth limitation, it just happens to be astronomical.

  • @12169413 If its done in a short period of time, yes, it could be considered a DDOS attack, which is punishable in the USA and UK with jail time.

    If you think going to jail for the equivalent of hitting the F5 key a bunch of times is silly, I suggest you contact your representatives about it.

  • nice post easy yet effective

Loading...
Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more