• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 13:23
CEST 19:23
KST 02:23
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL21] Ro24 Preview Pt2: News Flash1[ASL21] Ro24 Preview Pt1: New Chaos0Team Liquid Map Contest #22 - Presented by Monster Energy9ByuL: The Forgotten Master of ZvT30Behind the Blue - Team Liquid History Book20
Community News
Weekly Cups (March 16-22): herO doubles, Cure surprises3Blizzard Classic Cup @ BlizzCon 2026 - $100k prize pool48Weekly Cups (March 9-15): herO, Clem, ByuN win42026 KungFu Cup Announcement6BGE Stara Zagora 2026 cancelled12
StarCraft 2
General
Team Liquid Map Contest #22 - Presented by Monster Energy What mix of new & old maps do you want in the next ladder pool? (SC2) Potential Updates Coming to the SC2 CN Server Behind the Blue - Team Liquid History Book herO wins SC2 All-Star Invitational
Tourneys
RSL Season 4 announced for March-April Sparkling Tuna Cup - Weekly Open Tournament StarCraft Evolution League (SC Evo Biweekly) WardiTV Mondays World University TeamLeague (500$+) | Signups Open
Strategy
Custom Maps
[M] (2) Frigid Storage Publishing has been re-enabled! [Feb 24th 2026]
External Content
The PondCast: SC2 News & Results Mutation # 518 Radiation Zone Mutation # 517 Distant Threat Mutation # 516 Specter of Death
Brood War
General
[ASL21] Ro24 Preview Pt2: News Flash Pros React To: SoulKey vs Ample ASL21 General Discussion RepMastered™: replay sharing and analyzer site KK Platform will provide 1 million CNY
Tourneys
[ASL21] Ro24 Group D [ASL21] Ro24 Group C [Megathread] Daily Proleagues [ASL21] Ro24 Group B
Strategy
What's the deal with APM & what's its true value Fighting Spirit mining rates Simple Questions, Simple Answers
Other Games
General Games
General RTS Discussion Thread Nintendo Switch Thread Stormgate/Frost Giant Megathread Darkest Dungeon Path of Exile
Dota 2
The Story of Wings Gaming Official 'what is Dota anymore' discussion
League of Legends
G2 just beat GenG in First stand
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Five o'clock TL Mafia Mafia Game Mode Feedback/Ideas Vanilla Mini Mafia
Community
General
US Politics Mega-thread The Games Industry And ATVI European Politico-economics QA Mega-thread Canadian Politics Mega-thread Russo-Ukrainian War Thread
Fan Clubs
The IdrA Fan Club
Media & Entertainment
[Manga] One Piece [Req][Books] Good Fantasy/SciFi books Movie Discussion!
Sports
Formula 1 Discussion 2024 - 2026 Football Thread Cricket [SPORT] Tokyo Olympics 2021 Thread General nutrition recommendations
World Cup 2022
Tech Support
[G] How to Block Livestream Ads
TL Community
The Automated Ban List
Blogs
Funny Nicknames
LUCKY_NOOB
Money Laundering In Video Ga…
TrAiDoS
Iranian anarchists: organize…
XenOsky
FS++
Kraekkling
Shocked by a laser…
Spydermine0240
ASL S21 English Commentary…
namkraft
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1336 users

Solution to DDoS issues for streamers and players - Page 3

Forum Index > SC2 General
Post a Reply
Prev 1 2 3 4 5 6 Next All
Moderator note: The instructions in this thread will do nothing to protect you from a DDoS attack. The only way to prevent an attack is to avoid your IP address becoming public.
nemonic
Profile Joined November 2011
132 Posts
September 03 2012 21:28 GMT
#41
On September 04 2012 06:25 LunaSea wrote:
Show nested quote +
On September 04 2012 06:17 trGKakarot wrote:
On September 04 2012 06:15 LunaSea wrote:
On September 04 2012 06:13 trGKakarot wrote:
I will admit I only skimmed this thread (since it seems like if somebody solved DDoS attacks they would be getting a lot more traction than a random thread on TL), but from what I gather the OP is assuming that an ISP will send an infinite amount of data to your router and filtering out bad IP addresses at your router level will solve the problem since then you only accept "x" amount of data?


Yes, except it's not your ISP sending the data originally, but a bunch of hacked computers rented by a random kid.


Right, but you are only connected to the outside world through your ISP (unless they are somehow on your intranet, which means you have a bigger problem).

Maybe I am missing something...


Yes but what I meant is this :

A --> sends a packet to B --> who forwards it to C

Where :

A is the attacker,
B your ISP,
and C is you.

A is the one the packets originate from and B only forwards it to the destination indicated in the packet.


Why would that matter at all?

The thing is simply that some host in the internet bombs your IP with packets, and your ISP will forward all these packets until they reach your router. You are free to drop them at the router level, but the bottleneck is between you and your ISP. Filtering at the router has no effect whatsoever in the scenario of a (D)DoS as the bottleneck will also be choked no matter what you filter at the router.
Cinim
Profile Joined April 2011
Denmark866 Posts
Last Edited: 2012-09-03 21:38:09
September 03 2012 21:28 GMT
#42
On September 04 2012 05:13 Tao367 wrote:
Show nested quote +
On September 04 2012 05:07 Pumplekin wrote:
I'm not meaning to be offensive here, but the vast majority of this advice is just straight up wrong to the point it isn't worth reading.

Blocking a denial of service attack on a home based router is going to do nothing, the problem is the buffer in whatever access device lives at your ISP. If you have 10mbit downstream at home and you want to use it all, and I'm throwing 1gbit of garbage at your IP address, only around 1 in 100 of your legitimate packets is going to make it, the rest are going to be discarded before they even get to your home router, so no matter what filtering you apply on it, it isn't going to help you.

The real solutions to DDoS for the home streamer are :-

1.) Don't leak your IP address (and stuff like IRC without host hiding, Skype and other IM programs and I'm sure many other things can make this hard to do).
2.) Don't anger the internet bad guys (yeah, sometimes that is just impossible).
3.) Be very friendly with your ISP support staff (as the standard ISP response to a major DDoS is going to be to null route at the ISP's borders to protect other customers).


Pretty sure there is no way to discover ip's through skype/other IM services, if there was there would be huge news about it.


Skype etc. is actually THE way that people gather IP adresses, and it's not news, most people have known it for many years now, nothing new... if just all providers would provide static IP adresses there wouldn't be any issues )

Edit: dynamic, not static
Hell, it's about time
trGKakarot
Profile Joined October 2011
United States129 Posts
September 03 2012 21:29 GMT
#43
On September 04 2012 06:25 LunaSea wrote:
Show nested quote +
On September 04 2012 06:17 trGKakarot wrote:
On September 04 2012 06:15 LunaSea wrote:
On September 04 2012 06:13 trGKakarot wrote:
I will admit I only skimmed this thread (since it seems like if somebody solved DDoS attacks they would be getting a lot more traction than a random thread on TL), but from what I gather the OP is assuming that an ISP will send an infinite amount of data to your router and filtering out bad IP addresses at your router level will solve the problem since then you only accept "x" amount of data?


Yes, except it's not your ISP sending the data originally, but a bunch of hacked computers rented by a random kid.


Right, but you are only connected to the outside world through your ISP (unless they are somehow on your intranet, which means you have a bigger problem).

Maybe I am missing something...


Yes but what I meant is this :

A --> sends a packet to B --> who forwards it to C

Where :

A is the attacker,
B your ISP,
and C is you.

A is the one the packets originate from and B only forwards it to the destination indicated in the packet.


Right, but B cannot send an unlimited amount of data to C, so if A floods B with 1,000,000 packets to go to C then the other data which B was going send to C might not get sent.

So doing something at the C end doesn't seem like it would help ... right?
hihi glgl
nemonic
Profile Joined November 2011
132 Posts
September 03 2012 21:34 GMT
#44
On September 04 2012 06:28 Cinim wrote:
Show nested quote +
On September 04 2012 05:13 Tao367 wrote:
On September 04 2012 05:07 Pumplekin wrote:
I'm not meaning to be offensive here, but the vast majority of this advice is just straight up wrong to the point it isn't worth reading.

Blocking a denial of service attack on a home based router is going to do nothing, the problem is the buffer in whatever access device lives at your ISP. If you have 10mbit downstream at home and you want to use it all, and I'm throwing 1gbit of garbage at your IP address, only around 1 in 100 of your legitimate packets is going to make it, the rest are going to be discarded before they even get to your home router, so no matter what filtering you apply on it, it isn't going to help you.

