73-997563179
Aug 17 2001, 10:26 AM
Zombie Zapper - an active attack tool created to fight DDoS
Details
Zombie Zapper is a free, open source tool that can tell a 'zombie' system flooding packets to stop flooding. This affectively stops Trinoo, TFN, and Stacheldraht. It assumes various defaults used by these attack tools are still in place, but allows you to put the zombies to sleep.
Zombie Zapper works against Trinoo, TFN, and Stacheldraht. Assuming that the default passwords have not been changed, you can simply use the same commands that an attacker would use to stop the flood. On Trinoo, it stops the daemon entirely (although it is typically set to be restarted by cron, silently awaiting more commands), but on TFN and Stacheldraht the flooding just stops. This gives you the advantage of telling the daemon to stop flooding without stopping the daemon, enabling you to track down where they are, and more importantly, how they got there in the first place.
Since Zombie Zapper assumes the default passwords were left intact, it will not work against TFN2K, which forces you to use a new password during setup.
Links
The tool can be downloaded from: razor.bindview.com/tools/index.shtml.
I understand that this is quite the program. Basically during an attack, this program tells the DoS program to stop sending packets using the same language as the attacker is using.
Interceptor
Jun 14 2002, 10:23 PM
Zombie Zapper - an active attack tool created to fight DDoS
Details
Zombie Zapper is a free, open source tool that can tell a 'zombie' system flooding packets to stop flooding. This affectively stops Trinoo, TFN, and Stacheldraht. It assumes various defaults used by these attack tools are still in place, but allows you to put the zombies to sleep.
Zombie Zapper works against Trinoo, TFN, and Stacheldraht. Assuming that the default passwords have not been changed, you can simply use the same commands that an attacker would use to stop the flood. On Trinoo, it stops the daemon entirely (although it is typically set to be restarted by cron, silently awaiting more commands), but on TFN and Stacheldraht the flooding just stops. This gives you the advantage of telling the daemon to stop flooding without stopping the daemon, enabling you to track down where they are, and more importantly, how they got there in the first place.
Since Zombie Zapper assumes the default passwords were left intact, it will not work against TFN2K, which forces you to use a new password during setup.
Links
The tool can be downloaded from: razor.bindview.com/tools/index.shtml.
I understand that this is quite the program. Basically during an attack, this program tells the DoS program to stop sending packets using the same language as the attacker is using.