Isn’t the Internet built for spoofing who/what sent something? As I understand it, when you peel the layers and look deeper, there is no stringent authentication or identity verification that really happens, which makes it easy to exploit for DDoS attacks (using IP spoofing, which may help for certain kinds of attacks, or BGP spoofing).
Just spoof it. This is already how many volumetric ddos attacks work because of all the ISPs who still don't filter egress. Like an envelope with a bogus return address.
Comments
Great thought experiment that I’d like to expand to the question of how to send a single anonymous packet on the Internet?
Isn’t the Internet built for spoofing who/what sent something? As I understand it, when you peel the layers and look deeper, there is no stringent authentication or identity verification that really happens, which makes it easy to exploit for DDoS attacks (using IP spoofing, which may help for certain kinds of attacks, or BGP spoofing).
Just spoof it. This is already how many volumetric ddos attacks work because of all the ISPs who still don't filter egress. Like an envelope with a bogus return address.