6 ms·
I take it then that there are legitimate sites that do offer this service but properly verify owners first?
by Namrog84 8y ago
I take it then that there are legitimate sites that do offer this service but properly verify owners first?
- ceejayoz 8y agoYes. I used Blitz.io a couple of times; they'd require you to put either a DNS entry in place or upload a file to a specific location in the domain's root.
- yepguy 8y agoThat doesn't really prevent anyone from attacking a hosting service like GitHub Pages or Netlify, though.
- giancarlostoro 8y agoYou could check the existing DNS of a domain, if they're GitHub or Netlify's DNS addresses / IP's then you don't stress those.
- lelandbatey 8y agoThe idea is that the stress testing site dictates where the file must go, not the user. So for them to run the test, they may need to see a specific file at "subjectsite.com/secretguid" The idea being that unless you have total domain control, you can't get that file where they want you to put it.
- msmith 8y agoI was a lead on Blitz. You’re right that there are ways to get around this domain ownership check, but in practice it was enough of a hurdle to avoid bad actors. Also, I’m pretty sure that these stressors were way more cost effective if your only goal is to DDoS a site.
- Haydos585x2 8y agoYou're right. There are plenty of legitimate companies that offer security services whether it's pentesting or DOS attacks. The dark web/malicious providers normally say something like: "this can only be used on machines you have permission to test" while doing absolutely no verification that the services are owned by the purchaser.