<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Trehb101.com - Got Geek? &#187; DDoS</title>
	<atom:link href="http://www.trehb101.com/index.php/tag/ddos/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.trehb101.com</link>
	<description>Information Security : Technology : Project Management : Life</description>
	<lastBuildDate>Thu, 31 Mar 2011 22:23:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>CISSP Exam Note (Domain 2: Telecommunications and Networking Security) – Denial of Service Attack</title>
		<link>http://www.trehb101.com/index.php/2009/12/10/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-denial-of-service-attack/</link>
		<comments>http://www.trehb101.com/index.php/2009/12/10/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-denial-of-service-attack/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 17:25:44 +0000</pubDate>
		<dc:creator>TheDon</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Systems]]></category>
		<category><![CDATA[Buffer Overflow]]></category>
		<category><![CDATA[CISSP Exam]]></category>
		<category><![CDATA[CISSP Notes]]></category>
		<category><![CDATA[CISSP reviewer]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[denial of service]]></category>
		<category><![CDATA[Distributed Denial of Service Attack]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Fraggle]]></category>
		<category><![CDATA[Smurf]]></category>
		<category><![CDATA[SYN Attack]]></category>
		<category><![CDATA[Teardrop]]></category>

		<guid isPermaLink="false">http://www.trehb101.com/?p=249</guid>
		<description><![CDATA[A denial-of-service attack (DoS attack) or distributed denial-of-service attack (DDoS attack) is an attempt to make a computer resource unavailable to its intended users. Although the means to carry out, motives for, and targets of a DoS attack may vary, it generally consists of the concerted efforts of a person or people to prevent an Internet site or service from functioning efficiently or at all, temporarily or indefinitely. Perpetrators of DoS attacks typically target sites or services hosted on high-profile web servers such as banks, credit card payment gateways, and even root nameservers.]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Stachledraht DDos Attack" src="http://upload.wikimedia.org/wikipedia/commons/thumb/3/3f/Stachledraht_DDos_Attack.svg/424px-Stachledraht_DDos_Attack.svg.png" alt="" width="284" height="403" />A denial-of-service attack (DoS attack) or distributed denial-of-service attack (DDoS attack) is an attempt to make a computer resource unavailable to its intended users. Although the means to carry out, motives for, and targets of a DoS attack may vary, it generally consists of the concerted efforts of a person or people to prevent an Internet site or service from functioning efficiently or at all, temporarily or indefinitely. Perpetrators of DoS attacks typically target sites or services hosted on high-profile web servers such as banks, credit card payment gateways, and even root nameservers.</p>
<p>One common method of attack involves saturating the target (victim) machine with external communications requests, such that it cannot respond to legitimate traffic, or responds so slowly as to be rendered effectively unavailable. In general terms, DoS attacks are implemented by either forcing the targeted computer(s) to reset, or consuming its resources so that it can no longer provide its intended service or obstructing the communication media between the intended users and the victim so that they can no longer communicate adequately.<span id="more-249"></span>Denial-of-service attacks are considered violations of the IAB&#8217;s Internet proper use policy, and also violate the acceptable use policies of virtually all Internet Service Providers. They also commonly constitute violations of the laws of individual nations. (Source: <a href="http://en.wikipedia.org/wiki/Denial-of-service_attack" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/Denial-of-service_attack?referer=');">http://en.wikipedia.org/wiki/Denial-of-service_attack</a>)</p>
<p><!--Start CISSP ebook ad--></p>
<table border="0" width="100%">
<tbody>
<tr>
<td bgcolor="#ffcc99">
<h1 style="text-align: center;"><strong>Planning to take the CISSP Exam? </strong></h1>
