TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Using Google to DDoS any website

6 点作者 coffeecodecouch大约 11 年前

1 comment

leepowers大约 11 年前
Previous discussion:<p><a href="https://news.ycombinator.com/item?id=7371176" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=7371176</a><p>For sites like Gravatar[1] that generate an image from a given URL:<p>&gt; In addition to allowing you to use your own image, Gravatar has a number of built in options which you can also use as defaults .... Most of these work by taking the requested email hash and using it to generate a themed image that is unique to that email address.<p>Not only would it such an attack function as a network DDOS, but could also cause CPU thrashing as thousands of images are generated simultaneously.<p>There may also a danger of an amplification attack using Gravatar (or a similar site). For instance, from the Gravatar docs:<p>&gt; If you&#x27;d prefer to use your own default image (perhaps your logo, a funny face, whatever), then you can easily do so by supplying the URL to an image in the d= or default= parameter.<p>Which will cause a Gravatar server to fetch the image in question.<p>So - in the Google spreadsheet an attacker could also add an additional Gravatar line for each image, doubling the number of requesting servers with little extra effort.<p>[1] <a href="https://en.gravatar.com/site/implement/images/" rel="nofollow">https:&#x2F;&#x2F;en.gravatar.com&#x2F;site&#x2F;implement&#x2F;images&#x2F;</a>