Dejkala
No Result
View All Result
  • Home
  • Tech
  • Banking & loan
  • Games
  • Car’s & Bike’s
  • Home
  • Tech
  • Banking & loan
  • Games
  • Car’s & Bike’s
No Result
View All Result
Dejkala
No Result
View All Result
Home Latest update

Meet the Windows servers that have been fueling massive DDoSes for months- Dejkala

by hasibul
October 28, 2022
in Latest update
0
Meet the Windows servers that have been fueling massive DDoSes for months- Dejkala
0
VIEWS
Share on FacebookShare on Twitter


Meet the Windows servers that have been fueling massive DDoSes for months

Aurich Lawson / Getty

A small retail business in North Africa, a North American telecommunications provider, and two separate religious organizations: What do they have in common? They’re all running poorly configured Microsoft servers that for months or years have been spraying the Internet with gigabytes-per-second of junk data in distributed-denial-of-service attacks designed to disrupt or completely take down websites and services.

In all, recently published research from Black Lotus Labs, the research arm of networking and application technology company Lumen, identified more than 12,000 servers—all running Microsoft domain controllers hosting the company’s Active Directory services—that were regularly used to magnify the size of distributed-denial-of-service attacks, or DDoSes.

A never-ending arms race

For decades, DDoSers have battled with defenders in a constant, never-ending arms race. Early on, DDoSers simply corralled ever-larger numbers of Internet-connected devices into botnets and then used them to simultaneously send a target more data than they can handle. Targets—be they game companies, journalists, or even crucial pillars of Internet infrastructure—often buckled at the strain and either completely fell over or slowed to a trickle.

Companies like Lumen, Netscout, Cloudflare, and Akamai then countered with defenses that filtered out the junk traffic, allowing their customers to withstand the torrents. DDoSers responded by rolling out new types of attacks that temporarily stymied those defenses. The race continues to play out.

One of the chief methods DDoSers use to gain the upper hand is known as reflection. Rather than sending the torrent of junk traffic to the target directly, DDoSers send network requests to one or more third parties. By choosing third parties with known misconfigurations in their networks and spoofing the requests to give the appearance they were sent by the target, the third parties end up reflecting the data at the target, often in sizes that are tens, hundreds, or even thousands of times bigger than the original payload.

Advertisement

Some of the better-known reflectors are misconfigured servers running services such as open DNS resolvers, the network time protocol, memcached for database caching, and the WS-Discovery protocol found in Internet-of-Things devices. Also known as amplification attacks, these reflection techniques allow record-breaking DDoSes to be delivered by the tiniest of botnets.

When domain controllers attack

Over the past year, a growing source of reflection attacks have been the Connectionless Lightweight Directory Access Protocol. A Microsoft derivation of the industry-standard Lightweight Directory Access Protocol, CLDAP uses User Datagram Protocol packets so Windows clients can discover services for authenticating users.

“Many versions of MS Server still in operation have a CLDAP service on by default,” Chad Davis, a researcher at Black Lotus Labs, wrote in an email. “When these domain controllers are not exposed to the open Internet (which is true for the vast majority of the deployments) this UDP service is harmless. But on the open Internet, all UDP services are vulnerable to reflection.”

DDoSers have been using it since at least 2017 to magnify data torrents by a factor of 56 to 70, making it among the more powerful reflectors available. When CLDAP reflection was first discovered, the number of servers exposing the service to the Internet was in the tens of thousands. After coming to public attention the number dropped. Since 2020, however, the number has once again climbed, with a 60-percent spike in the past 12 months alone, according to Black Lotus Labs.

The researcher went on to profile four of those servers. The most destructive one was affiliated with an unidentified religious organization and routinely generates torrents of unthinkable sizes of reflected DDoS traffic. As the following figure shows, this source was responsible for numerous bursts from July through September, with four of them exceeding 10 Gbps and one approaching 17 Gbps.


