Тёмный

Black Hat USA 2013 - Lessons from Surviving a 300Gbps Denial of Service Attack 

Black Hat
Подписаться 229 тыс.
Просмотров 138 тыс.
50% 1

Опубликовано:

 

2 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 90   
@MrProfessorLightyear
@MrProfessorLightyear 8 лет назад
DDOS ME 127.0.0.1
@crazyvet112
@crazyvet112 8 лет назад
I'm trying but my computer keeps freezing up.
@encycl07pedia-
@encycl07pedia- 7 лет назад
+EdgeOfLight It's "script KIDDIE," you fucking idiot. Also "themselves."
@SkyBluPinked
@SkyBluPinked 7 лет назад
IP Address: 127.0.0.1 Reverse DNS:** server can't find 1.0.0.127.in-addr.arpa: SERVFAILHostname: localhostLookup IP Address Location For IP: 127.0.0.1Continent:Europe (EU)Country: Unknown Capital:StockholmState:Stockholms Lan NICE PROXY ;)
@secrecy3915
@secrecy3915 4 года назад
@Spoopy the answer would've been yes, if not for you.
@bloodbath4087
@bloodbath4087 4 года назад
@@SkyBluPinked bro... it is for internal services running on ur pc...
@jackv.z7141
@jackv.z7141 6 лет назад
Summary: Hi I make money stopping ddos attacks, I will now explain how to perform a ddos
@leonhma
@leonhma 4 года назад
10:19
@adrianalexandrov7730
@adrianalexandrov7730 Год назад
nore people knowibg is good for business
@crazyvet112
@crazyvet112 8 лет назад
I did a 300pb/s ddos with a 1973 Texas Instruments calculator routed through my Commodore 64.
@vcokltfre
@vcokltfre 4 года назад
As in picobits per second, right?
@TheFatDemon
@TheFatDemon 10 лет назад
Slutty DNS xD
@MrEndzo
@MrEndzo Год назад
I wonder what kind of number they do these days.
@j.b.9581
@j.b.9581 2 года назад
At 27:00 he mentions 'Anycast.' Anycast is still around protecting networks from DDOS attacks. It's still imperfect, yet it apparently still works in the same manner. And yeah, I am catching up some on my cyber stuffs.
@johnnyblaze9217
@johnnyblaze9217 2 года назад
Lmfao if you want to know more about ddos and ddos mitigation drop your discord I can teach you
@MrNullGaming
@MrNullGaming 10 лет назад
Simply a NTP attack these are as easy as anything scan for the open lists on the server with another tab open attacking, scanning for lists takes a few days but results are extreme
@ChristopherGray00
@ChristopherGray00 8 лет назад
How does it feel when a 15 year old kid takes down your service? Must be embarrassing.
@alexanderilliescu249
@alexanderilliescu249 8 лет назад
+Code Ex Even a 10 year old could do it these days.
@ChristopherGray00
@ChristopherGray00 8 лет назад
Primal 101 Nope, you'd need atleast 200 gbps of raw power to take down one cloudflare protected server, and i'm talking about raw power, and 200 gbps is not easy to get, sure there are stressers, but these tools can mostly only hit off home connections.
@alexanderilliescu249
@alexanderilliescu249 8 лет назад
they probs bouht like 5 dedis and used hping3 not a big deal even a guy without arms could do this
@ChristopherGray00
@ChristopherGray00 8 лет назад
Primal 101 No, most VPS's don't allow these types of attacks to be sent, you'd need some massive botnet.
@alexanderilliescu249
@alexanderilliescu249 8 лет назад
most dont, but there are some that do
@MotorsportsX
@MotorsportsX 7 лет назад
rip headphone users
@ogamibirdflu5152
@ogamibirdflu5152 Год назад
56:04 That accent...is it French? PseudoPalestinian? Something else?
@ChillerDragon
@ChillerDragon 4 года назад
57:25 weird flex but ok xd
@goeiecool9999
@goeiecool9999 7 лет назад
So NOBODY is going to comment on the announcer saying gigabyte instead of gigabit? It's right at the start of the video.
@emsicz
@emsicz 6 лет назад
No because we're actually mature and don't need to reeee for every little mistake someone makes when we know exactly what they meant.
@computerfreak944
@computerfreak944 3 года назад
Thank you very much for addressing it. I searched this comment because it triggered me hard and i checked three times if he really said it like that.
@blu3_enjoy
@blu3_enjoy Год назад
He betrayed kiwi farm.
@destrierofdark_
@destrierofdark_ 4 года назад
Someone should create a cyclic DDoSer that basically nukes every open resolver based on this list, with some of the packet information being a "you're running an open resolver, see this link for more" and then basically have that link be instructions on how to close their resolver, essentially as a mechanism of hard peer pressure to get as many open resolvers to a closed status as possible. And if you disagree, I understand, but vast problems require respectively equal drastic measures.
@cipheroth
@cipheroth 4 года назад
"Stunningly Simple" of course... for that reason it is not fixed
@angiemariapicadoleiton4290
@angiemariapicadoleiton4290 4 года назад
Aint no body watch this!
@ryanrussell5166
@ryanrussell5166 8 лет назад
hit 192.168.0.1
@garbagetrash1793
@garbagetrash1793 8 лет назад