<h2><strong>Get a copy of my personal notes (300plus pages worth) that I used to pass the exam for only <span class="style1">$25.00</span>.</strong></h2>
<div><strong> </strong></p>
<div class="wp-caption alignleft" style="width: 110px"><strong><strong><a href="http://www.trehb101.com/index.php/2009/11/18/cissp-review-notes-notes-i-used-to-pass-the-exam/"><img title="CISSP Exam Review Notes" src="http://www.trehb101.com/images/entries/CISSP-Review-Notes-PACK-small.png" alt="Click the Add To Cart Button to Purchase" width="100" height="192" /></a></strong></strong><p class="wp-caption-text">Click the Add To Cart Button to Purchase</p></div>
<p><strong>Plus you will also get copies of notes from other CISSPs. </strong></p>
<p><strong>Learn more about this package by visiting this blog entry: <a href="http://www.trehb101.com/index.php/2009/11/18/cissp-review-notes-notes-i-used-to-pass-the-exam/">CISSP REVIEW NOTES I USED TO PASS THE  EXAM. </a></strong></div>
<p style="text-align: center;" align="center"><strong>CLICK BELOW TO MAKE YOUR PURCHASE NOW. </strong></p>
<p style="text-align: center;" align="center"><strong><object><form method="post"  action=""  style="display:inline" onsubmit="return ReadForm(this, true);"><input type="submit" value="Add to Cart" /><input type="hidden" name="product" value="CISSP Review Notes Package" /><input type="hidden" name="price" value="25.00" /><input type="hidden" name="product_tmp" value="CISSP Review Notes Package" /><input type="hidden" name="addcart" value="1" /></form></object></strong></p>
<p style="text-align: center;" align="center">All Purchases are securely processed through Paypal. Once you click the button please check your shopping cart at the upper right hand side of the page to complete your order.</p>
<p style="text-align: center;" align="center"><strong>IMPORTANT NOTICE: </strong></p>
<p style="text-align: center;" align="center">I  MANUALLY REVIEW ALL ORDERS. SO ONCE YOU PURCHASE THE PRODUCT, THERE  WILL BE SOME DELAY ON YOU RECEIVING AN E-MAIL FROM ME WITH THE LINK TO  THE DOWNLOAD AREA OF THE PRODUCT. YOU WILL GET A RESPONSE FROM ME  WITHIN 24-48 HOURS.</p>
</td>
</tr>
</tbody>
</table>
<p><!--End CISSP ebook ad--></p>
<p><strong>Common DoS Attacks</strong></p>
<ul>
<li>Filling hard drive space with e-mail attachments</li>
<li>Sending a message that resets a targets host      subnet mask causing routing disruption</li>
<li>Using up all the target’s resources to accept      network connections</li>
</ul>
<p><strong>Additional DoS Attacks</strong></p>
<ul>
<li>Buffer Overflow Attack
<ul>
<li>When a process receives much more data that       expected</li>
<li>Since buffers are created to contain a finite       amount of data, the extra information, which has to go somewhere – can       overflow in adjacent buffers, corrupting or overwriting the valid data       held in them</li>
<li>PING – Packet Internet Groper – uses ICMP –       Internet Control Message Protocol</li>
<li>PING of Death – Intruder sends a PING that consists of an illegally modified and       very large IP datagram, thus overfilling the system buffers and causing       the system to reboot or hang</li>
</ul>
</li>
<li>SYN Attack
<ul>
<li>Attacks the buffer space during a TCP handshake</li>
<li>Attacker f;ppds the target system’s “in-process”       queue with connection requests causing the system to timeout</li>
</ul>
</li>
<li>Teardrop Attack
<ul>
<li>Modifying the length of the fragmentation fields       in the IP packet</li>
<li>When a machine receives this attack, it is       unable to handle the data and can exhibit behavior ranging from a lost       Internet connection to the infamous BSOD, the machine becomes confused       and crashes</li>
</ul>
</li>
<li>Smurf Attack
<ul>
<li>Source site sends spoofed network requests to a       large network (bounce site) and all machines responds to a target site</li>
<li>Exploits IP broadcast addressing</li>
</ul>
</li>
<li>Fraggle Attack
<ul>
<li>“Cousin” of the Smurf Attack</li>
<li>uses UDP echo packets in the same fashion as the       ICMP echo packet</li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.trehb101.com/index.php/2009/12/10/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-denial-of-service-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

