DDoS attacks can be launched by using tools that are built to generate DDoS attacks.
There are many DDoS attack tools. Some well-known tools are listed below:
Trinoo — It is an attack tool that installs agent programs on compromised hosts and uses the agents through a master program to attack one Trinoo, or more target hosts by flooding them with UDP packets. Communication between the master and agents is password protected.
Tribal Flood Network (TFN) — TFN uses an attack approach similar to Trinoo, can generate multiple attacks, and use spoofed IP addresses. ICMP echo request flood, TCP SYN flood, and UDP flood are some of the attacks that can be launched by TFN.
TFN2K — TFN2K is an advanced version of TFN with features that makes it more difficult to detect. TFN2K uses multiple protocols including UDP, TCP, and ICMP.
Stacheldraht — Stacheldraht, which means barbed wire in German, has features that include those of Trinoo and TFN. Stacheldraht has features like encrypted communication between agents and the master program.
Shaft — Shaft is a tool similar to Trinoo that can launch packet-flooding attacks.
Trinity — Trinity is a flood attack tool that uses chat programs such as Internet Relay Chat (IRC).
MStream — MStream is a tool based on stream.c attack in which access to the handler is password protected.