0 Members and 1 Guest are viewing this topic.
ive read that three times and im still lost, anyone help me out here?
The very fact it refers to the WMW blocklist renders it useless for detecting flooders, because that list requires you've already detected them.. it's totally redundant.... or at least, that's how it reads to me....
for those who didn't understand it the basic idea is simple:run multiple primaries to get flooders to try connecting, and make a note of which IP Addresses tried connecting to that primary and which didn't (for that purpose simply logging inbound connections to live primaries would be effective), if the same IP Address attempts to connect to multiple primaries then it is a flooder - as the flooders will connect to many primaries whereas legitimate users would only connect to a single primary