Gamespy DDoS attack threat

Author
Aron Schatz
Posted
January 18, 2003
Views
1475
Tags Bugs

Page All:

Page 1
Wow, when did you think that game servers can be used to make a large DDoS attack? There are many games affected, you're probably playing at least one of them.

Quote

The flaw occurs because servers that include the GameSpy networking code automatically send responses to queries for status information and don't verify the sender's address. An attacker can just ask the server for the information, but forge the data so that the packets appear to come from a fake address. When the game server responds, the large amount of information sent in reply goes to the target of the attack instead.

Title

Medium Image View Large