Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.javascript > #16362

Re: Thwarting DoS attacks

Path csiph.com!usenet.pasdenom.info!gegeweb.org!eternal-september.org!feeder.eternal-september.org!mx04.eternal-september.org!.POSTED!not-for-mail
From Denis McMahon <denismfmcmahon@gmail.com>
Newsgroups comp.lang.javascript
Subject Re: Thwarting DoS attacks
Date Wed, 3 Oct 2012 22:13:27 +0000 (UTC)
Organization A noiseless patient Spider
Lines 41
Message-ID <k4ida6$1pq$1@dont-email.me> (permalink)
References <ad34l0Fka06U1@mid.individual.net>
Mime-Version 1.0
Content-Type text/plain; charset=UTF-8
Content-Transfer-Encoding 8bit
Injection-Date Wed, 3 Oct 2012 22:13:27 +0000 (UTC)
Injection-Info mx04.eternal-september.org; posting-host="986f797cbd3b8f473a4775d73e9098bc"; logging-data="1850"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+dkP0oOjSlP4n9x3vZ6EWKzIUcR2hlgDg="
User-Agent Pan/0.136 (I'm far too busy being delicious; GIT 926a150 git://git.gnome.org/pan2)
Cancel-Lock sha1:OvxC4W7h5wt+XS02qyN+mH4n1uQ=
Xref csiph.com comp.lang.javascript:16362

Show key headers only | View raw


On Wed, 03 Oct 2012 09:41:17 -0600, Mel Smith wrote:

> Question:
>    Is there a different download technique whereby my 'script' 
>    (actually a
> C-based executable)
> could intercept the download request, investigate it, then (perhaps)
> refuse the download request.

Another technique:

Ask them for an email addr. Email a unique link to each addr that is 
submitted. Something like:

"Hi

You (or someone pretending to be you) submitted a request for a download 
link for [name of software].

To confirm that you want this link, click the following url:

http://host/confirm1?x=some_hash_here

Otherwise, please ignore this email.

Best Wishes

Mel Smith, blah blah blah"

When they click on the confirm link, email a unique (using a different 
hash) download link to the email addy for that hash. In your download 
handler, check for valid second stage hashes.

A bit more fiddly to program and use, but possibly less fiddly to the 
user than a captcha, and if / once the attacker catches up with the new 
system, you may over time be able to identify email providers that are 
being used in the attacks.

Rgds

Denis McMahon

Back to comp.lang.javascript | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 09:41 -0600
  Re: Thwarting DoS attacks Dr.Kral@nyc.rr.com - 2012-10-03 14:29 -0400
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 14:39 -0600
  Re: Thwarting DoS attacks Daniel Pitts <newsgroup.nospam@virtualinfinity.net> - 2012-10-03 14:49 -0700
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:15 -0600
      Re: Thwarting DoS attacks Gene Wirchenko <genew@ocis.net> - 2012-10-03 17:26 -0700
  Re: Thwarting DoS attacks Denis McMahon <denismfmcmahon@gmail.com> - 2012-10-03 22:13 +0000
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:20 -0600
  Re: Thwarting DoS attacks dann90038@gmail.com - 2012-10-03 15:45 -0700
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:24 -0600
  Re: Thwarting DoS attacks Stefan Weiss <krewecherl@gmail.com> - 2012-10-04 00:51 +0200
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:28 -0600

csiph-web