Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Peer-to-peer networks co-opted for DOS attacks
Robert Lemos, SecurityFocus 2007-05-28

A flaw in the design of a popular peer-to-peer network software has given attackers the ability to create massive denial-of-service attacks that can easily overwhelm corporate Web sites, a security firm warned last week.

Comments Mode:
Peer-to-peer networks co-opted for DOS attacks 2007-05-29
Fulgan (1 replies)
Proof that some people shouln't be trusted with a compiler or even a text editor......

[ more ]  [ reply ]
Re: Peer-to-peer networks co-opted for DOS attacks 2007-05-30
Brotherred (1 replies)
It seems to me that if one knows that an attack is coming from people hired by their competitors then there should be proof of this unlawful business transaction just waiting to be found. I will never believe that restricting a law abiding persons rights is a real fix for anything. Yes that does sou...

[ more ]  [ reply ]
Re: Re: Peer-to-peer networks co-opted for DOS attacks 2007-05-30
Ken (1 replies)
The problem with this (and the gun control arguement) rights related arguement is the inherent lack of responsibility we tie to rights. We don't tie the "right" to own a gun to the reponsibility that should be assumed by the "right holder" should that gun is used in the commission of an offence. If ...

[ more ]  [ reply ]
Re: Re: Re: Peer-to-peer networks co-opted for DOS attacks 2007-05-31
chaosuk
We are not machines, you cant have one rule for one person and not his neighbour. Every indiviudal is ultimately responsible for his or her actions in this life. The buck stops with he who actually pulled the trigger not he who told him to do it or he who provided him the means....

[ more ]  [ reply ]
Peer-to-peer networks co-opted for DOS attacks 2007-05-29
lsi
Is the flaw really in the server software, or actually in the protocol which permits servers to instruct clients to request information from a specific IP?

Perhaps a new version of the DC++ client that failed to honour this part of the protocol would help....

[ more ]  [ reply ]
DC++ hub software 2007-05-30
PPK
DC++ hub software compatible with Direct Connect protocol (DCH++) have fix, but this software is used with less than 0.01 % of hubs. It's not used with more hubs because use too much resources, don't have features needed by hub owners, is not available to download anymore and license don't allowing ...

[ more ]  [ reply ]
"It's difficult to impossible to restrict this"? 2007-05-30
Anonymous (1 replies)
Why don't DC++ clients ignore this stupid feature, at least by default, since 2 years ago when this attack was publicised? If they had, this would be a relatively minor problem now....

[ more ]  [ reply ]
Re: "It's difficult to impossible to restrict this"? 2007-05-31
Vektor
The idea of Direct Connect is to allow users connect to each other. Restricting user connections would turn Direct Connect into IRC....

[ more ]  [ reply ]
Peer-to-peer networks co-opted for DOS attacks 2007-05-30
Chris G.
All of these funny suggestions to have clients ignore this and that are nonsense. That would cripple the way their product works. This week it's DC++. Last week it was IRC. before that it was whatever. There will always be a DDOS threat. blaming the source is not the answer. it's like playing...

[ more ]  [ reply ]
Firewall that filters garbage traffic 2007-05-31
Vektor
There is already a firewall solution that detects and filters all IPs involved in a DDoS attack caused by using the Direct Connect exploit and an implementation of a server that uses it. The firewall can also be used by other servers.

Documentation and sourcecode for it can be found here: http://so...

[ more ]  [ reply ]
Peer-to-peer networks co-opted for DOS attacks 2007-05-31
Anonymous (1 replies)
I think this problem has been typically simplified and many facts surrounding the demise of some of the DC++ projects are missing. The opinions of those who directly suffered at the hands of the so called 'groups' of attackers are biased and rightly so. This however, allows some of the most importan...

[ more ]  [ reply ]
Re: Peer-to-peer networks co-opted for DOS attacks 2007-07-09
Anonymous
The firewall mentioned above does filter the traffic of DDoS and even can help you identify the hub source of attack.

Plus it is not the ISP fault for the traffic but the hub owners ignorance and lack of interest in solvating the problem.

...

[ more ]  [ reply ]
Peer-to-peer networks co-opted for DOS attacks 2009-05-07
Anonymous
Protip: Vektor is one of those "rouge DC users" that caused the attacks with a group named TeamElite. Shocker how he uses the same nick everywhere eh Lord_Zero :P...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus