Types of DoS attacks 08-04-2014, 05:25 PM
#1
Note: This thread is primarily about educating users about methods malicious hackers use to attack web services. This is not an endorsement to use any of these methods against services you do not own, or do not have permission to test.
A common misconception is that DoS attacks and DDoS attacks are different things. DDoS is in fact a variety of a DoS attack. DoS (denial of service) attacks aim to make a service unavailable to an end user. DDoS attacks (Distributed denial of service) do the same things, but use multiple attackers.
There are two categories of DoS attacks: Layer 3/4 and Layer 7.
![[Image: OSI-Layer-Functions.jpg]](http://ddosattackprotection.org/blog/wp-content/uploads/2013/12/OSI-Layer-Functions.jpg)
As seen in the image, Layer 3/4 work by attempting to flood the network, ports, or the service itself by sending a wave of fake requests. Most layer 3/4 attacks are DDoS, normally perpetrated by a botnet, or other large network of computers that can generate enough traffic to take a website down. Common attacks: SYN Flood, UDP/TCP Flood
You can protect yourself (or your services) from these attacks by using a firewall to filter out bad traffic, a proxy or CDN to make an attacker hit the wrong IP address, or upgrading your network/hardware to allow more traffic. Large websites or servers may benefit by paying for a DDoS protection service.
Layer 7 attacks are almost always DoS. These attack work by exploiting weaknesses or design flaws in software, causing it to crash. These attacks are also known as "application level", as they only target applications on a web host. When you are under a Layer 7 attack, you will most likely not notice a large increase in traffic, as most of these attacks send very few packets. Common attacks: Slowloris, RUDY, HTTP POST
Blocking Layer 7 attacks is much more difficult than Layer 3/4 as there is no large increase in traffic volume. Most Layer 7 attacks exploit vulnerabilities in software, so keeping software up-to-date is paramount. As well, you can secure small services from the public eye by using an IP whitelist for access, and blocking failed access attempts.
A common misconception is that DoS attacks and DDoS attacks are different things. DDoS is in fact a variety of a DoS attack. DoS (denial of service) attacks aim to make a service unavailable to an end user. DDoS attacks (Distributed denial of service) do the same things, but use multiple attackers.
There are two categories of DoS attacks: Layer 3/4 and Layer 7.
![[Image: OSI-Layer-Functions.jpg]](http://ddosattackprotection.org/blog/wp-content/uploads/2013/12/OSI-Layer-Functions.jpg)
As seen in the image, Layer 3/4 work by attempting to flood the network, ports, or the service itself by sending a wave of fake requests. Most layer 3/4 attacks are DDoS, normally perpetrated by a botnet, or other large network of computers that can generate enough traffic to take a website down. Common attacks: SYN Flood, UDP/TCP Flood
You can protect yourself (or your services) from these attacks by using a firewall to filter out bad traffic, a proxy or CDN to make an attacker hit the wrong IP address, or upgrading your network/hardware to allow more traffic. Large websites or servers may benefit by paying for a DDoS protection service.
Layer 7 attacks are almost always DoS. These attack work by exploiting weaknesses or design flaws in software, causing it to crash. These attacks are also known as "application level", as they only target applications on a web host. When you are under a Layer 7 attack, you will most likely not notice a large increase in traffic, as most of these attacks send very few packets. Common attacks: Slowloris, RUDY, HTTP POST
Blocking Layer 7 attacks is much more difficult than Layer 3/4 as there is no large increase in traffic volume. Most Layer 7 attacks exploit vulnerabilities in software, so keeping software up-to-date is paramount. As well, you can secure small services from the public eye by using an IP whitelist for access, and blocking failed access attempts.
Pay respects to the malformed SYN packet.




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)











![[Image: 7ajmN5P.jpg]](https://i.imgur.com/7ajmN5P.jpg)
![[Image: jWSyE88.png]](http://i.imgur.com/jWSyE88.png)