![]() |
|
Register | FAQ | The Twelve Commandments | Members List | Calendar | Arcade | Find the Best VPN | Today's Posts | Search |
New Feature Requests Your idea for a cool new feature. Or, a LimeWire annoyance that has to get changed. |
![]() |
| LinkBack | Thread Tools | Display Modes |
| |||
![]() How to use Gnutella for EASY distributed denial of service attacks As I understand it, when an XML search (under the LimeWire System) is recieved by a servent, the search contains the URL of the XML schema it is using. The servent must then have a copy of the XML schema, so if it hasn't downloaded it already, it will download it now. Then the servent must parse the Schema, etc... So I could initate a XML search request with the URL of the Schema being somthing like: http://site_to_crash.com/fakeschema.xml Then all of the thousands of servents that would recieve it would contact that site and try to download that file. If I initate a few dozen search requests like this ( each with a different filename on the same host ) I could probably crash that site ( unless it has lots of servers ) |
| ||||
![]() This is not a bug: no such attack is possible, given the fact that LimeWire does not download schemas from the indicated URL. The URL for the schema is just a namespace (this is compliant to the W3C rules regarding XML schemas), and the namespace is always solved locally, by using a local store of the XML schemas. You should reread the specification of XML, and you'll see that a compliant XML parser does not need to refer the XSD schema by downloading it prior to validating a XML document. LimeWire uses the W3C-compliant "Xerces" XML parser for Java.
__________________ LimeWire is international. Help translate LimeWire to your own language. Visit: http://www.limewire.org/translate.shtml Last edited by verdyp; October 12th, 2002 at 07:45 PM. |
![]() |
| |
![]() | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Virus Attacks, Download Locations...Please Help | bsbkitty | Download/Upload Problems | 7 | October 3rd, 2005 08:36 PM |
Distributed computing! | sweeppicker | General Gnutella Development Discussion | 5 | January 10th, 2004 04:12 AM |
Hope you can help for instal problem where service@limewire.com ignore ... | tullefrk | Download/Upload Problems | 0 | November 28th, 2002 09:34 AM |
can't download = won't upload = same trivial problem: easy fix everyone apply it pls! | Unregistered | Download/Upload Problems | 1 | March 21st, 2002 07:41 PM |
Can we do something about attacks? | pitchurmenthees | Site Feedback | 2 | July 10th, 2001 08:21 AM |