>Blacklists and attribution do not hold that much value
Only because spoofing prevents them from being reliable in any way.
>in which case you want to be blacklisting the resolvers
This approach is idiotic and its the reason these attacks are still a problem. EVERY DNS SERVER can be used if it resolves anything, not just if it's an open resolver. So your blacklist would have to include the root name servers, the .com names servers, etc.
>if you aren't amplifying your attack using UDP protocols you will usually not going to be using IP spoofing in the first place
Completely false. SYN floods and non amplified UDP floods very frequently spoof because it makes pruning attacks upstream by source impossible.
I'm not sure where you got this information, but stop spreading it. It's protecting incompetent network operators, harassing service operators, and doing little to improve the security of the Internet.
Only because spoofing prevents them from being reliable in any way.
>in which case you want to be blacklisting the resolvers
This approach is idiotic and its the reason these attacks are still a problem. EVERY DNS SERVER can be used if it resolves anything, not just if it's an open resolver. So your blacklist would have to include the root name servers, the .com names servers, etc.
>if you aren't amplifying your attack using UDP protocols you will usually not going to be using IP spoofing in the first place
Completely false. SYN floods and non amplified UDP floods very frequently spoof because it makes pruning attacks upstream by source impossible.
I'm not sure where you got this information, but stop spreading it. It's protecting incompetent network operators, harassing service operators, and doing little to improve the security of the Internet.