*127.0.0.1
@oizy1760
@oizy1760 8 лет назад
Same thing, lmao.
@garbagetrash1793
@garbagetrash1793 8 лет назад
127.0.0.1 is always a loopback address. 192.168.0.1 isn't always the router. I think Cisco defaults to 192.168.1.1 and they can be manually changed. Yeah same concept though, I said it ironically.
@oizy1760
@oizy1760 8 лет назад
+StressingModz- who
@Exsyting
@Exsyting 10 лет назад
hahaha i live in Mn but damn I wonder how many terabytes of data could be sent if a big botnet took control and actually could spoof a target???
@RobertMorgan
@RobertMorgan 9 лет назад
Chris Fischer Read this for a good example of when it's happened in the past... archive.wired.com/wired/archive/11.07/slammer.html "Slammer's attack was ruthless and quick, spreading hundreds of times faster than the Code Red virus or Nimda worm. Yet it started with a single killer packet. The tiny worm hit its first victim at 12:30 am Eastern standard time. The machine - a server running Microsoft SQL - instantly started spewing millions of Slammer clones, targeting computers at random. By 12:33 am, the number of slave servers in Slammer's replicant army was doubling every 8.5 seconds. By 12:45 am, huge sections of the Internet began to wink out of existence. Net Access Corporation, one of the Northeast's largest ISPs, sent out an early SOS: "Nearly half our ports are in delta alarm right now." Up on the big screen, Maresh could see backbone carrier Level 3's transcontinental chain of routers trying to find working paths to the rest of the world - and failing. Three hundred thousand cable modems in Portugal went dark, and South Korea fell right off the map: no cell phone or Internet service for 27 million people. Five of the Internet's 13 root-name servers - hardened systems, all - succumbed to the squall of packets. Corporate email systems jammed. Web sites stopped responding. A Linux specialist in Manhattan spammed his colleagues in uppercase to make it clear he was screaming: "MS SQL WORM IS DESTROYING INTERNET - BLOCK PORT 1434!" But by then Slammer had knocked out more than just the Internet. Emergency 911 dispatchers in suburban Seattle resorted to paper. Continental Airlines, unable to process tickets, canceled flights from its Newark hub."
@smiley_1000
@smiley_1000 3 года назад
@@RobertMorgan what a well-deserved attack - it's insane that we still rely on the naive and unstable architecture of IP routing & DNS resolving.
@pavelyankouski4913
@pavelyankouski4913 2 года назад
I wonder is it possible to use alternative router if the original was under attack or some critical packet loss, like uninterruptible power supply unit ? So just switch to an another source of the ethernet. I mean "ups" is existing, why there is no "uis"
@thewhitefalcon8539
@thewhitefalcon8539 2 года назад
There is, and they use it. But if it's an attack then the attacker is also using the uis so what's the point? Analogy: you have redundant power supplies and someone plugs in 1000 space heaters, blowing the fuse. The power supply switches over, and they're still plugged in, so that fuse blows too
@pavelyankouski4913
@pavelyankouski4913 2 года назад
@@thewhitefalcon8539Uninterruptible power supplies are equipped with fuses that protect them
@anonymous-di3qg
@anonymous-di3qg 9 лет назад
is there anyway a large gameserver like gta 5 on psn could be ddos'd? what kind of ddos protection do they have? i know theyre servers are always going down for no reoson is it possibly ddos?
@commit123
@commit123 9 лет назад
Don't fucking do it; you'll have your fucking hands in cuffs for 10 years before you even know it.
@nickpaschkov1138
@nickpaschkov1138 9 лет назад
Oh please do it you won't get arrested all you need is one of those free booted and ddos with 1 tb of power it's also untraceable
@index2086
@index2086 9 лет назад
xComiiT You're actually fucking stupid, just use a vpn.
@commit123
@commit123 9 лет назад
cybybybybybybybbybyb Are you a dumbass or something? A VPN is made by a company, not a criminal. If you take as server down as big as that they will trackdown th IP, and eventually find out it's a VPN. Then they will go to the company and ask them who was using that server, and them being a company will immediately give up where you live. And bam, you're in prison for 10 years.
@commit123
@commit123 9 лет назад
cybybybybybybybbybyb Look it up, I'm not completely sure but they will find out. It's happened so many times before and if they're not found imediatelly it will be sometime within the next two years. If you really want to be safe, use a botnet. But even that has major risks.
@normalperson5281
@normalperson5281 9 лет назад
+James Bond can we talk
@ryancampos3843
@ryancampos3843 8 лет назад
Duvildo you guys knocks my IP 189.1.172.204
@SkullHunterLy
@SkullHunterLy 9 лет назад