The real solutions to DDoS for the home streamer are :-

1.) Don't leak your IP address (and stuff like IRC without host hiding, Skype and other IM programs and I'm sure many other things can make this hard to do).
2.) Don't anger the internet bad guys (yeah, sometimes that is just impossible).
3.) Be very friendly with your ISP support staff (as the standard ISP response to a major DDoS is going to be to null route at the ISP's borders to protect other customers).


Pretty sure there is no way to discover ip's through skype/other IM services, if there was there would be huge news about it.


Skype etc. is actually THE way that people gather IP adresses, and it's not news, most people have known it for many years now, nothing new... if just all providers would provide static IP adresses there wouldn't be any issues )


You mean dynamic IP addresses? If all providers used static IPs then this would actually suck pretty hard in terms of DDoS, since if your IP only leaks one single time then you can theoretically be flooded forever.
LunaSea
Profile Joined October 2011
Luxembourg369 Posts
September 03 2012 21:34 GMT
#45
On September 04 2012 06:28 pmp10 wrote:
+ Show Spoiler +
On September 04 2012 06:10 LunaSea wrote:
Show nested quote +
On September 04 2012 06:06 pmp10 wrote:
+ Show Spoiler +
On September 04 2012 05:51 LunaSea wrote:
Show nested quote +
On September 04 2012 05:47 pmp10 wrote:
On September 04 2012 05:41 LunaSea wrote:
On September 04 2012 05:38 pmp10 wrote:
Wait - so all you did was make a switch to a white-list ACL to save CPU cycles of a router?
That's essentially worthless - router CPUs are not overburdened during an DDoS attack.
The network resources are.


Yes that's why you have a white-list, so that your tcp window won't be full of corrupted packets.

Your tcp connection (window?) will receive only what gets through the ISP/buffers ect.
So essentially not much - certainly very little of what you are hoping for.


The TCP window is a buffer.
Nice try mister professional.


Pretty sure it isn't.
Last I recall buffer was a kind of a memory while a window a part of TCP packet but maybe things have changed.



Show nested quote +
The simplest way of considering the window size is that it indicates the size of the device's receive buffer for the particular connection.


-- http://www.tcpipguide.com/free/t_TCPWindowSizeAdjustmentandFlowControl.htm

plz ...

Please look up those terms somewhere more reputable,
Gross oversimplification and completely mismatched definitions won't help your education.
Buffer is about as much a TCP window as operating system is a RAM.
TCP window can set buffer size but they are completely different things.


I did projects around sequence number guessing exploits using window size and OS window scaling.
I think I know more on that subject that what you can grasp.
"Your f*cking wrong, but I respect your opinion" --Day[9]
Pumplekin
Profile Blog Joined April 2011
United Kingdom50 Posts
Last Edited: 2012-09-03 21:37:43
September 03 2012 21:36 GMT
#46
Okay, almost sick of this now, but let us just imagine this situation.

A is me, I'm the attacker. Lets imagine I run, from a host with a 1gbit/s internet connection a udp flood attack, which just generates a bunch of random UDP packets (all from the same, non-spoofed) address, and sends them to your public IPv4 address.

B is your ISP, and you have a 10mbit/s connection to your ISP. Lets assume otherwise your ISP is amazing and has multiple 10gbit/s links everywhere, and can easily carry the 1gbit/s all the way down to your DSLAM or BRAS or whatever it is that your access circuit is connected to. Lets further define B as this BRAS or DSLAM. Lets also just assume you are using DSL and a DSLAM to make this easy to talk about.

C is your router.


I start the attack, and the first UDP packet arrives B. It delivers it down your DSL line. Because my 1gbit/s is 100 times faster than your 10mbit/s connection, while that packet was being delivered down the DSL line, 99 more packets arrived at B, which put them into a buffer.

Then the 2nd of my attack packets is played out the DSL line, and while that is going, 99 more packets arrive. You now have 198 packets in B's buffer. We repeat for the 3rd packet, and you now have 297 packets in B's buffer. This continues until B's buffer is full or filling. What happens then depends on the buffer management strategy in B, which may be tail-drop, it may be RED or WRED or some other congestion control mechanism, but at the end of the day, all these different strategies are is different ways to decide what to throw away when your buffers are full.

