republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » More On Media Defender's Latest Screw Up » Illegal?
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
What a moronic analogy »
« Required Topic  
Crookshanks

join:2008-02-04
Endicott, NY

Re: Illegal?

said by Matt See Profile :

Trying to establish 8000 new sessions a SECOND is a DDoS
Minor nitpick but I don't know as if I'd call that a 'DDoS'. DDoS == distributed denial of service attack and is typically something that is launched with thousands of different hosts on hundreds of different networks, usually using owned systems (via a botnet).

What Media Defender did definitely qualifies as a DoS but I'd question whether or not the usage of the term 'DDoS' is accurate here.
Necronomikro

join:2005-09-01

Re: Illegal?

said by Crookshanks See Profile :

said by Matt See Profile :

Trying to establish 8000 new sessions a SECOND is a DDoS
Minor nitpick but I don't know as if I'd call that a 'DDoS'. DDoS == distributed denial of service attack and is typically something that is launched with thousands of different hosts on hundreds of different networks, usually using owned systems (via a botnet).

What Media Defender did definitely qualifies as a DoS but I'd question whether or not the usage of the term 'DDoS' is accurate here.
"The company, with 2,000 servers and 9Gbps of dedicated bandwidth at their disposal"

Sounds like a DDOS to me. May not have been distributed amongst many different networks, but it was many different computers within a high-speed network.

dnoyeB
Ferrous Phallus

join:2000-10-09
Southfield, MI

Re: Illegal?

I think its resonable to assume it was distributed. Otherwise 2000 computers are not getting out of the same network pipe without DOSsing themselves.
Fieryphoenix

join:2004-05-10

Re: Illegal?

Actually, MD has a staggeringly huge pipe. All the servers were likely at their location, not distributed.
cornelius785

join:2006-10-26
Worcester, MA

i consider a DoS attack to be a DDoS attack when the packets come from computers that are distributed over a large area, not (from the sounds of it) a server farm. i don't know all the little details but based on "The company, with 2,000 servers and 9Gbps of dedicated bandwidth at their disposal" and that all the packets originated from a small set of IP addresses (maybe one???), but i wouldn't consider that a DDoS attack. i'm guessing the reason for all the servers (assuming they were in a server farm) was to be able to ensure the entire bandwidth of the connection (9 Gbps) could be saturated.

james

join:2001-02-26
antarctica

Re: Illegal?

said by cornelius785 See Profile :

i consider a DoS attack to be a DDoS attack when the packets come from computers that are distributed over a large area, not (from the sounds of it) a server farm.
You can't just make up definitions for commonly used terms and then expect everyone to go along with you.
The distributed refers to not being a single computer attack, physical location is irrelevant.

funchords
Hello
Premium,MVM
join:2001-03-11
Washington, DC
·Verizon Online DSL
·Skype

Re: Illegal?

said by james See Profile :

said by cornelius785 See Profile :

i consider a DoS attack to be a DDoS attack when the packets come from computers that are distributed over a large area, not (from the sounds of it) a server farm.
You can't just make up definitions for commonly used terms and then expect everyone to go along with you.
The distributed refers to not being a single computer attack, physical location is irrelevant.
Whatever. I don't disagree with you, but whatever. We're arguing over semantics while agreeing on what happened.
--
Robb Topolski -= funchords.com =- Hillsboro, Oregon
HTTP is the new Bandwidth Hog...

funchords
Hello
Premium,MVM
join:2001-03-11
Washington, DC
·Verizon Online DSL
·Skype

said by Necronomikro See Profile :

"The company, with 2,000 servers and 9Gbps of dedicated bandwidth at their disposal"

Sounds like a DDOS to me. May not have been distributed amongst many different networks, but it was many different computers within a high-speed network.
According to the logs that I saw, two IPTABLES entries would have solved it. It sounds like they made a last-minute change on a Friday and left town for the weekend. MediaDefender's buggy scripts went nuts.

This was "amateur hour" on both MediaDefenders and Revision3's accounts. That said, MediaDefender was the inflicter of damage and was the primary cause of this accident.
--
Robb Topolski -= funchords.com =- Hillsboro, Oregon
HTTP is the new Bandwidth Hog...

Matt
Take me down to the paradise city
Premium
join:2003-07-20
Jamestown, NC
·North State Commun..

Re: Illegal?

said by funchords See Profile :

said by Necronomikro See Profile :

"The company, with 2,000 servers and 9Gbps of dedicated bandwidth at their disposal"

Sounds like a DDOS to me. May not have been distributed amongst many different networks, but it was many different computers within a high-speed network.
According to the logs that I saw, two IPTABLES entries would have solved it. It sounds like they made a last-minute change on a Friday and left town for the weekend. MediaDefender's buggy scripts went nuts.

This was "amateur hour" on both MediaDefenders and Revision3's accounts. That said, MediaDefender was the inflicter of damage and was the primary cause of this accident.
Doesn't matter what you do with iptables if you're sitting on a 100Mbps, or even 1Gbps port, and you have 9Gbps of traffic coming at you.
openbox9

join:2004-01-26
Alexandria, VA
·AT&T Southeast

Re: Illegal?

I doubt that MD was utilizing all 9 Gbps to flood Revision3. I haven't seen the logs that funchords See Profile is referring to, but iptables or PF, or pick your packet filter can be quite effective against rudimentary DoS attacks.

funchords
Hello
Premium,MVM
join:2001-03-11
Washington, DC
very true

GamerGeek

join:2003-07-26
Fortuna, CA

said by Crookshanks See Profile :

said by Matt See Profile :

Trying to establish 8000 new sessions a SECOND is a DDoS
Minor nitpick but I don't know as if I'd call that a 'DDoS'. DDoS == distributed denial of service attack and is typically something that is launched with thousands of different hosts on hundreds of different networks, usually using owned systems (via a botnet).

What Media Defender did definitely qualifies as a DoS but I'd question whether or not the usage of the term 'DDoS' is accurate here.
I'd be inclined to agree. Swap distributed for directed and it becomes exactly what MD planned.

burner50
Pinlifter
Premium,VIP
join:2002-06-05
EN22wm
·Mediacom
·FrontierNet Intern..

When the DoS attack is distributed over 2000 computers even if they are all in the same building IMO that is Distributed...

They DISTRIBUTED the DoS load over their entire server farm...

This company needs to go down.
--
I'm tired of killing stupid people just trying to do my job and go home!
Forums » More On Media Defender's Latest Screw UpWhat a moronic analogy »
« Required Topic  


Sunday, 06-Dec 03:01:49 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [128] Comcast Makes NBC Universal Acquisition Official
· [123] The Bandwidth Hog Does Not Exist
· [105] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [85] FCC Ponders Moving From PSTN To IP Voice
· [82] Latest Consumer Reports Survey Not Kind To AT&T
· [80] New Bill Aims To Limit ETFs
· [75] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Farewell [Bell Canada]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· [DNS] Google's public DNS... performance increases? [Comcast HSI]
· [Unlock] TUTORIAL: VONAGE WRTP54G/RTP300 WITH 5.01.04 [VOIP Tech Chat]
· Opening a file download dialog from a JavaScript function. [Webmasters and Developers]