40. DoS and DDoS – Availability Attacks
40.10 Putting It Together – Purple Team Mindset
Thodkyaat: DoS/DDoS chapter = availability + classes + SYN/amp/app + Mirai lesson + scrub stack + ethics + IR. Tools change; habit (own-lab only, rate limit, hide origin) rahate.
Interview model (clean English): "I never run floods or amplification against systems I do not own. In the lab I stress my own nginx, then apply rate limits and timeouts. For real incidents I escalate to ISP/CDN scrubbing and protect origin IP."
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
| Full chain in lab: weak origin → controlled load → outage | Purple Team: limit_req + firewall + monitoring proven |
| Shames SME during festival outage | Helps SME scrub + communicate; documents lessons for Raja/Rani |
Ravindra Bagale's Tip
Volumetric numbers look huge in the news – your first job is often an app-layer rate limit + a CDN checkbox. Keep the basics strong. Next up: session hijacking!
Ravindra Bagale's Tip – मराठी
Volumetric numbers बातम्यांमध्ये खूप मोठे दिसतात – तुमचे पहिले काम बऱ्याचदा app-layer rate limit + CDN tickbox असते. Basics strong ठेवा. आता पुढे session hijacking!
Ravindra Bagale's Tip – हिंदी
Volumetric numbers खबरों में बहुत बड़े दिखते हैं – आपका पहला काम अक्सर app-layer rate limit + CDN tickbox होता है. Basics strong रखो. अब आगे session hijacking!
Lab
Chapter project (40.9 box) complete kara. Mag 10 flashcards: DoS, DDoS, volumetric, SYN flood, amplification, slowloris-class, Mirai, scrubbing, Anycast, limit_req. Pair: ek Red "how availability breaks", ek Blue "how we survive".
Thodkyaat sangaycha tar
- DoS = few sources; DDoS = many (botnet) – both attack availability (उपलब्धता).
- Classes: volumetric, protocol, application-layer – different Blue controls.
- SYN flood → SYN cookies + rate limits; never flood shared/public networks.
- Amplification/reflection (DNS/NTP/Memcached) – study GitHub 2018; never amp the internet.
- App-layer: rate limits, timeouts, WAF, sensible workers.
- Mirai-class: IoT defaults + segmentation + egress hygiene.
- Defence stack: monitor, scrub, Anycast CDN, WAF, origin limits, firewalld/ufw.
- Lab ethics: own VMs/host-only only; IT Act awareness; project Build-Hack-Fix for Raja-Rani order page.
- IR: confirm → mitigate upstream → communicate → harden; CERT-In / cybercrime.gov.in awareness.
Samjla ka? DoS/DDoS shiklo – pan pratyek sobat bachav ani safe lab. Pudhchya chapter madhe **session hijacking** (session tokens, cookies, defence) – CEH modules pudhe. Chala pudhe, mitrano!