Now with this attack going, something legit tries to send you a packet (say it is the SYN+ACK to the web request you just made to teamliquid.net). Unless that packet arrives at JUST the right time at B, it is going to be discarded. Even if it DOES arrive at just the right time, the odds of the NEXT packet (the first of the HTTP payload) also arriving at JUST the right time is super slim. Effectively you are trying to use an internet connection with 99% packet loss, and that just is never going to work well at all.
Loves Cows
CatNzHat
Profile Blog Joined February 2011
United States1599 Posts
September 03 2012 21:36 GMT
#47
layer 7...
Cinim
Profile Joined April 2011
Denmark866 Posts
September 03 2012 21:37 GMT
#48
On September 04 2012 06:34 .syd. wrote:
Show nested quote +
On September 04 2012 06:28 Cinim wrote:
On September 04 2012 05:13 Tao367 wrote:
On September 04 2012 05:07 Pumplekin wrote:
I'm not meaning to be offensive here, but the vast majority of this advice is just straight up wrong to the point it isn't worth reading.

Blocking a denial of service attack on a home based router is going to do nothing, the problem is the buffer in whatever access device lives at your ISP. If you have 10mbit downstream at home and you want to use it all, and I'm throwing 1gbit of garbage at your IP address, only around 1 in 100 of your legitimate packets is going to make it, the rest are going to be discarded before they even get to your home router, so no matter what filtering you apply on it, it isn't going to help you.

The real solutions to DDoS for the home streamer are :-

1.) Don't leak your IP address (and stuff like IRC without host hiding, Skype and other IM programs and I'm sure many other things can make this hard to do).
2.) Don't anger the internet bad guys (yeah, sometimes that is just impossible).
3.) Be very friendly with your ISP support staff (as the standard ISP response to a major DDoS is going to be to null route at the ISP's borders to protect other customers).


Pretty sure there is no way to discover ip's through skype/other IM services, if there was there would be huge news about it.


Skype etc. is actually THE way that people gather IP adresses, and it's not news, most people have known it for many years now, nothing new... if just all providers would provide static IP adresses there wouldn't be any issues )


You mean dynamic IP addresses? If all providers used static IPs then this would actually suck pretty hard in terms of DDoS, since if your IP only leaks one single time then you can theoretically be flooded forever.

Yes, I meant dynamic xD static is ofc the opposite of what you would want
Hell, it's about time
LunaSea
Profile Joined October 2011
Luxembourg369 Posts
September 03 2012 21:37 GMT
#49
On September 04 2012 06:29 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:25 LunaSea wrote:
Show nested quote +
On September 04 2012 06:17 trGKakarot wrote:
On September 04 2012 06:15 LunaSea wrote:
On September 04 2012 06:13 trGKakarot wrote:
I will admit I only skimmed this thread (since it seems like if somebody solved DDoS attacks they would be getting a lot more traction than a random thread on TL), but from what I gather the OP is assuming that an ISP will send an infinite amount of data to your router and filtering out bad IP addresses at your router level will solve the problem since then you only accept "x" amount of data?


Yes, except it's not your ISP sending the data originally, but a bunch of hacked computers rented by a random kid.


Right, but you are only connected to the outside world through your ISP (unless they are somehow on your intranet, which means you have a bigger problem).

Maybe I am missing something...


Yes but what I meant is this :

A --> sends a packet to B --> who forwards it to C

Where :

A is the attacker,
B your ISP,
and C is you.

A is the one the packets originate from and B only forwards it to the destination indicated in the packet.


Right, but B cannot send an unlimited amount of data to C [...]


Yes, they can actually.
B is an ISP and has bandwidth that is magnitude higher than what a personal connection can handle.
"Your f*cking wrong, but I respect your opinion" --Day[9]
trGKakarot
Profile Joined October 2011
United States129 Posts
September 03 2012 21:40 GMT
#50
On September 04 2012 06:37 LunaSea wrote:
Show nested quote +
On September 04 2012 06:29 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:25 LunaSea wrote:
Show nested quote +
On September 04 2012 06:17 trGKakarot wrote:
On September 04 2012 06:15 LunaSea wrote:
On September 04 2012 06:13 trGKakarot wrote:
I will admit I only skimmed this thread (since it seems like if somebody solved DDoS attacks they would be getting a lot more traction than a random thread on TL), but from what I gather the OP is assuming that an ISP will send an infinite amount of data to your router and filtering out bad IP addresses at your router level will solve the problem since then you only accept "x" amount of data?


Yes, except it's not your ISP sending the data originally, but a bunch of hacked computers rented by a random kid.


Right, but you are only connected to the outside world through your ISP (unless they are somehow on your intranet, which means you have a bigger problem).

