  • Suppose, I have a static IP on my PC and is known to others. None of my softwares listen for remote connection. Is it still possible for someone to DOS attack me in such cases? If yes, how it is possible?

    DDoS is not specific to HTTP or any service, a Distributed Denial of Service simply means that are multiples sources for the attacker trying to make it so your network connection is non functional.

    A denial of service could happen by making your system crash or become unresponsive (if its not on, it won't respond), by filling up all your bandwidth (your pipe), or most simply by physically severing the connection. Distributed denial of services attacks can be started by using multiple clients the attacker controls or by tricking innocent clients to participate.

    Refer to the OSI Model or the TCP Layers. HTTP is going to be at the application layer, but you can attack at any layer to cause denial of service.

    A very simple example of a lower level DDoS attack, would be the smurf attack. In this attack you take advantage of a broadcast message to all stations on network responding to the spoofed source target, which is the victim.

    A similar attack, is the DNS amplification attack, where you trick a bunch of DNS servers into giving unsolicited responses to the victim.

    Alternatively, if the attacker controls a botnet they can just send any type of unsolicited traffic and clog up your pipe or clog up your workstation with requests, pings, etc.

