<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to Prevent Denial of Service Attacks</title>
	<atom:link href="http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks/feed" rel="self" type="application/rss+xml" />
	<link>http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks</link>
	<description>Where 127.0.0.1 is Home.</description>
	<lastBuildDate>Mon, 30 Apr 2012 06:04:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Mennley Womb</title>
		<link>http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks/comment-page-1#comment-32414</link>
		<dc:creator>Mennley Womb</dc:creator>
		<pubDate>Wed, 08 Feb 2012 17:51:27 +0000</pubDate>
		<guid isPermaLink="false">http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks#comment-32414</guid>
		<description>Hello there!
How could i defend against a denial of service attack where the attacker is originated in my network?</description>
		<content:encoded><![CDATA[<p>Hello there!<br />
How could i defend against a denial of service attack where the attacker is originated in my network?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phil</title>
		<link>http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks/comment-page-1#comment-31230</link>
		<dc:creator>Phil</dc:creator>
		<pubDate>Wed, 18 Jan 2012 13:27:04 +0000</pubDate>
		<guid isPermaLink="false">http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks#comment-31230</guid>
		<description>Isnt it possible to somehow get some QoS to the ICMP Ping port on the router so if its taken up a certain percentage of the bandwidth (like 12% or something) then deny any other packets from that port?</description>
		<content:encoded><![CDATA[<p>Isnt it possible to somehow get some QoS to the ICMP Ping port on the router so if its taken up a certain percentage of the bandwidth (like 12% or something) then deny any other packets from that port?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SpYdee</title>
		<link>http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks/comment-page-1#comment-27791</link>
		<dc:creator>SpYdee</dc:creator>
		<pubDate>Mon, 21 Nov 2011 22:38:17 +0000</pubDate>
		<guid isPermaLink="false">http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks#comment-27791</guid>
		<description>does any1 know a simple c++ source code that can help auto detect dos attacks on a network….please help</description>
		<content:encoded><![CDATA[<p>does any1 know a simple c++ source code that can help auto detect dos attacks on a network….please help</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joseph</title>
		<link>http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks/comment-page-1#comment-22386</link>
		<dc:creator>Joseph</dc:creator>
		<pubDate>Mon, 06 Jun 2011 02:39:52 +0000</pubDate>
		<guid isPermaLink="false">http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks#comment-22386</guid>
		<description>I think most routers have a &quot;block WAN ping&quot; option.....which prevents the network behind that router or set of routers from being pinged to death</description>
		<content:encoded><![CDATA[<p>I think most routers have a &#8220;block WAN ping&#8221; option&#8230;..which prevents the network behind that router or set of routers from being pinged to death</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks/comment-page-1#comment-15023</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Thu, 07 Oct 2010 19:16:23 +0000</pubDate>
		<guid isPermaLink="false">http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks#comment-15023</guid>
		<description>Great work. Simple and very comprehensive.</description>
		<content:encoded><![CDATA[<p>Great work. Simple and very comprehensive.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ibrahim Hudhaif</title>
		<link>http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks/comment-page-1#comment-10465</link>
		<dc:creator>Ibrahim Hudhaif</dc:creator>
		<pubDate>Sun, 15 Nov 2009 12:51:47 +0000</pubDate>
		<guid isPermaLink="false">http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks#comment-10465</guid>
		<description>First of, I don&#039;t think buying IDS would effectively help avoiding DDoS. IDS is only after facts device and do not help to overcome such an issue. 

