Autor Beitrag
patmann2001
ontopic starontopic starontopic starontopic starontopic starontopic starontopic starontopic star
Beiträge: 201

Windows 7 Prof.
Delphi XE2
BeitragVerfasst: Di 27.06.06 22:04 
Hallo Leute,

ich möchte gern Interprozesscommunikation (IPC) über Sockets machen. Soweit kein Problem, meine Kollegen meinen jedoch, das meine Server dann durch einen DoS (Denial of Service) Angriff auszuschalten währen.
Ich habe daher überlegt, das ich auf alle Connect Anfragen die nicht die IP 127.0.0.1 (LokalHost) als Absender haben, gar nicht reagiere (Socket.close).
Würde mich das nicht vor einem DoS schützen??

Problematisch würde natürlich ein DRDoS werden, aber da ich nur an bereits angemeldete Clients antworte (TCP/IP) und keine "offene" Kommunikatin zulassen möchte, müsste ich da doch auch sicher sein.

Ist mein Gedane so richtig oder habe ich da was übersehen? :?:

cu Patmann
BenBE
ontopic starontopic starontopic starontopic starontopic starontopic starhalf ontopic starofftopic star
Beiträge: 8721
Erhaltene Danke: 191

Win95, Win98SE, Win2K, WinXP
D1S, D3S, D4S, D5E, D6E, D7E, D9PE, D10E, D12P, DXEP, L0.9\FPC2.0
BeitragVerfasst: Di 27.06.06 22:37 
DoS ist nicht an Sockets gebunden. Es gab auch schon DoS-Schwachstellen, die man durch manipulierte Eingaben dazu bringen konnte, dass sie nicht mehr reagiert haben...

Zu deinem Problem: Du kannst beim Server.Listen angeben, auf welcher IP der Server warten soll. Wer hier 0.0.0.0 angibt, ist selber schuld, wenn er nur lokale Verbindungen brauch ...

_________________
Anyone who is capable of being elected president should on no account be allowed to do the job.
Ich code EdgeMonkey - In dubio pro Setting.
patmann2001 Threadstarter
ontopic starontopic starontopic starontopic starontopic starontopic starontopic starontopic star
Beiträge: 201

Windows 7 Prof.
Delphi XE2
BeitragVerfasst: Mi 28.06.06 12:13 
Danke für deine Antwort.

cu Patmann