Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

When it comes to ip spoofing based ddos attacks, the ISPs capable of tracking spoofed traffic on their network don't allow spoofed traffic. If they don't allow the spoofed traffic, you aren't participating in the DDoS.


Absolutely. No ISP should allow a packet with a spoofed IP leave it's network.


Is there an easy way to figure out if it's possible on my ISP's network?


Run tcpdump on an ec2 instance and send spoofed traffic to it to see if it shows up. :)


It's about blocking non-spoofed attacks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: