Skip to content
June 10, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • Technique
  • What is DDos attack?
  • Technique

What is DDos attack?

Do Son June 9, 2017 7 minutes read

While large sites are often attacked, and under overloaded workloads, these companies and networks still have to do everything they can to move these attacks, and the most important thing is to keep their sites going to be able to navigate properly. Even if the management of a small site, such as small companies or small sites on this scale of the network, do not know when someone will be in your hands. Then take a look at DDoS “behind” some of the details and attacks, in order to make the network more secure.

Multiple types of attacks

With the PING command can be executed on the operation of ICMP request, this request is very easy to cause network congestion. DDoS attacks can be done in a variety of ways, ICMP is only one of them.

In addition, there is a Syn attack, launched this attack, in fact, just open a TCP link, then usually connected to a website, but the key is that this operation did not complete the initial handshake, left the server The

Another clever way is to use DNS. There are many network providers have their own DNS server, and allow anyone to query, and even some people are not their customers. And the general DNS is the use of UDP, UDP is a connectionless transport layer protocol. With the above two conditions as a basis, those attackers are very easy to launch a denial of service attacks. All the attackers have to do is find an open DNS resolver, making a virtual UDP packet and forging an address, facing the target site to send it to the DNS server. When the server receives a request from an attacker, it will be true and send a request response to the forged address. In fact, the target site received a group of open DNS resolver on the Internet request and reply, which instead of the botnet attacks. In addition, such attacks have a very large scalability, because the DNS server can send a UDP packet, request a side of the dump, resulting in a large flow of response.

DDoS attacks in a variety of ways

Denial of service was a very simple way of attack. Some people start running on their computer PING command, lock the target address, let it run at high speed, trying to send flooded ICMP request command or packet to the other end. Of course, because of this side of the sending speed changes, the attacker needs a greater bandwidth than the other site. First of all, they will move to a large host of the place, similar to a university server or teaching and research as a large area of bandwidth, and then from here to attack. But the modern botnet in almost any case can be used, relatively speaking, its operation is more simple so that the attack is completely distributed, it is more subtle.

In fact, because of the maker of malware, botnet operation has become a distinct industry chain. In fact, they have already started to rent those meat machines and are charged on an hourly basis. If someone wants to ruin a website, just give these attackers enough money, and then there will be thousands of zombie computers to attack that site. An infected computer may not be able to ruin a site, but if there are more than 10,000 computers at the same time to send the request, they will unprotect server “stuffed.”

How to protect the network

DDoS attacks are varied, hard to prevent when you want to establish a defense system against DDoS, you need to master the variation of these attacks.

The most stupid defense method is to spend a lot of money to buy more bandwidth. Denial of service is like a game. If you use 10,000 systems to send 1Mbps traffic, it means that you deliver 10Gb of data per second to your server. This will cause congestion. In this case, the same rules apply to normal redundancy. At this point, you need more servers, all over the data center, and better load balancing services. Traffic will be distributed to multiple servers, traffic balance, greater bandwidth to deal with a variety of high traffic problems. But the modern DDoS attacks more and crazier, the need for more and more bandwidth, the financial situation is not allowed to put more money. In addition, the vast majority of the time, the site is not the main target, many administrators have forgotten this point.

The most critical piece of the network is the DNS server. It is absolutely undesirable to put the DNS resolver in an open state, and it should be locked to reduce the risk of some attacks. But after doing so, the server is safe? The answer is of course negative, even if your site, no one can link to your DNS server, help you resolve the domain name, which is also the very bad thing. Most of the registered domain names require two DNS servers, but that is not enough. You want to make sure that your DNS server and your website and other resources are in a load-balanced protection state. You can also use redundant DNS provided by some companies. For example, many people use the content distribution network (distributed state) to send files to customers, this is a very good way to resist DDoS attacks. If you need, there are many companies to provide this enhanced DNS protection measures.

If you manage your own network and data, then you need to focus on protecting your network layer, to carry out a lot of configuration. First of all to ensure that all of your routers are able to shield junk data packets, remove some unused protocols, such as ICMP this. Then set up a firewall. Obviously, your site will never let the random DNS server access, so there is no need to allow UDP 53 port packets through your server. In addition, you can let your suppliers help you make some border network settings, block some useless traffic, and ensure that you can get one of the largest and most unobstructed bandwidths. Many network providers give businesses this service, you can contact their network operations center, so that they help you optimize the flow, to help you monitor whether you have to attack.

Similar to Syn’s attacks, there are many ways to stop, such as by giving TCP backlog, reducing the Syn-Receive timer, or using the Syn cache.

Finally, you have to think about how to intercept them before these attacks arrive at your site. For example, modern sites use a lot of dynamic resources like a mitigation and detection system like FastNetMon. In the case of attack when the bandwidth is relatively easy to control, but in the end is often lost by the database or you run the script. You can consider using the cache server to provide as much as possible static content, but also quickly with static resources to replace the dynamic resources and to ensure that the detection system to normal operation.

The worst case is that your network or site is completely paralyzed, and you should be ready at the beginning of the attack. Because the attack once started, want to stop DDoS from the source is very difficult. Finally, you should be pondering how to make your infrastructure more reasonable and safe, and to focus on your network settings. These are very important.

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. DieNet Hacktivist Group Exploits DDoS-as-a-Service in Rapid Attacks
  2. Cloudflare Mitigates Record 7.3 Tbps DDoS Attack: 37.4 TB in 45 Seconds
  3. Operation Eastwood: Europol Leads Massive Global Crackdown on Pro-Russian Cybercrime Group NoName057(16)
  4. SVF Botnet: New Python DDoS Threat Leverages Discord for Stealthy C&C on Linux Servers
  5. AISURU Botnet: From Record-Breaking DDoS to Residential Proxy Empire
Tags: ddos

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-45328CVSS 9.3
    ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions...
  • CVE-2026-48030CVSS 9.9
    ### Summary An OS Command Injection vulnerability in the terminal action handler...
  • CVE-2026-48303CVSS 10.0
    Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected...
  • CVE-2026-47938CVSS 10.0
    Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected...
  • CVE-2026-47928CVSS 9.6
    ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input...
  • CVE-2026-30141CVSS 9.8
    An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in...
  • CVE-2026-10045CVSS 9.8
    Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121,...
  • CVE-2026-34691CVSS 9.3
    Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are...
  • CVE-2026-49841CVSS 9.8
    FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from...
  • CVE-2026-49840CVSS 9.1
    FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.