Possible flaw in LOIC - Tool used to DDoS Amazon
blog.unixy.net
blog.unixy.net
https://github.com/NewEraCracker/LOIC/
A quick skim-read of the code mentioned in the post shows that this version seems to be different, specifically:
https://github.com/NewEraCracker/LOIC/blob/master/HTTPFloode...
if (random == true)
buf = System.Text.Encoding.ASCII.GetBytes(
String.Format("GET {0}{1} HTTP/1.1{2}Host: {3}{2}{2}{2}",
Subsite, new Functions().RandomString(), Environment.NewLine, Host));
else
buf = System.Text.Encoding.ASCII.GetBytes(
String.Format("GET {0} HTTP/1.1{1}Host: {2}{1}{1}{1}",
Subsite, Environment.NewLine, Host));
(botched indentation is my own)The Host header mentioned in the blog post is present, the protocol is now HTTP/1.1 and random string appears to be an attempt to defeat a simple packet matching algorithm.
I doubt many legitimate requests these days come without a User-Agent header, though...
These problems are really easy to fix, so I'm not sure whether it's worth discussing them; most people on HN aren't in a position to actually implement countermeasures to this tool, and there's nothing conceptually interesting about it to learn from.
Since most modern browsers send HTTP/1.1 requests, they may be able to filter by ignoring HTTP/1.0 traffic in general.
Thanks for the bug report :)1) It's not just LOIC users DDoSing. There are usually small to medium sized botnets involved, especially on big attacks.
2) You said it yourself - there are tens of thousands of clients involved, and it's often difficult to tell because of #3 (unless there's a TCP/UDP message specified, which is a surefire way to ID attacks)
3) Most LOIC users use the /hivemind option, which turns control over to a master in an IRC channel. It can selectively throttle (most) clients, and spread the work around the net to make the attack more difficult to block.
4) They've got a standard line for getting caught[1] (sorry for the offensive URL)
The other thing to note is the time and expense involved in trying to identify and prosecute a few thousand people for participating would be enormous. We'll have to see if they try this time.
Joke aside, Host: is optional in HTTP/1.0 (it's mandatory in HTTP/1.1). I would not be surprised if blocking on this cut out some set of proxies and spiders out there as well (whether these are customers you can't afford to block is another question).