Maybe I am missing something...


Yes but what I meant is this :

A --> sends a packet to B --> who forwards it to C

Where :

A is the attacker,
B your ISP,
and C is you.

A is the one the packets originate from and B only forwards it to the destination indicated in the packet.


Right, but B cannot send an unlimited amount of data to C [...]


Yes, they can actually.
B is an ISP and has bandwidth that is magnitude higher than what a personal connection can handle.


You don't pay for that much bandwidth, therefore you will not be sent that much data.

You seem to be mixing what is theoretically possible, and what is actually implemented.
hihi glgl
LunaSea
Profile Joined October 2011
Luxembourg369 Posts
Last Edited: 2012-09-03 21:43:37
September 03 2012 21:42 GMT
#51
On September 04 2012 06:40 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:37 LunaSea wrote:
Show nested quote +
On September 04 2012 06:29 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:25 LunaSea wrote:
Show nested quote +
On September 04 2012 06:17 trGKakarot wrote:
On September 04 2012 06:15 LunaSea wrote:
On September 04 2012 06:13 trGKakarot wrote:
I will admit I only skimmed this thread (since it seems like if somebody solved DDoS attacks they would be getting a lot more traction than a random thread on TL), but from what I gather the OP is assuming that an ISP will send an infinite amount of data to your router and filtering out bad IP addresses at your router level will solve the problem since then you only accept "x" amount of data?


Yes, except it's not your ISP sending the data originally, but a bunch of hacked computers rented by a random kid.


Right, but you are only connected to the outside world through your ISP (unless they are somehow on your intranet, which means you have a bigger problem).

Maybe I am missing something...


Yes but what I meant is this :

A --> sends a packet to B --> who forwards it to C

Where :

A is the attacker,
B your ISP,
and C is you.

A is the one the packets originate from and B only forwards it to the destination indicated in the packet.


Right, but B cannot send an unlimited amount of data to C [...]


Yes, they can actually.
B is an ISP and has bandwidth that is magnitude higher than what a personal connection can handle.


You don't pay for that much bandwidth, therefore you will not be sent that much data.

You seem to be mixing what is theoretically possible, and what is actually implemented.


There is no theory.
If someone send you 1Gbit of data on your 10Mbit connection you will receive them is will just create a huge congestion and packets will be dropped by the ISP.
"Your f*cking wrong, but I respect your opinion" --Day[9]
Senx
Profile Blog Joined March 2008
Sweden5901 Posts
Last Edited: 2012-09-03 21:43:25
September 03 2012 21:43 GMT
#52
I had no idea we had so many network engineers on this website. Jesus christ so many convincing arguments from so many people..
"trash micro but win - its marine" MC commentary during HSC 4
nemonic
Profile Joined November 2011
132 Posts
September 03 2012 21:43 GMT
#53
On September 04 2012 06:42 LunaSea wrote:
Show nested quote +
On September 04 2012 06:40 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:37 LunaSea wrote:
Show nested quote +
On September 04 2012 06:29 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:25 LunaSea wrote:
Show nested quote +
On September 04 2012 06:17 trGKakarot wrote:
On September 04 2012 06:15 LunaSea wrote:
On September 04 2012 06:13 trGKakarot wrote:
I will admit I only skimmed this thread (since it seems like if somebody solved DDoS attacks they would be getting a lot more traction than a random thread on TL), but from what I gather the OP is assuming that an ISP will send an infinite amount of data to your router and filtering out bad IP addresses at your router level will solve the problem since then you only accept "x" amount of data?


Yes, except it's not your ISP sending the data originally, but a bunch of hacked computers rented by a random kid.


Right, but you are only connected to the outside world through your ISP (unless they are somehow on your intranet, which means you have a bigger problem).

Maybe I am missing something...


Yes but what I meant is this :

A --> sends a packet to B --> who forwards it to C

Where :

A is the attacker,
B your ISP,
and C is you.

A is the one the packets originate from and B only forwards it to the destination indicated in the packet.


Right, but B cannot send an unlimited amount of data to C [...]


Yes, they can actually.
B is an ISP and has bandwidth that is magnitude higher than what a personal connection can handle.


You don't pay for that much bandwidth, therefore you will not be sent that much data.

You seem to be mixing what is theoretically possible, and what is actually implemented.


There is no theory.
If someone send you 1Gbit of data on your 10Mbit connection you will receive them is will just create a huge congestion.


... which is the purpose of a DDoS attack
Cite
Profile Joined August 2010
Australia251 Posts
September 03 2012 21:43 GMT
#54
@Luna: Your clarification on page 2 yourself should have made what Pimp, trG etc are trying to say clear. They're pretty much saying the path to your router gets shited up by a DDoS and nothing you do on your side will increase the ize of your allocated bandwidth path so thus blocking on your final end is indeed quite useless.

And No ISPS will not simply increase your bandwidth so they can suddenly account for your burst of incomming data. Itll get clogged and wait till you yourself deny it on your end.
trGKakarot
Profile Joined October 2011
United States129 Posts
September 03 2012 21:44 GMT
#55
On September 04 2012 06:42 LunaSea wrote:
Show nested quote +
On September 04 2012 06:40 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:37 LunaSea wrote:
Show nested quote +
On September 04 2012 06:29 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:25 LunaSea wrote:
Show nested quote +
On September 04 2012 06:17 trGKakarot wrote:
On September 04 2012 06:15 LunaSea wrote:
On September 04 2012 06:13 trGKakarot wrote:
I will admit I only skimmed this thread (since it seems like if somebody solved DDoS attacks they would be getting a lot more traction than a random thread on TL), but from what I gather the OP is assuming that an ISP will send an infinite amount of data to your router and filtering out bad IP addresses at your router level will solve the problem since then you only accept "x" amount of data?


Yes, except it's not your ISP sending the data originally, but a bunch of hacked computers rented by a random kid.


Right, but you are only connected to the outside world through your ISP (unless they are somehow on your intranet, which means you have a bigger problem).

Maybe I am missing something...


Yes but what I meant is this :

A --> sends a packet to B --> who forwards it to C

Where :

A is the attacker,
B your ISP,
and C is you.

A is the one the packets originate from and B only forwards it to the destination indicated in the packet.


Right, but B cannot send an unlimited amount of data to C [...]


Yes, they can actually.
B is an ISP and has bandwidth that is magnitude higher than what a personal connection can handle.


You don't pay for that much bandwidth, therefore you will not be sent that much data.

You seem to be mixing what is theoretically possible, and what is actually implemented.


There is no theory.
If someone send you 1Gbit of data on your 10Mbit connection you will receive them is will just create a huge congestion.



This will make you receive packets with significant delay, which at a certain point makes you're service ... denied.
hihi glgl
karpo
Profile Joined October 2010
Sweden1998 Posts
September 03 2012 21:44 GMT
#56
On September 04 2012 06:37 LunaSea wrote:
Show nested quote +
On September 04 2012 06:29 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:25 LunaSea wrote:
Show nested quote +
On September 04 2012 06:17 trGKakarot wrote:
On September 04 2012 06:15 LunaSea wrote:
On September 04 2012 06:13 trGKakarot wrote:
I will admit I only skimmed this thread (since it seems like if somebody solved DDoS attacks they would be getting a lot more traction than a random thread on TL), but from what I gather the OP is assuming that an ISP will send an infinite amount of data to your router and filtering out bad IP addresses at your router level will solve the problem since then you only accept "x" amount of data?


Yes, except it's not your ISP sending the data originally, but a bunch of hacked computers rented by a random kid.


Right, but you are only connected to the outside world through your ISP (unless they are somehow on your intranet, which means you have a bigger problem).

Maybe I am missing something...


Yes but what I meant is this :

A --> sends a packet to B --> who forwards it to C

Where :

A is the attacker,
B your ISP,
and C is you.

A is the one the packets originate from and B only forwards it to the destination indicated in the packet.


Right, but B cannot send an unlimited amount of data to C [...]


Yes, they can actually.
B is an ISP and has bandwidth that is magnitude higher than what a personal connection can handle.


I want that kind of connection. A gigabit+ download bandwidth all to myself?

You do realize that the ISP has to police your bandwidth somehow, else they would have to supply a fiber connection to every customer.
Cinim
Profile Joined April 2011
Denmark866 Posts
September 03 2012 21:45 GMT
#57
Please everyone, no one here seems to know at all what they are talking about, especially this Pumplekin guy, no offense but you're not really anything close to and expert.
He never said this was a perfect solution, especially because you have to block off connection to mostly every server out there, so this is a solution that only works in very very rare occasions.
You guys are going on about how big this would be IF it worked, but if it does work, the fact that it's a whitelist as he say and not a blacklist, is exactly why this isn't a great solution, unless you are in the unique situation that it is neccesary.

