So perhaps the next wave of booter sites can avoid scrutiny by adding a dialog asking the customer if they own the target or are authorized to attack it (in addition to not publishing ads advertising targets like websites and game servers) ?
So perhaps the next wave of booter sites can avoid scrutiny by adding a dialog asking the customer if they own the target or are authorized to attack it (in addition to not publishing ads advertising targets like websites and game servers) ?
Also keep in mind that a DDoS affects infrastructure on the way whose operators have not consented.
I don't really think there's an ethical way to run a DDoS "stresser" service on the public Internet.
Typically a service using domain verification will ask you to create a specific, randomly generated TXT or similar record on your domain. After you’ve created the record you click a button or something and they do a query for it.
Only someone with access to DNS for the domain can create such a record.
Suppose:
EXAMPLE.VICTIM.XYZ -> A 1.2.3.4
EXAMPLE.ATTACKER.XYZ -> A 1.2.3.4
EXAMPLE.ATTACKER.XYZ -> TXT whatever verification is needed
DDoSes operate on IPs, not dns names. In the end, the target IP is getting DDoSed anyway.Yes, of course DDoS or any kind of traffic can be pointed at an IP or any arbitrarily created DNS record.
The only way for a “reputable” stress testing platform to validate IP space would be RIR validation via WHOIS or similar, PTR records, etc. Of course this isn’t practical because most people don’t control their IP space or even have the foggiest idea what any of that means (because why should they).
That's why OP specified their DNS record. You buy/use a random domain name you own, point the A record at the IP you wish to attach, and then simply complete the TXT record verification since you have full control over the domain, while the booter resolves the A record to the true target.
How else do you imagine this working?
No, most (?) DDoS attacks aren’t botnets sending HTTP requests directly, those would have terrible throughput and be trivial to mitigate. Instead they use amplification from third party servers where you send a small packet to get a big packet in response, mistakenly routed to the victim. There’s usually no way to attach a Referer to those, most of which aren’t even HTTP-based.
Evil haxxxor: creates domain name pointed at target it doesn’t own
Innocent stress test site: prove you own this domain by adding cname in the DNS record
EH: sure, heh heh heh
ISTS: performs ddos against target
Requiring the owner to post a file at a specific URL would prove actual control of the server in a way that domain records don't. I can point a domain at whatever server I want, no need for it to be my own.
That should work.
The only way I can think around that would be to have a reverse proxy that forwards most traffic but not requests for that one file, but then your DDoS isn't actually distributed.
I create my own SharedPHPHosting site, host the file, and point the stress testing site at it. Both my site and my victim's site are down. Success.
I believe "neocities" uses the same IP and servers for all neocities websites, so there's another example where this would work.
2. Hurt your competition. In some online businesses DDoS attacks are used to compete with other businesses since if your competitor is offline more people will come to you.
3. Power. Some people want to flex the power they have over others.
4. Fame. You can get notoriety for taking something offline.
Dont like what a site is saying? DDOS so it cant load and people cant read it. For bonus points you are preventing site from getting clicks and thus ad revenue.
There are communities on discord that setup donation links to make sure sites they dont like keep getting hit by DDOS via crowdfunding.
The company I work for actually contemplated creating such a service (strictly for testing purposes, which is our business), and one of the major problems was that we would actually need to have contracts with all ISPs and transit providers that the traffic would pass through, even if we could make sure that the destination was owned by whoever was paying for the test.