ShareTweetShare

Related Posts

Philips Evnia 7000 monitor review: It shines bright, but doesn’t spark envy- Dejkala
Latest update

Philips Evnia 7000 monitor review: It shines bright, but doesn’t spark envy- Dejkala

June 8, 2023
Adobe brings Firefly, ‘commercially safe’ image-generating AI, to the enterprise- Dejkala
Latest update

Adobe brings Firefly, ‘commercially safe’ image-generating AI, to the enterprise- Dejkala

June 8, 2023
ChatGPT for iOS gets support for Siri and Shortcuts- Dejkala
Latest update

ChatGPT for iOS gets support for Siri and Shortcuts- Dejkala

June 8, 2023
Boeing hit with a lawsuit over alleged “theft” of SLS rocket tools- Dejkala
Latest update

Boeing hit with a lawsuit over alleged “theft” of SLS rocket tools- Dejkala

June 8, 2023
The Bizarre Reality of Getting Online in North Korea- Dejkala
Latest update

The Bizarre Reality of Getting Online in North Korea- Dejkala

June 8, 2023
A survey of 472 corporate board directors ahead of the SEC's cyber-risk regulations: 76% have at least one expert, 62% say risk awareness is improving, and more (Wall Street Journal)- Dejkala
Latest update

A survey of 472 corporate board directors ahead of the SEC's cyber-risk regulations: 76% have at least one expert, 62% say risk awareness is improving, and more (Wall Street Journal)- Dejkala

June 8, 2023
Next Post
EU member countries agree to ban sale of gas-powered cars and vans starting in 2035- Dejkala

EU member countries agree to ban sale of gas-powered cars and vans starting in 2035- Dejkala

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Earn Money Online
  • Game news and review
  • Laptops
  • Latest update
  • Smartphone Reviews & News
  • TODAY Tech News
  • Upcoming Technology
  • Wordpress plugin
  • WordPress themes
  • World Wide Bike Reviews and News
  • World Wide Car News

Recommended

How to change how Alt + Tab behaves in Microsoft Edge- Dejkala

How to change how Alt + Tab behaves in Microsoft Edge- Dejkala

February 19, 2023
Twitter restores gold badges to some news organizations, including the BBC, The New York Times, and Bellingcat; the BBC and Bellingcat say they did not pay (Zoe Kleinman/BBC)- Dejkala

Twitter restores gold badges to some news organizations, including the BBC, The New York Times, and Bellingcat; the BBC and Bellingcat say they did not pay (Zoe Kleinman/BBC)- Dejkala

April 23, 2023
Analysts, investors, and founders expect a hard year for tech startups, including more down rounds; PitchBook says 400+ unicorns haven't raised funds since 2021 (Lizette Chapman/Bloomberg)- Dejkala

Analysts, investors, and founders expect a hard year for tech startups, including more down rounds; PitchBook says 400+ unicorns haven't raised funds since 2021 (Lizette Chapman/Bloomberg)- Dejkala

April 24, 2023
How to install Linux on your Raspberry Pi- Dejkala

How to install Linux on your Raspberry Pi- Dejkala

February 15, 2023
Research: between 100 and 150 crypto hedge funds, or 25%-40% of all specialized funds, have exposure to FTX or FTT, totaling around $2B (Financial Times)- Dejkala

Research: between 100 and 150 crypto hedge funds, or 25%-40% of all specialized funds, have exposure to FTX or FTT, totaling around $2B (Financial Times)- Dejkala

November 22, 2022
How to use Photo Unblur on the Google Pixel 7 series- Dejkala

How to use Photo Unblur on the Google Pixel 7 series- Dejkala

November 2, 2022
Philips Evnia 7000 monitor review: It shines bright, but doesn’t spark envy- Dejkala

Philips Evnia 7000 monitor review: It shines bright, but doesn’t spark envy- Dejkala

June 8, 2023
Adobe brings Firefly, ‘commercially safe’ image-generating AI, to the enterprise- Dejkala

Adobe brings Firefly, ‘commercially safe’ image-generating AI, to the enterprise- Dejkala

June 8, 2023
ChatGPT for iOS gets support for Siri and Shortcuts- Dejkala

ChatGPT for iOS gets support for Siri and Shortcuts- Dejkala

June 8, 2023

Categories

  • Earn Money Online
  • Game news and review
  • Laptops
  • Latest update
  • Smartphone Reviews & News
  • TODAY Tech News
  • Upcoming Technology
  • Wordpress plugin
  • WordPress themes
  • World Wide Bike Reviews and News
  • World Wide Car News

Pages

  • About Us
  • Banking & loan
  • Car’s & Bike’s
  • Contact Us
  • Games
  • Home
  • Home 2
  • Privacy Policy
  • Tech

© 2022 Dejkala

No Result
View All Result
  • Homepages
    • Home – Layout 1
    • Home – Layout 2

© 2022 Dejkala