06-21-2013, 03:18 AM
Actually you are wrong. Both methods work, and this is the first weapon you have to fight against a ddos. It has a big problem however, thats why its not used too often, the users having IPs in the range of the blocked ones, will be blocked too... But nice aportation, for those who have no clue, this should help, at least making them learn abit of logic.
The first bit of logic to learn is what youre lacking. This in no shape or form will stop any DDoS attack. You have to understand UDP packets are still parsed by the NIC before they can be ruled out by the firewall. Making any sort of software useless, even deflate. You simply cannot stop a hardware attack with software.

