EvilZone

Hacking and Security => Hacking and Security => : DextrousDave May 03, 2013, 08:44:55 AM

: DDOS attack - How to detect one
: DextrousDave May 03, 2013, 08:44:55 AM
Hi All


How do you know when you are having a Denial of Service attack? I know some antivirus programs pick it up, but else do you look for?Slow CPU, heavy network traffic? Also, how is one generated? A script, like a bat file or a simple cmd command?


Thanks
: Re: DDOS attack - How to detect one
: Stackprotector May 03, 2013, 09:20:50 AM
Hi All


How do you know when you are having a Denial of Service attack? I know some antivirus programs pick it up, but else do you look for?Slow CPU, heavy network traffic? Also, how is one generated? A script, like a bat file or a simple cmd command?


Thanks
Don't hesitate to post an introduction.

The idea behind a DDoS is flooding of packages by a [D]DoS distributed system of bots/programs.
On what system are you operating/wanting to detect the attack.

You could use the search function here or google and read something about networking and botnets.
: Re: DDOS attack - How to detect one
: WirelessDesert May 03, 2013, 04:17:24 PM
Could you post the ip address that maybe shows up in your antivirus? It could just be a bug, because why would some one want to do a dedicated DDoS on you?

::edit::
And again, I failed to interpret the thread.

Simply seeing a lot of unexpected traffic flooding in would  probably indicate an attack.
: Re: DDOS attack - How to detect one
: DextrousDave May 04, 2013, 03:02:18 PM
No the attack happened a while back  - But the ip address came from a PC on my LAN and although I know it was not the person at that PC, it had to come from the VPN that PC was connected to. IS s DDOS attack one where you sent large packets, continuously by using the ping command with other params like buffer size?
: Re: DDOS attack - How to detect one
: Snayler May 04, 2013, 04:23:25 PM
No, a DDoS (Distributed Denial of Service) is a attack performed by multiple computers (i.e. a botnet).
If it came from one computer, it would be just DoS. But it depends on what that computer was sending, and honestly, with the little information you provided, it's hard to guess what happened.
: Re: DDOS attack - How to detect one
: DextrousDave May 04, 2013, 04:59:22 PM
Thank you Snayler - OK I see. Yeah I was just wondering. I searched this site but there are no real insightful posts on Dos and DDOS attacks. I want to learn more about them, where can I go? Now how do you initiate a normal DOS attack? From cmd or do you use software for that?
: Re: DDOS attack - How to detect one
: Snayler May 04, 2013, 05:28:38 PM
Well, here are some good links for learning more about DoS attacks:
:
https://www.cert.org/tech_tips/denial_of_service.html
https://en.wikipedia.org/wiki/Denial-of-service_attack
http://www.cs.utexas.edu/users/chuang/dos.html
This last one seems to have some good examples and links to another pages describing various attack vectors and possible solutions. But it also seems a little outdated.
The wikipedia link seems to be full of information on DoS attack types.

Anyway, these 3 links were obtained via a simple google search. I guess there are some more pages with info on DoS.
: Re: DDOS attack - How to detect one
: NovaCygni May 04, 2013, 06:31:25 PM
Thank you Snayler - OK I see. Yeah I was just wondering. I searched this site but there are no real insightful posts on Dos and DDOS attacks. I want to learn more about them, where can I go? Now how do you initiate a normal DOS attack? From cmd or do you use software for that?


If you want to learn more about DoS and DDoS take a peek at the source-code of a few of the tools available, its a very simple concept, and even easiar to initiate!.
: Re: DDOS attack - How to detect one
: DextrousDave May 04, 2013, 07:01:48 PM
What tools are you referring too? I know about Loic - WHat other tools are there?
: Re: DDOS attack - How to detect one
: Snayler May 04, 2013, 08:07:07 PM
What tools are you referring too? I know about Loic - WHat other tools are there?
You really need to learn how to google...
: Re: DDOS attack - How to detect one
: Bye_Webster May 13, 2013, 03:20:02 PM
Learn With Amazing Tools, pentbox 1.5.. realy" cool.. ;)
: Re: DDOS attack - How to detect one
: hacker@sr.gov.yu May 14, 2013, 05:33:57 PM

Here is one  :)

:
https://code.google.com/p/httpflooder/
HTTPFlooder is a tool that can perform stress tests, load tests, botnet simulation, DoS/DDoS tests and fuzzing for HTTP protocol.
It supports the following attack types:
GET Flood
POST Flood
Slow Headers (Slowlories)
Slow POST
Hash DoS
Mix Flood (mixing GET/POST Flood)
Range Bytes
HTTP Header Fuzzing
Slow Header Fuzzing
MX Flooder over Balancer


And:


What a DDoS Attack Looks Like:
:
http://www.youtube.com/watch?feature=player_embedded&v=hNjdBSoIa8k
:
http://gizmodo.com/5995429/how-a-ddos-attack-looks-as-it-happens