ddos this ip 123.456.789
@JoeyplaysgamesLoL
@JoeyplaysgamesLoL 8 лет назад
+SkullHunterLy shit you must really hate that person.
@isidisi99
@isidisi99 8 лет назад
+SkullHunterLy Ayyy DDoS me 127.1.33.7
@dazzyx3644
@dazzyx3644 8 лет назад
+SkullHunterLy i know that's a joke, and an old post, but IP numbers cannot be higher than 256. just sayin
@isidisi99
@isidisi99 8 лет назад
+DazzyX Than 255*
@dazzyx3644
@dazzyx3644 8 лет назад
It is 256 :) Raggae Shark
@duskrisergfx6901
@duskrisergfx6901 8 лет назад
One time I had a backdoor on my computer, and it came with a virus that took the name of CloudFlare, while the hacker that put the virus on my computer DDoSes me every few hours. No joke, I did have problems with them because of it.
@osearthesp
@osearthesp 7 лет назад
i useda have a LOT of backdoor on my puters, nudge nudge eh guvna!
@JamesBond-xl1nt
@JamesBond-xl1nt 9 лет назад
thanks to this , i crash game servers super quickly :)
@elliottg7192
@elliottg7192 8 лет назад
HELLO GUYS +James Bond HERE, IM AN AUTISTIC 5 YEAR OLD SCRIPT KIDDY
@pavelyankouski4913
@pavelyankouski4913 2 года назад
This is why singleplayer mode still is the best choice for a game developers. Lans is almost dead, but I think "private" or "vip" lans could be a good alternative of the common internet. Internet became boring or better to say is an experimental place to clown out everybody
@adrianalexandrov7730
@adrianalexandrov7730 Год назад
Technically developers could embed vpn client into the game so that all your traffic would go as if alk of you are on the same LAN. But that might lead to other vulnerabilities
@pavelyankouski4913
@pavelyankouski4913 Год назад
@@adrianalexandrov7730 of course VPN. But its isn't legal for a competitive gaming like cybersport games, like StarCraft 1 or Warcraft3 classic or some sh*tty Dota and alternatives like LoL or HoN. The World internet will be cut into two pieces West and East segment, probably gaming will be segmented as well, at least i already predicted this variant for my future gaming platform
@adrianalexandrov7730
@adrianalexandrov7730 Год назад
@@pavelyankouski4913 sorry, bro, I don't know shit about modern competitive gaming and it's rules.
@pavelyankouski4913
@pavelyankouski4913 Год назад
@@adrianalexandrov7730 oh, no problem, I was a pro gamer back in 20 years. I won Samsung Golden Cup in 2003 in Minsk in a nomination 1v1 "Reign of Chaos". It was a lan tournament. Two Ukrainian players where in a finals, because I was born in Ukraine !
@adrianalexandrov7730
@adrianalexandrov7730 Год назад
@@pavelyankouski4913 wow, that's impressive. And thanks for the insight those kind of vulnerabilities hit gamers as well. P.S. Glory to Ukraine! As much as it costs from a guy born in Russia...
@privateserver4556
@privateserver4556 9 лет назад
Guys i will tell you how to secure from ddosers this doesnt work for web but it works for pc so ok if you want to secure your network you need to configuard your network that you need to enter first mac_version this isint mac windos.i mean when you confirm the network the ddoser will have no access to ddos you his sent packets will disable it but if you buy roater and dont configuard it when you join mc.cs. or some web or game the owner will have your ip and he can ddos you and turn of your network.so i mean you need first to know how ddos works to protect you self
@sjoepele
@sjoepele 9 лет назад
I have read this about 15 times and i still don't know what you mean. Nor do i think what you mean is necessarily true :P I think what you mean is - configure your network to only allow specific MAC addresses. This won't help against any kind of DoS attacks, it just means you're better protected from hackers who want to compromise your internal network (As they would have to spoof an authorized MAC). If you want to protect yourself from a DDoS attack, you essentially want to prevent people from getting your IP. There's a variety of ways to do that, one of which is getting a nice VPN. If i misunderstood what you were trying to say, i'm sorry, but you're kind of hard to understand :P
@TangentTouch
@TangentTouch 8 лет назад
+sjoepele LOL your first sentence made me laugh, but why did you bother reading 15 times man?lol
Далее
Black Hat 2013 - OPSEC Failures of Spies
25:11
Просмотров 223 тыс.
Iran launches wave of missiles at Israel
00:43
Просмотров 820 тыс.
Exploiting Network Printers
45:09
Просмотров 45 тыс.
Black Hat USA 2013 - Rooting SIM cards
58:32
Просмотров 1,7 тыс.
Wolfram Physics Project Launch
3:50:19
Просмотров 1,8 млн
Andrew Bustamante: CIA Spy | Lex Fridman Podcast #310
3:53:09
Defcon 21 - Stalking a City for Fun and Frivolity
45:20
Network Security - Deep Dive Replay
3:08:19
Просмотров 161 тыс.
Iran launches wave of missiles at Israel
00:43
Просмотров 820 тыс.