Author Topic: DDOS attack - How to detect one  (Read 3366 times)

0 Members and 1 Guest are viewing this topic.

Offline DextrousDave

  • NULL
  • Posts: 4
  • Cookies: 0
    • View Profile
DDOS attack - How to detect one
« on: May 03, 2013, 08:44:55 am »
Hi All


How do you know when you are having a Denial of Service attack? I know some antivirus programs pick it up, but else do you look for?Slow CPU, heavy network traffic? Also, how is one generated? A script, like a bat file or a simple cmd command?


Thanks

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Re: DDOS attack - How to detect one
« Reply #1 on: May 03, 2013, 09:20:50 am »
Hi All


How do you know when you are having a Denial of Service attack? I know some antivirus programs pick it up, but else do you look for?Slow CPU, heavy network traffic? Also, how is one generated? A script, like a bat file or a simple cmd command?


Thanks
Don't hesitate to post an introduction.

The idea behind a DDoS is flooding of packages by a [D]DoS distributed system of bots/programs.
On what system are you operating/wanting to detect the attack.

You could use the search function here or google and read something about networking and botnets.
~Factionwars

Offline WirelessDesert

  • Knight
  • **
  • Posts: 356
  • Cookies: 10
  • I think...
    • View Profile
Re: DDOS attack - How to detect one
« Reply #2 on: May 03, 2013, 04:17:24 pm »
Could you post the ip address that maybe shows up in your antivirus? It could just be a bug, because why would some one want to do a dedicated DDoS on you?

::edit::
And again, I failed to interpret the thread.

Simply seeing a lot of unexpected traffic flooding in would  probably indicate an attack.
« Last Edit: May 03, 2013, 04:20:43 pm by WirelessDesert »
Check out my arduino project: Moving car - School project!
"I'm like current, I always take the easiest route."

Offline DextrousDave

  • NULL
  • Posts: 4
  • Cookies: 0
    • View Profile
Re: DDOS attack - How to detect one
« Reply #3 on: May 04, 2013, 03:02:18 pm »
No the attack happened a while back  - But the ip address came from a PC on my LAN and although I know it was not the person at that PC, it had to come from the VPN that PC was connected to. IS s DDOS attack one where you sent large packets, continuously by using the ping command with other params like buffer size?

Offline Snayler

  • Baron
  • ****
  • Posts: 812
  • Cookies: 135
    • View Profile
Re: DDOS attack - How to detect one
« Reply #4 on: May 04, 2013, 04:23:25 pm »
No, a DDoS (Distributed Denial of Service) is a attack performed by multiple computers (i.e. a botnet).
If it came from one computer, it would be just DoS. But it depends on what that computer was sending, and honestly, with the little information you provided, it's hard to guess what happened.
« Last Edit: May 04, 2013, 04:24:31 pm by Snayler »

Offline DextrousDave

  • NULL
  • Posts: 4
  • Cookies: 0
    • View Profile
Re: DDOS attack - How to detect one
« Reply #5 on: May 04, 2013, 04:59:22 pm »
Thank you Snayler - OK I see. Yeah I was just wondering. I searched this site but there are no real insightful posts on Dos and DDOS attacks. I want to learn more about them, where can I go? Now how do you initiate a normal DOS attack? From cmd or do you use software for that?

Offline Snayler

  • Baron
  • ****
  • Posts: 812
  • Cookies: 135
    • View Profile
Re: DDOS attack - How to detect one
« Reply #6 on: May 04, 2013, 05:28:38 pm »
Well, here are some good links for learning more about DoS attacks:
Code: [Select]
https://www.cert.org/tech_tips/denial_of_service.html
https://en.wikipedia.org/wiki/Denial-of-service_attack
http://www.cs.utexas.edu/users/chuang/dos.html
This last one seems to have some good examples and links to another pages describing various attack vectors and possible solutions. But it also seems a little outdated.
The wikipedia link seems to be full of information on DoS attack types.

Anyway, these 3 links were obtained via a simple google search. I guess there are some more pages with info on DoS.
« Last Edit: May 04, 2013, 05:31:24 pm by Snayler »

Offline NovaCygni

  • Peasant
  • *
  • Posts: 86
  • Cookies: 2
  • 403:Forbidden
    • View Profile
Re: DDOS attack - How to detect one
« Reply #7 on: May 04, 2013, 06:31:25 pm »
Thank you Snayler - OK I see. Yeah I was just wondering. I searched this site but there are no real insightful posts on Dos and DDOS attacks. I want to learn more about them, where can I go? Now how do you initiate a normal DOS attack? From cmd or do you use software for that?


If you want to learn more about DoS and DDoS take a peek at the source-code of a few of the tools available, its a very simple concept, and even easiar to initiate!.
We do what we want, Because we can.

Offline DextrousDave

  • NULL
  • Posts: 4
  • Cookies: 0
    • View Profile
Re: DDOS attack - How to detect one
« Reply #8 on: May 04, 2013, 07:01:48 pm »
What tools are you referring too? I know about Loic - WHat other tools are there?
« Last Edit: May 04, 2013, 07:37:18 pm by DextrousDave »

Offline Snayler

  • Baron
  • ****
  • Posts: 812
  • Cookies: 135
    • View Profile
Re: DDOS attack - How to detect one
« Reply #9 on: May 04, 2013, 08:07:07 pm »
What tools are you referring too? I know about Loic - WHat other tools are there?
You really need to learn how to google...

Offline Bye_Webster

  • NULL
  • Posts: 1
  • Cookies: 0
    • View Profile
Re: DDOS attack - How to detect one
« Reply #10 on: May 13, 2013, 03:20:02 pm »
Learn With Amazing Tools, pentbox 1.5.. realy" cool.. ;)

Offline hacker@sr.gov.yu

  • VIP
  • Peasant
  • *
  • Posts: 142
  • Cookies: 25
  • Tools don't make hackers, hackers make tools!
    • View Profile
Re: DDOS attack - How to detect one
« Reply #11 on: May 14, 2013, 05:33:57 pm »

Here is one  :)

Code: [Select]
https://code.google.com/p/httpflooder/
HTTPFlooder is a tool that can perform stress tests, load tests, botnet simulation, DoS/DDoS tests and fuzzing for HTTP protocol.
It supports the following attack types:
GET Flood
POST Flood
Slow Headers (Slowlories)
Slow POST
Hash DoS
Mix Flood (mixing GET/POST Flood)
Range Bytes
HTTP Header Fuzzing
Slow Header Fuzzing
MX Flooder over Balancer


And:


What a DDoS Attack Looks Like:
Code: [Select]
http://www.youtube.com/watch?feature=player_embedded&v=hNjdBSoIa8k
Code: [Select]
http://gizmodo.com/5995429/how-a-ddos-attack-looks-as-it-happens
« Last Edit: May 14, 2013, 05:39:25 pm by hacker@sr.gov.yu »