Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

4/30/2013
03:30 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Printers, Routers And Other Internet Devices Being Hijacked To Participate In DrDoS Cyber Attacks

New Prolexic white paper explains how to secure your devices and infrastructure from SNMP, NTP, and CHARGEN attacks

HOLLYWOOD, FL – (April 30, 2013) – Prolexic, the global leader in Distributed Denial of Service (DDoS) protection services, announced today that Distributed Reflection and Amplification Denial of Service (DrDoS) attacks have grown increasingly popular with malicious actors as the number of vulnerable network appliances and servers has grown.

While DrDoS attack tactics have been used successfully for more than a decade, their popularity and effectiveness has increased during the past year. Specific DrDoS attacks target IP-based devices – printers, cameras, routers, hubs, sensors and other network devices – to take advantage of inherent vulnerabilities in standard network protocols, coopt the devices, and transform them into malicious bots.

"Protocol reflection attacks are a serious problem, but system administrators can help protect their organization and the Internet community by taking steps to avoid participating in these types of DrDoS attacks," said Stuart Scholly, Prolexic President. "Unfortunately, the protocols were written with functionality, not security, in mind. The Internet used to be a safer place than it is now."

DrDoS attacks using these protocols can be difficult to trace back to the malicious actor because they often involve spoofing, or faking, the origin of the attack.

In the new DrDoS white paper, the Prolexic Security Engineering & Response Team (PLXsert) explains how malicious actors leverage three common network protocols inherent in network servers and devices:

Simple Network Management Protocol (SNMP), used to communicate with IP-based devices, such as routers

Network Time Protocol (NTP), used to synchronize time and date information across the network

Character Generation Protocol (CHARGEN), used to test and debug network connections

The white paper, second in the DrDoS series, explains the protocol vulnerabilities and how they are used in DDoS attacks. It also identifies actions system administrators can take to reduce, or mitigate, the vulnerability of their network devices and servers.

The SNMP, NTP, CHARGEN Reflection Attacks white paper by PLXsert is available free of charge at www.prolexic.com/drdos.

About the Prolexic Security Engineering & Response Team (PLXsert)

PLXsert monitors malicious cyber threats globally and analyzes DDoS attacks using proprietary techniques and equipment. Through data forensics and post attack analysis, PLXsert is able to build a global view of DDoS attacks, which is shared with customers. By identifying the sources and associated attributes of individual attacks, the PLXsert team helps organizations adopt best practices and make more informed, proactive decisions about DDoS threats.

Details of Prolexic's DDoS mitigation activities and insights into the latest tactics, types, targets and origins of global DDoS attacks are provided in quarterly reports published by the company. A complimentary copy of Prolexic's most recent Global DDoS Attack Report is available at www.prolexic.com/attackreports.

About Prolexic

Prolexic is the world's largest, most trusted Distributed Denial of Service (DDoS) mitigation provider. Able to absorb the largest and most complex attacks ever launched, Prolexic restores mission-critical Internet-facing infrastructures for global enterprises and government agencies within minutes. Ten of the world's largest banks and the leading companies in e-Commerce, SaaS, payment processing, travel/hospitality, gaming and other at-risk industries rely on Prolexic to protect their businesses. Founded in 2003 as the world's first in-the-cloud DDoS mitigation platform, Prolexic is headquartered in Hollywood, Florida, and has scrubbing centers located in the Americas, Europe and Asia. To learn more about how Prolexic can stop DDoS attacks and protect your business, please visit www.prolexic.com, follow us on LinkedIn, Facebook, Google+, YouTube, and @Prolexic on Twitter.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14994
PUBLISHED: 2019-09-19
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version...
CVE-2019-15000
PUBLISHED: 2019-09-19
The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6....
CVE-2019-15001
PUBLISHED: 2019-09-19
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.1.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain rem...
CVE-2019-16398
PUBLISHED: 2019-09-19
On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskj_script_run.sh that executes a reverse shell.
CVE-2019-11779
PUBLISHED: 2019-09-19
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.