__  _______                             
 .--|  ||   _   |.-----.    .--------..-----.
 |  _  ||.  |   ||-- __| __ |        ||  -__|
 |_____||.  |   ||_____||__||__|__|__||_____|
        |:  1   |                            
        |::.. . |                            
        `-------'                            

by Ben Schmidt (supernothing) of spareclockcycles.org




POST GET



Disclaimer: I am not responsible for any malicious use of this demonstration, nor any damages caused by it. It was created as an example of the serious consequences of the Internet's increased reliance upon URL shortners, as well as how easy it is to create an unwitting DDoS botnet using new HTML5 features without actually exploiting a single computer. It is intended only for demonstration and testing purposes; if you target a site that is not yours, you are responsible for the consequences.

If you believe that you have been a victim of abuse due to the actions of this site's users, or you wish to add your site to a list of protected domains, please contact me at supernothing 4T spareclockcycles D0T org. Please note that simply by being on this list, you are *not* magically protected against the attack demonstrated here, only from those originating from this site. I (and many others) have posted on various mitagation techniques that might alleviate some of the effects of such an attack, but a permanent solution will probably require browser updates.


All code used on this site is released under the GPLv3, and is available here.

Coding is not a crime. [eff.org]