Ddos

1999hacktivist tacticclassic

DDoS, short for Distributed Denial of Service, is a cyberattack method that floods a target website or server with junk traffic from thousands of hijacked machines until it collapses under the load. First documented against a University of Minnesota system in August 1999, DDoS became the signature protest weapon of hacktivist groups like Anonymous and LulzSec through the late 2000s and 2010s before rising to headline-grabbing scale in the Spamhaus and Dyn attacks.

Overview

A DDoS attack works by hijacking a large number of computers, called a botnet, and directing them to send simultaneous requests at a single server or network until the flood saturates its bandwidth or exhausts its processing capacity, blocking legitimate users from reaching the service5. The 'distributed' part is what makes the tactic hard to shut down: because the traffic comes from thousands of scattered sources at once, blocking a single IP address does nothing meaningful, and defenders have to filter the noise from real requests at scale2.

Common attack methods include SYN floods, UDP floods, and DNS reflection, where attackers trick a DNS server into sending a large reply to a spoofed target address7. Paid 'stresser' or 'booter' services take a different approach, letting customers rent botnet firepower by the hour with a credit card, often running on hacked Internet of Things devices with default passwords6. That mix of easy tools, cheap services, and poorly secured hardware is why the technique kept scaling up rather than getting solved.

How It Spread

DDoS jumped into mainstream news in February 2000, when back-to-back attacks took down Yahoo, Amazon, Buy.com, CNN, eBay, E*Trade and ZDNet within days of each other, with Yahoo losses estimated near $500,000 and Amazon losses near $600,0003. Three years later, Oregon prosecutors charged 21-year-old Anthony Scott Clark of Beaverton with commanding a 20,000-computer botnet against eBay in 2003, exploiting a Windows vulnerability to build his army through a password-protected IRC server before pleading guilty to intentionally damaging a protected computer4.

The mid-2000s pushed DDoS into geopolitics and hacktivism. Estonian government sites were pounded by attacks traced back to Russia in 2007, similar assaults hit Georgian, Azerbaijani and Russian government targets in 2008, Anonymous adopted the Low Orbit Ion Cannon that same year for Project Chanology's Scientology attacks, then reused the model through Operation Payback against the RIAA and MPAA in September 2010, Operation Avenge Assange against PayPal, Visa and MasterCard after those companies cut off WikiLeaks, and LulzSec's brief 2011 spree against Sony Pictures and the CIA website3.

March 2013 raised the ceiling. Dutch web host CyberBunker allegedly retaliated against anti-spam group Spamhaus with a 300 gigabit-per-second flood, at that point the largest publicly announced DDoS attack on record and, according to Spamhaus chief executive Steve Linford, big enough to slow global internet traffic, with five national cyber-police forces investigating1. On October 21, 2016, an attack on DNS provider Dyn knocked Twitter, Spotify, Reddit, Tumblr and other major services offline across the US East Coast, powered by hijacked cameras, DVRs and home routers infected with IoT botnet malware that made the assembled botnet far bigger than any traditional PC-based one2.

How to Use This Meme

A typical DDoS attack has three parts: an attacker, a control channel, and a botnet of hijacked machines. In the 2000s the control channel was often a password-protected IRC server the bots would connect to and wait for orders from, as in the Anthony Scott Clark eBay case where 20,000 machines sat on IRC waiting for the launch command4. By the mid-2010s, paid 'stresser' services took the setup mainstream: Lizard Squad's Lizard Stresser, launched in late 2014, let paying customers rent DDoS firepower against any IP with a credit card, running on thousands of hacked home routers protected only by factory-default passwords6. Basic hacktivist tools like the Low Orbit Ion Cannon (LOIC) took a different route, with each participant opting in through a graphical interface, which Urban Dictionary flags as a 'bad choice' because it means the attackers are not unwitting bots and can be traced back7.

Cultural Impact

By the mid-2010s DDoS was mainstream news outside the security beat. The 2013 Spamhaus incident got wall-to-wall coverage in outlets like the BBC, with Spamhaus chief executive Steve Linford quoted saying the scale was unprecedented1. Security blogger Brian Krebs, whose site was itself knocked offline by Lizard Squad's stresser service in early 2015, traced the botnet back to hacked home routers in his follow-up investigation, cementing DDoS as a running story in tech journalism6. The 2016 Dyn attack pushed the message further: a single DNS provider outage could take down Twitter, Spotify, Reddit and Tumblr at the same time, and Krebs used the moment to warn about the growing pool of poorly secured Internet of Things devices being conscripted into botnets2.

Frequently Asked Questions