Vulnerability Development mailing list archives

Re: R: New DoS attack


From: 11a () GMX NET (Bluefish)
Date: Sat, 17 Jun 2000 15:10:41 +0200


Understanding that UDP is faster and necessary for game programmers, still I
can't understand the lack of security. A simple "3-way handshaking" roughly
reproduced by UDP method would stop all of this, right ?

Which would introduce some of the "slowness" in TCP. Once you make UDP
into something more complex, you loose some of the benefits UDP offers.

Sounds to me like you would be re-inventing TCP except that you would
remove the "slow start" feature (and ehem... papers proving that the slow
start in TCP can be avoided. But I suppose "3way UDP" is better than
asking people to hack their TCP-stack ;-)

Sadly it seems that scriptkidz cannot accept that the services offered by
internet games are dependent upon lack of abuse. I fear that in the end
that security updates will slow down game servers, so that all the users
will recieve less QoS.

I realise that under some insane way of thinking you can concider taking
down huge e-commerece sites with DoS-attacks to be some kind of proof that
we need new protocolls, but what drives some small, pathetic, human into
bring down *games*??

Just my .02 EUR (which is a little less than .02$ I fear)

I can't resist mentioning that the Swedish economy also has a better
development that the EUR. Glad I ain't getting my paychecks in EUR :)

..:::::::::::::::::::::::::::::::::::::::::::::::::..
     http://www.11a.nu || http://bluefish.11a.nu
    eleventh alliance development & security team


Current thread: