+ All Categories
Home > Economy & Finance > Denial Of services

Denial Of services

Date post: 18-May-2015
Category:
Upload: ammar-wk
View: 1,095 times
Download: 3 times
Share this document with a friend
Popular Tags:
36
Ahmad Muammar W. K. http://google.com/search?q=y3dips
Transcript
Page 1: Denial Of services

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 2: Denial Of services

http://google.com/search?q=y3dips

DOSTypesSimulationInternet WormDDOSDiscussion

Details

Page 3: Denial Of services

http://google.com/search?q=y3dips

A denial-of-service attack is an attack on a computer system or network that causes a loss of service to users

DOS

Page 4: Denial Of services

http://google.com/search?q=y3dips

MotivesMoneyRevengePrestigeGaining AccessPolitic

Page 5: Denial Of services

http://google.com/search?q=y3dips

DOS HistoryClassical DOS Internet WormsDdos

Page 6: Denial Of services

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 7: Denial Of services

http://google.com/search?q=y3dips

Classical DOSApplication BugConsumption of computational resourcesDisabling web trafficMail bombing

Page 8: Denial Of services

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 9: Denial Of services

http://google.com/search?q=y3dips

TCP syn floodICMP/UDP/ECHO (ping) to broadcast addresses ( SMURF)Out of Band (oob) Attack (winnuke:139) ARP poisoningPing of Death (win95)Port flooding Mail bombing

Some Examples/Types

Page 10: Denial Of services

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 11: Denial Of services

http://google.com/search?q=y3dips

Mass Spamming?A Real Life ExampleUsing SMTPEasy Proof Of concept

Page 12: Denial Of services

Reply to : [email protected]

Sender : [email protected]

To : xxx@multiple server

Received : [email protected]

Mail Server A

Mail Server B

Mail Server C

Page 13: Denial Of services

http://google.com/search?q=y3dips

<?

$recipient = “xxx@multiple mailserver";

$subject = “fake";

$mailheaders = "From: [email protected] \n";

$mailheaders .= "Reply-To: [email protected]\n";

$msg= "\nIts a spam\n";

mail($recipient, $subject, $msg, $mailheaders) or die (“tidak terkirim!");

?>

Page 14: Denial Of services
Page 15: Denial Of services

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 16: Denial Of services

http://google.com/search?q=y3dips

ApplicationServicesSystem

CPUMemoryRamNetworking

DDOS against

Page 17: Denial Of services

http://google.com/search?q=y3dips

DDos Against IEInternet Explorer is Microsoft Windows Web browserSome Version has hole in XML scriptError in Application

Page 18: Denial Of services

<!-- Discovered byInge Henriksen ([email protected]) http://ingehenriksen.blogspot.com/--><table>

<tr><td><IMG align=left>X X X<?xml:namespace prefix=v>

<v:X style="HEIGHT:1"></td></tr>

</table>

Page 19: Denial Of services

http://google.com/search?q=y3dips

Apache is a free web server Some Version vulnerable to this kind of DosServer temporary down

DDos Against Apache

Page 20: Denial Of services
Page 21: Denial Of services

http://google.com/search?q=y3dips

Limited ResourcesMultiple ProcessSome Infinite loop wouls suck more resources

DDos Against cpu, memory, ram

Page 22: Denial Of services
Page 23: Denial Of services
Page 24: Denial Of services

http://google.com/search?q=y3dips

Flooding the networkCut all trafficFill the bandwidth

DDos Against Network

Page 25: Denial Of services
Page 26: Denial Of services

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 27: Denial Of services

http://google.com/search?q=y3dips

WormA computer program which replicates itself and is self-propagating. Worms, as opposed to viruses, are meant to spawn in network environments.

Page 28: Denial Of services

http://google.com/search?q=y3dips

WormActive propagated itself Combine With sytem/application hole Ddos Agent/zombie

web traffic flooding

Mass war machine

Resources Take Over

Page 29: Denial Of services
Page 30: Denial Of services

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 31: Denial Of services

http://google.com/search?q=y3dips

Distributed AttackMultiple ImpactZombie/Agent

D dos

Page 32: Denial Of services

http://google.com/search?q=y3dips

Any types of Dos ttack

Single user Target

Page 33: Denial Of services

Attacker

zombie

zombie

zombie

zombiezombie

zombie

Target

Page 34: Denial Of services

Ahmad Muammar W. K.http://google.com/search?q=y3dips

Page 35: Denial Of services

http://google.com/search?q=y3dips

Survive (mitigate Ddos)Network ConfigurationChange IP AddressStrong peripheral

Filtering Technique (signatures of the traffic)Some Mirror/Backup

Page 36: Denial Of services

Ahmad Muammar W. K.http://google.com/search?q=y3dips


Recommended