Comment by shakna
8 years ago
> They're probably already committing a felony accessing the computer.
He bases this attack on IP addresses. IPv4 addresses are regularly shared between consumers. He's tossing a knife into a crowd because he thought he saw someone.
> you could make a pretty good fleeing felon argument.
In a nation that allows you to attack, not just restrain, a fleeing felon.
But his attack may hit a nation that doesn't allow that.
He does not base the attack on IP address. He detects vulnerability scanner and send them the crafted content.
You ask for something a vulnerability scanner would ask for? You get a gzip bomb.
> Awesome! My production implementation of the bomb also looks at 404's and 403's per IP and if there are too many of those it will send the bomb. [0]
[0] https://www.reddit.com/r/PHP/comments/6lfl6p/i_have_created_...