IPS could be much better than IDS but still if you don&#039;t have a good relationship with your ISPs by retaining an emergency contacts of the technical staff and proper procedure of what to do if that happen! Because it would a panic time... so some written documents should guide on what do!</description>
		<content:encoded><![CDATA[<p>First of, I don&#8217;t think buying IDS would effectively help avoiding DDoS. IDS is only after facts device and do not help to overcome such an issue. </p>
<p>IPS could be much better than IDS but still if you don&#8217;t have a good relationship with your ISPs by retaining an emergency contacts of the technical staff and proper procedure of what to do if that happen! Because it would a panic time&#8230; so some written documents should guide on what do!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ramil</title>
		<link>http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks/comment-page-1#comment-10043</link>
		<dc:creator>Ramil</dc:creator>
		<pubDate>Sun, 11 Oct 2009 10:59:26 +0000</pubDate>
		<guid isPermaLink="false">http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks#comment-10043</guid>
		<description>I was told to help organize and prevent a DoS attack for a web-site for testing purposes. This was really helpful to start with. Great job! Tnx a lot.</description>
		<content:encoded><![CDATA[<p>I was told to help organize and prevent a DoS attack for a web-site for testing purposes. This was really helpful to start with. Great job! Tnx a lot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erin</title>
		<link>http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks/comment-page-1#comment-9578</link>
		<dc:creator>Erin</dc:creator>
		<pubDate>Fri, 11 Sep 2009 12:32:32 +0000</pubDate>
		<guid isPermaLink="false">http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks#comment-9578</guid>
		<description>DDoS attacks are done using the ping flood method.  
No ip verify unicast reverse-path is only going to filter out the actual attacker but not all the zombies because they are coming from legit IP&#039;s.
DDoS attack zombies sometimes are in specific geographic areas....so lets say some guys in Korea has it out for your company or website....and 90% of his zombies are in Korea....you can filter whole A or B blocks of IP&#039;s.....if it is truly distributed....things get really hairy really quickly.</description>
		<content:encoded><![CDATA[<p>DDoS attacks are done using the ping flood method.<br />
No ip verify unicast reverse-path is only going to filter out the actual attacker but not all the zombies because they are coming from legit IP&#8217;s.<br />
DDoS attack zombies sometimes are in specific geographic areas&#8230;.so lets say some guys in Korea has it out for your company or website&#8230;.and 90% of his zombies are in Korea&#8230;.you can filter whole A or B blocks of IP&#8217;s&#8230;..if it is truly distributed&#8230;.things get really hairy really quickly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric</title>
		<link>http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks/comment-page-1#comment-8996</link>
		<dc:creator>Eric</dc:creator>
		<pubDate>Tue, 11 Aug 2009 03:20:37 +0000</pubDate>
		<guid isPermaLink="false">http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks#comment-8996</guid>
		<description>Well written but I hope you&#039;re open to critizism.

You talked about all the details of the DoS attacks until you reached the DDos.  At that point you just explained what a zombie is which really says nothing about the actual attack of each individual zombie, it only describes that you are being attacked from multiple vectors.  Are those vectors using tcp syn, smurf, pod, fraggle, teardrop or what?  I would expand on DDos a little more.  Maybe cit examples like Kraken or Srizbi and what specifc methods they use.</description>
		<content:encoded><![CDATA[<p>Well written but I hope you&#8217;re open to critizism.</p>
<p>You talked about all the details of the DoS attacks until you reached the DDos.  At that point you just explained what a zombie is which really says nothing about the actual attack of each individual zombie, it only describes that you are being attacked from multiple vectors.  Are those vectors using tcp syn, smurf, pod, fraggle, teardrop or what?  I would expand on DDos a little more.  Maybe cit examples like Kraken or Srizbi and what specifc methods they use.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: varun naresh</title>
		<link>http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks/comment-page-1#comment-8938</link>
		<dc:creator>varun naresh</dc:creator>
		<pubDate>Fri, 07 Aug 2009 14:46:03 +0000</pubDate>
		<guid isPermaLink="false">http://learn-networking.com/network-security/how-to-prevent-denial-of-service-attacks#comment-8938</guid>
		<description>This article is so awsome XD !

Amazing really !

well done !</description>
		<content:encoded><![CDATA[<p>This article is so awsome XD !</p>
<p>Amazing really !</p>
<p>well done !</p>
]]></content:encoded>
	</item>
</channel>
</rss>

