How does IP spoofing even work outside of those DNS reflection attacks mentioned on Krebs' blog? [1]
> "many were garbage Web attack methods that require a legitimate connection between the attacking host and the target, including SYN, GET and POST floods."
I constantly see references relating to DDoS attacks about how IP spoofing is such an obvious trick to use but I've never seen any way to actually do it. Why wouldn't every device on the internet spoof their IP?
[1] https://web.archive.org/web/20160922021000/http://krebsonsec...