Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

4/30/2013
03:30 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Printers, Routers And Other Internet Devices Being Hijacked To Participate In DrDoS Cyber Attacks

New Prolexic white paper explains how to secure your devices and infrastructure from SNMP, NTP, and CHARGEN attacks

HOLLYWOOD, FL – (April 30, 2013) – Prolexic, the global leader in Distributed Denial of Service (DDoS) protection services, announced today that Distributed Reflection and Amplification Denial of Service (DrDoS) attacks have grown increasingly popular with malicious actors as the number of vulnerable network appliances and servers has grown.

While DrDoS attack tactics have been used successfully for more than a decade, their popularity and effectiveness has increased during the past year. Specific DrDoS attacks target IP-based devices – printers, cameras, routers, hubs, sensors and other network devices – to take advantage of inherent vulnerabilities in standard network protocols, coopt the devices, and transform them into malicious bots.

"Protocol reflection attacks are a serious problem, but system administrators can help protect their organization and the Internet community by taking steps to avoid participating in these types of DrDoS attacks," said Stuart Scholly, Prolexic President. "Unfortunately, the protocols were written with functionality, not security, in mind. The Internet used to be a safer place than it is now."

DrDoS attacks using these protocols can be difficult to trace back to the malicious actor because they often involve spoofing, or faking, the origin of the attack.

In the new DrDoS white paper, the Prolexic Security Engineering & Response Team (PLXsert) explains how malicious actors leverage three common network protocols inherent in network servers and devices:

Simple Network Management Protocol (SNMP), used to communicate with IP-based devices, such as routers

Network Time Protocol (NTP), used to synchronize time and date information across the network

Character Generation Protocol (CHARGEN), used to test and debug network connections

The white paper, second in the DrDoS series, explains the protocol vulnerabilities and how they are used in DDoS attacks. It also identifies actions system administrators can take to reduce, or mitigate, the vulnerability of their network devices and servers.

The SNMP, NTP, CHARGEN Reflection Attacks white paper by PLXsert is available free of charge at www.prolexic.com/drdos.

About the Prolexic Security Engineering & Response Team (PLXsert)

PLXsert monitors malicious cyber threats globally and analyzes DDoS attacks using proprietary techniques and equipment. Through data forensics and post attack analysis, PLXsert is able to build a global view of DDoS attacks, which is shared with customers. By identifying the sources and associated attributes of individual attacks, the PLXsert team helps organizations adopt best practices and make more informed, proactive decisions about DDoS threats.

Details of Prolexic's DDoS mitigation activities and insights into the latest tactics, types, targets and origins of global DDoS attacks are provided in quarterly reports published by the company. A complimentary copy of Prolexic's most recent Global DDoS Attack Report is available at www.prolexic.com/attackreports.

About Prolexic

Prolexic is the world's largest, most trusted Distributed Denial of Service (DDoS) mitigation provider. Able to absorb the largest and most complex attacks ever launched, Prolexic restores mission-critical Internet-facing infrastructures for global enterprises and government agencies within minutes. Ten of the world's largest banks and the leading companies in e-Commerce, SaaS, payment processing, travel/hospitality, gaming and other at-risk industries rely on Prolexic to protect their businesses. Founded in 2003 as the world's first in-the-cloud DDoS mitigation platform, Prolexic is headquartered in Hollywood, Florida, and has scrubbing centers located in the Americas, Europe and Asia. To learn more about how Prolexic can stop DDoS attacks and protect your business, please visit www.prolexic.com, follow us on LinkedIn, Facebook, Google+, YouTube, and @Prolexic on Twitter.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14821
PUBLISHED: 2019-09-19
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->l...
CVE-2019-15032
PUBLISHED: 2019-09-19
Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal server information.
CVE-2019-15033
PUBLISHED: 2019-09-19
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to index.php, when sending a file to a remote server, as demonstrated by the file=http%3A%2F%2F192.168.1.2 substring.
CVE-2019-16412
PUBLISHED: 2019-09-19
In goform/setSysTools on Tenda N301 wireless routers, attackers can trigger a device crash via a zero wanMTU value. (Prohibition of this zero value is only enforced within the GUI.)
CVE-2019-16510
PUBLISHED: 2019-09-19
libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrated by server_example_goose.