If you need to be on the site it’s not a botnet and there is no C&C server coordinating the attack. It‘s just the JS on the site that makes the attack.
Why? I did not visit the site to participate in a DoS attack; yet my machine was coaxed into participating against my will. Whether this is happening in JS or a drive-by download or a browser 0-day is irrelevant.
If you need to be on the site it’s not a botnet and there is no C&C server coordinating the attack. It‘s just the JS on the site that makes the attack.
> If you need to be on the site it’s not a botnet
Why? I did not visit the site to participate in a DoS attack; yet my machine was coaxed into participating against my will. Whether this is happening in JS or a drive-by download or a browser 0-day is irrelevant.
You did participate in archive.today’s DDoS without visiting the site?
How if it‘s JS code in the site?
Does this mean that the Great Cannon of China is not a botnet because it stops working when you close your browser?
Does the Great Cannon of China coordinate the attacks?
Does archive.today?
Hijacking a software like the browser is something completely different to a simple JS on a website.
4 replies →