I suggest that people do 1 simple thing: actually test it out, someone stream, someone intentionally try and DDoS him, and see if it works, rather than argueing constantly for no reason. Everyone who worked with tech will know that nothing is ever certain when it's just theory.
Hell, it's about time
karpo
Profile Joined October 2010
Sweden1998 Posts
September 03 2012 21:47 GMT
#58
On September 04 2012 06:45 Cinim wrote:
Please everyone, no one here seems to know at all what they are talking about, especially this Pumplekin guy, no offense but you're not really anything close to and expert.
He never said this was a perfect solution, especially because you have to block off connection to mostly every server out there, so this is a solution that only works in very very rare occasions.
You guys are going on about how big this would be IF it worked, but if it does work, the fact that it's a whitelist as he say and not a blacklist, is exactly why this isn't a great solution, unless you are in the unique situation that it is neccesary.

I suggest that people do 1 simple thing: actually test it out, someone stream, someone intentionally try and DDoS him, and see if it works, rather than argueing constantly for no reason. Everyone who worked with tech will know that nothing is ever certain when it's just theory.


The "Pumplekin guy" does know what he's saying. And i know a fair bit about it too as i have a degree in network engineering.
LunaSea
Profile Joined October 2011
Luxembourg369 Posts
September 03 2012 21:47 GMT
#59
On September 04 2012 06:44 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:42 LunaSea wrote:
Show nested quote +
On September 04 2012 06:40 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:37 LunaSea wrote:
Show nested quote +
On September 04 2012 06:29 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:25 LunaSea wrote:
Show nested quote +
On September 04 2012 06:17 trGKakarot wrote:
On September 04 2012 06:15 LunaSea wrote:
On September 04 2012 06:13 trGKakarot wrote:
I will admit I only skimmed this thread (since it seems like if somebody solved DDoS attacks they would be getting a lot more traction than a random thread on TL), but from what I gather the OP is assuming that an ISP will send an infinite amount of data to your router and filtering out bad IP addresses at your router level will solve the problem since then you only accept "x" amount of data?


Yes, except it's not your ISP sending the data originally, but a bunch of hacked computers rented by a random kid.


Right, but you are only connected to the outside world through your ISP (unless they are somehow on your intranet, which means you have a bigger problem).

Maybe I am missing something...


Yes but what I meant is this :

A --> sends a packet to B --> who forwards it to C

Where :

A is the attacker,
B your ISP,
and C is you.

A is the one the packets originate from and B only forwards it to the destination indicated in the packet.


Right, but B cannot send an unlimited amount of data to C [...]


Yes, they can actually.
B is an ISP and has bandwidth that is magnitude higher than what a personal connection can handle.


You don't pay for that much bandwidth, therefore you will not be sent that much data.

You seem to be mixing what is theoretically possible, and what is actually implemented.


There is no theory.
If someone send you 1Gbit of data on your 10Mbit connection you will receive them is will just create a huge congestion.



This will make you receive packets with significant delay, which at a certain point makes you're service ... denied.


Which is the definition of a DDoS. Thank you but I wrote the definition in the OP.
Next time read the thread before plz.
"Your f*cking wrong, but I respect your opinion" --Day[9]
nkr
Profile Blog Joined November 2010
Sweden5451 Posts
September 03 2012 21:49 GMT
#60
On September 04 2012 06:44 karpo wrote:
Show nested quote +
On September 04 2012 06:37 LunaSea wrote:
On September 04 2012 06:29 trGKakarot wrote:
+ Show Spoiler +
On September 04 2012 06:25 LunaSea wrote:
Show nested quote +
On September 04 2012 06:17 trGKakarot wrote:
On September 04 2012 06:15 LunaSea wrote:
On September 04 2012 06:13 trGKakarot wrote:
I will admit I only skimmed this thread (since it seems like if somebody solved DDoS attacks they would be getting a lot more traction than a random thread on TL), but from what I gather the OP is assuming that an ISP will send an infinite amount of data to your router and filtering out bad IP addresses at your router level will solve the problem since then you only accept "x" amount of data?


Yes, except it's not your ISP sending the data originally, but a bunch of hacked computers rented by a random kid.


Right, but you are only connected to the outside world through your ISP (unless they are somehow on your intranet, which means you have a bigger problem).

Maybe I am missing something...


Yes but what I meant is this :

A --> sends a packet to B --> who forwards it to C

Where :

A is the attacker,
B your ISP,
and C is you.

A is the one the packets originate from and B only forwards it to the destination indicated in the packet.


Right, but B cannot send an unlimited amount of data to C [...]


Yes, they can actually.
B is an ISP and has bandwidth that is magnitude higher than what a personal connection can handle.


I want that kind of connection. A gigabit+ download bandwidth all to myself?

You do realize that the ISP has to police your bandwidth somehow, else they would have to supply a fiber connection to every customer.


Move to Lund ^^

http://labs2.com/brikks/kundreferenser/gigabit-i-lund
ESPORTS ILLUMINATI
Prev 1 2 3 4 5 6 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 1h 37m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
LamboSC2 380
BRAT_OK 66
StarCraft: Brood War
Britney 34304
EffOrt 741
Mini 347
ggaemo 339
actioN 184
Soulkey 174
Rush 173
firebathero 148
hero 102
Shine 68
[ Show more ]
Hyun 53
Aegong 32
GoRush 20
Bale 20
Movie 10
Dota 2
Gorgc10864
qojqva1212
Super Smash Bros
Mew2King119
Heroes of the Storm
Liquid`Hasu513
Khaldor431
MindelVK12
Other Games
Grubby3270
singsing1802
Liquid`RaSZi1551
RotterdaM408
KnowMe400
B2W.Neo340
Hui .156
crisheroes145
Organizations
Other Games
gamesdonequick1662
StarCraft 2
ComeBackTV 687
Other Games
BasetradeTV159
StarCraft 2
angryscii 28
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 24 non-featured ]
StarCraft 2
• Berry_CruncH65
• LUISG 13
• Adnapsc2 6
• Reevou 5
• musti20045 2
• intothetv
• IndyKCrew
• Kozan
• Migwel
• LaughNgamezSOOP
• AfreecaTV YouTube
• sooper7s
StarCraft: Brood War
• blackmanpl 28
• Airneanach24
• Azhi_Dahaki21
• HerbMon 16
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• WagamamaTV567
League of Legends
• Jankos6305
• Nemesis4105
Other Games
• imaqtpie424
• Shiphtur211
Upcoming Events
BSL
1h 37m
Replay Cast
6h 37m
Replay Cast
15h 37m
Afreeca Starleague
16h 37m
Light vs Calm
Royal vs Mind
Wardi Open
17h 37m
Monday Night Weeklies
22h 37m
OSC
1d 6h
Sparkling Tuna Cup
1d 16h
Afreeca Starleague
1d 16h
Rush vs PianO
Flash vs Speed
Replay Cast
2 days
[ Show More ]
Afreeca Starleague
2 days
BeSt vs Leta
Queen vs Jaedong
Replay Cast
3 days
The PondCast
3 days
Replay Cast
4 days
RSL Revival
4 days
Replay Cast
5 days
RSL Revival
5 days
BSL
6 days
RSL Revival
6 days
uThermal 2v2 Circuit
6 days
Liquipedia Results

Completed

Proleague 2026-03-27
WardiTV Winter 2026
Underdog Cup #3

Ongoing

BSL Season 22
CSL Elite League 2026
CSL Season 20: Qualifier 1
ASL Season 21
Acropolis #4 - TS6
2026 Changsha Offline CUP
StarCraft2 Community Team League 2026 Spring
RSL Revival: Season 4
Nations Cup 2026
NationLESS Cup
BLAST Open Spring 2026
ESL Pro League S23 Finals
ESL Pro League S23 Stage 1&2
PGL Cluj-Napoca 2026
IEM Kraków 2026
BLAST Bounty Winter 2026
BLAST Bounty Winter Qual

Upcoming

CSL Season 20: Qualifier 2
Escore Tournament S2: W1
CSL 2026 SPRING (S20)
Acropolis #4
IPSL Spring 2026
BSL 22 Non-Korean Championship
CSLAN 4
Kung Fu Cup 2026 Grand Finals
HSC XXIX
uThermal 2v2 2026 Main Event
IEM Cologne Major 2026
Stake Ranked Episode 2
CS Asia Championships 2026
IEM Atlanta 2026
Asian Champions League 2026
PGL Astana 2026
BLAST Rivals Spring 2026
CCT Season 3 Global Finals
IEM Rio 2026
PGL Bucharest 2026
Stake Ranked Episode 1
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.