Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And they are going to get around anycast redundancy how? [0] Also, what consumer level ISP allows egress of packets with a spoofed source IP?

[0] http://www.icann.org/en/announcements/factsheet-dns-attack-0...



Anycast in a DDoS situation would help, but if you throw enough traffic at it you end up with the original DDoS, plus a second DoS caused by cascade failure of the individual nodes going offline, causing BGP flap dampening.

Not sure if Anonymous has those kinds of resources though.


TFA recommends using VPN (which I assume has fewer restrictions than residential ISPs), or TOR (which has most of its outbound bandwidth on very large pipes which probably aren't filtered much).


TOR (which has most of its outbound bandwidth on very large pipes which probably aren't filtered much).

TOR itself filters it:

    Also, remember that many of their more subtle communication mechanisms
    (like spoofed UDP packets) can't be used over Tor, because it only transports
    correctly-formed TCP connections. 
My guess is that they're just clueless.


I suspect they were planning to use Tor for command and control.

Odd that it was only a requirement for the Windows software though. Perhaps they script its installation on the Linux side.


Command and control, of what? The ramp instances? Why would they need that?

And if the actual attack is direct, how will they escape the ISP's filters? According to The Spoofer Project[1], no ISP lets you spoof packets with IPs outside of at least the same /8 subnet. Can you even get a consumer connection with an IP in those subnets?

[1]: http://spoofer.csail.mit.edu/summary.php


> Command and control, of what? The ramp instances?

That's what I was thinking. But I'm just guessing without having downloaded the package.

> Why would they need that?

It's hard to know the motivations behind the person who wrote the Pastebin, but if you were to go to all the trouble to amass an army of bots with the capability of sending arbitrary packets with forged source IPs, wouldn't you want to retain some degree of control over it?

> And if the actual attack is direct, how will they escape the ISP's filters? According to The Spoofer Project[1], no ISP lets you spoof packets with IPs outside of at least the same /8 subnet. Can you even get a consumer connection with an IP in those subnets?

(Thank you for that fascinating link BTW.)

I dunno, the same thought occurred to me too.

Note that they encourage the use of "VPNs", though they don't specify to where. Maybe "VPN" to their audience is expected to represent some sort of anonymizing service (e.g. for illicit filesharing) that typically terminates at a backend datacenter which might not have effective egress filtering.

Again, just speculating.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: