In the past I had to do several DoS security audits, with múltiples types of tests and intensities. Sometimes several DDoS protections were present like Akamai for static content, and Arbor for absorb part of the bandwith.
One consideration for the DoS/DDoS tools is that probably it will loss the control of the attacker host, and the tool at least has to be able to stop automatically with a timeout, but can also implement remote response checks.
In order to size the minimum mbps needed to flood a service or to retard the response in a significant amount of time, the attacker hosts need a bandwith limiter, that increments in a logarithmic way up to a limit agreed with the customer/isp/cpd.
There are DoS tools that doesn't have this timeouts, and bandwith limit based on mbps, for that reason I have to implement a LD_PRELOAD based solution: bwcontrol
Although there are several good tools for stressing web servers and web aplications like apache ab, or other common tools used for pen-testing, but I also wrote a fast web flooder in c++ named wflood.
As expected the most effective for taking down the web server are the slow-loris, slow-read and derivatives, few host were needed to DoS an online banking.
Remote attacks to database and highly dynamic web content were discarded, that could be impacted for sure.
I did another tool in c++ for crafting massive tcp/udp/ip malformed packets, that impacted sometimes on load balancers and firewalls, it was vulcan, it freezed even the firewall client software.
The funny thing was that the common attacks against Akamai hosts, where ineffective, and so does the slow-loris family of attacks, because are common, and the Akamai nginx webservers are well tunned. But when tried vulcan, few intensity was enough to crash Akamai hosts.
Another attack vector for static sites was trying to locate the IP of the customer instead of Akamai, if the customer doesn't use the Akamai Shadow service, it's possible to perform a HTTP Host header scan, and direct the attack to that host bypassing Akamai.
And what about Arbor protection? is good for reducing the flood but there are other kind of attacks, and this protection use to be disabled by default and in local holidays can be a mess.
Related links
- Hack Tools Github
- Hak5 Tools
- What Is Hacking Tools
- Hacker Tools Linux
- Hak5 Tools
- Wifi Hacker Tools For Windows
- Tools Used For Hacking
- Computer Hacker
- Pentest Reporting Tools
- Hacker Tools Github
- Pentest Tools
- Pentest Tools Android
- Easy Hack Tools
- Hacking Tools For Windows
- Install Pentest Tools Ubuntu
- Hack Website Online Tool
- Hack Tool Apk
- Hacker Tools Github
- Bluetooth Hacking Tools Kali
- Pentest Box Tools Download
- Pentest Tools Website Vulnerability
- Pentest Tools Bluekeep
- Pentest Tools Website Vulnerability
- How To Make Hacking Tools
- Hacker Tools Software
- Hacker Tools Mac
- Pentest Tools
- Hack Tools For Games
- Hacking Tools For Windows
- Hacking Tools Name
- Pentest Tools List
- Hacking Tools For Windows Free Download
- Hacking Tools For Mac
- Hacker Tools Free
- Hacker Tools Apk Download
- Hack Tools For Games
- Tools Used For Hacking
- Underground Hacker Sites
- Hacking Tools Github
- Install Pentest Tools Ubuntu
- Hack Tools For Games
- Pentest Tools Review
- Hacking Tools Mac
- Tools For Hacker
- Hacker Tools Free
- Hacking Apps
- Hack Tools Pc
- Hacking Tools For Pc
- Pentest Automation Tools
- Pentest Tools
- How To Hack
- Beginner Hacker Tools
- Hacker Tools Free Download
- Hacker Hardware Tools
- Pentest Tools Android
- Pentest Tools Review
- How To Make Hacking Tools
- Hacking Tools 2019
- Hacker Tools For Mac
- Hack Tools Download
- Underground Hacker Sites
- What Is Hacking Tools
- Hacker Tools Mac
- Hack Website Online Tool
- Hack Tools 2019
- Growth Hacker Tools
- Pentest Tools
- Pentest Tools Github
- Hacker Tools
- How To Install Pentest Tools In Ubuntu
- Hacking Tools For Pc
- Hacker Tools Free Download
- Hacking Tools For Games
- Hacker Hardware Tools
- Hacking Tools And Software
- Easy Hack Tools
- Pentest Reporting Tools
- Pentest Tools Kali Linux
- Pentest Automation Tools
- Hack Tools Github
- Nsa Hack Tools Download
- Hacking Tools For Pc
- Hacking Tools And Software
- Hacker Tools Software
- Hacker Tools Free
- Nsa Hacker Tools
- Game Hacking
- Pentest Reporting Tools
- Pentest Tools Nmap
- Best Hacking Tools 2019
- Hacking Tools For Games
- Hackers Toolbox
- Hacker Tools Online
- Hack Tools
- Pentest Recon Tools
- Hacker Tools For Windows
- Hack Tools For Mac
- Nsa Hack Tools Download
- Hacking Tools For Pc
- Free Pentest Tools For Windows
- Hacking Tools 2019
- Hacker Tools Hardware
- Pentest Tools Find Subdomains
- Pentest Automation Tools
- Hacker Security Tools
- Hacker Tools For Mac
- Pentest Tools Bluekeep
- Hacker Tools Github
- Pentest Tools Free
- Beginner Hacker Tools
- Pentest Tools For Mac
- Game Hacking
- Hack Tools For Games
- Hacking Tools Software
- Pentest Tools Kali Linux
- Pentest Tools Website Vulnerability
- Tools Used For Hacking
- Pentest Tools For Android
- Hacker Tools
- How To Make Hacking Tools
- Tools Used For Hacking
- Hacker
- Pentest Tools Website
- Pentest Tools Subdomain
- Hack And Tools
- Hacker Tools List
- Pentest Tools Android
- Pentest Automation Tools
- New Hack Tools
- Beginner Hacker Tools
- Computer Hacker
- Hacking Tools Windows
- Kik Hack Tools
- Hacker Tools For Ios
- Pentest Tools Download
- Pentest Tools Tcp Port Scanner
- How To Hack
- What Are Hacking Tools
- Pentest Tools Linux
- Hacking Tools For Windows
- Tools For Hacker
- Hack Tool Apk No Root
- Hack Rom Tools
- Best Hacking Tools 2019
- Install Pentest Tools Ubuntu
- Blackhat Hacker Tools
- How To Install Pentest Tools In Ubuntu
- Hacker Tools 2019
ไม่มีความคิดเห็น:
แสดงความคิดเห็น