HomeSecurityDoS Attacks

DoS Attacks

Year: 1999. Region: Attica. A fairly strong earthquake of magnitude 5.7 on the Richter scale, with its epicenter at Mount Parnitha hits the plain (and not only) at 14:57. Terrified, the residents take to the streets. They try to contact their own people. In vain! Mobile phones do not… respond! So what happened? Could any central OTE antenna have collapsed? Why do we have no communication? What happened?

Hmm… the obvious. What we used to say back then (we, the older ones!!) “blocked” the lines! The mobile carriers' databases were not prepared to handle such a large number of calls and “handed over” spirit or otherwise refused to serve and, in more Greek, they performed deny of services (DOS – do not confuse DOS (Denial Of Services) with the well‑known and not exceptional DOS (Disk Operating System) which as an operating system dominated the 10th decade of ’80. They are two completely different things.).

Without meaning to, the Athenians carried out a Denial Of Services (DOS attack) or better Distributed Denial Of Services (DDOS because there were more than… one, on the servers of mobile phone providers. A natural consequence is that these servers will “go down” unable to serve so many massive call requests!

Similar attacks can be carried out on any server or service system in general. Okay, we do not intend to do a systemic analysis (at least in this article!) but we should mention that such attacks are not always “by accident” or due to “conspiracies”. They can occur (intentionally or not) from a simple pc without internet connection to a… social system!! However, let's limit ourselves to our field, which concerns a more virtual world: the electronic one.

Every action that leads a system to be unable to respond to what it was built for can be classified (sometimes more, sometimes less) in the category of DOS attacks. That's what we commonly say: “What did you do there, kid? You broke it!!!” 😉

dos_pic1
Image 1: The classic Firefox screen that informs us that the server does not… respond!

In the world of computers, this phenomenon is quite common and we can divide it into two basic categories regarding the “intent” of the attacker. In the first category, we have good intentions. That is, there was no deceit, no intention to cause damage. We will not deal much with these attacks, we will simply mention an example:
Suppose we maintain a forum (let's say about security) on a server on the internet. Our forum is not very popular, at most about 10 people enter per day. At a given time, however, we discover a very large security “hole” in a very well-known operating system (we won't say names!! - no matter how hard you press us) and we publish it in a post with the title “Big Hole!”. The “Big Hole!” gets publicity and you mention it as a link on the well-known https://slashdot.org/, that is, on a site that receives about 200 thousand visits per day! Suddenly, hundreds of users start visiting our site to see the “Big Hole!” If our server is not ready to cope with the new conditions, it will simply stop serving calls (see image 1 – slashdot phenomenon!!). At the end of the article we will tell you some little secrets that could make our server able (or at least trying!) to respond to such situations.

dos_pic2
Image 2: The site of our well‑known, carefree before it receives the attack (here it appears in Firefox 3 from a Linux system)!

Let's now come to the dark side! The attacks that are made deliberately with the aim of stopping the server from responding. The types of attacks are very many (https://tinyurl.com/2c59m4) and we are not interested in their simple listing which can be found very easily on the net. After all, we are concerned with the… unorthodox approach to the issues 😉
we will present a real example of an attack (with all its… results!!) from Windows Vista. We will also show how such programs are made, showing a simple program in the perl language, this time on Linux Ubuntu. We will also show how we tested this program with a victim (this time)… ourselves! Finally, we will mention techniques for dealing with intentional or unintentional dos attacks.

Before we start, however, we must mention that the use and execution of programs for DOS attacks is strictly prohibited unless we are the owners of the site and the server is ours or we do it with the owner's consent! We want to emphasize that you should not make superficial or unauthorized use of anything presented below, as it is very likely that the administrator of the target server will take legal action against you and you could face serious penalties.

Attack from Windows Vista
The most common attack is to send random data – garbage (flood) to the server on which we want to test the strength. This data will be random bytes, kBytes or even Mbytes and will be sent by a program that will create (in memory) multiple connections (multiple asynchronous sockets) with the server to increase both the volume of data sent and the number of connections. The result as you will see is the denial of service from the server. The remarkable thing in this case is not so much the result as the… collateral losses as you will see below, as well as the reaction of the owner of the Host service who (admittedly) had every right to complain!!
So we will show you a real and “complete” cycle of an attack!

For this specific attack, we used a ready-made program that is commercially available and is used for “resistance” tests on servers from DOS attacks (servers crash tests). This program is DoSHTTP (figure 3) and you can download an evaluation version from the site of the company that created it (https://socketsoft.net/).

dos_pic3
Image 3: A program for testing “endurance” in a DOS attack (servers crash tests)

The site that will receive the attack is a Greek portal/forum (image 2) that concerns security, whose administrators we know and we had their consent. The only thing we had to do was run the program and provide the victim site's address (image 3). In the form fields we left the defaults: The user agent concerns the information of the http header and in the fields Sockets (connections) and Requests (type of requests) we set respectively 500 (connections) and continuous (continuous connections with the server – see more details below in “Protection Methods”). Pressing the “Start Flood” button the program started its marvelous work: to send thousands of requests to the server. While the program was running, we tried to access the site with Firefox. The results are shown in the image below:

dos_pic4
Image 4: The server (here specifically the SQL server)… “crashed”.

The server could not serve all the… requests and it “cut us off”. The response is quite classic for this type of attacks. However, our program after a short while finished, giving us important information:

dos_pic5
Image 5: After the end of the dOs we also have… statistical data!

Alright up to here! All good! Now the site (since our program has finished) should logically allow us access, right? Not at all! We logged in without the innkeeper. The company that has the site decided to cut off our access (not only for us but for everyone) to this site, as shown by the image below.

dos_pic6
Image 6: We have the site's statistics… but we don't have the site itself!

The owning company, noticing a DoS attack, redirected the site to the page you see in image 6 and locked the administrators' accounts as well as any access to it (such as ftp etc.)!

From here on, a round of negotiations begins (with emails etc.) to convince the hosting company that the attach was for testing purposes.
For your information, we show you the company's first response when we asked them to restore the site:

Why would you do that ?

You are on a shared server and you are effecting other customers on the server.

We will not unsuspended you.
Thank You,
Gxxxxxxxx Wxxxxxxxx

www.webhostingpad.com

Ticket Details
===================
Ticket ID: Nxxxxxxxxxxx
Department: Manager
Priority: High
Status: Closed

More at: p0wnbox.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS