Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

4/30/2013
03:30 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Printers, Routers And Other Internet Devices Being Hijacked To Participate In DrDoS Cyber Attacks

New Prolexic white paper explains how to secure your devices and infrastructure from SNMP, NTP, and CHARGEN attacks

HOLLYWOOD, FL – (April 30, 2013) – Prolexic, the global leader in Distributed Denial of Service (DDoS) protection services, announced today that Distributed Reflection and Amplification Denial of Service (DrDoS) attacks have grown increasingly popular with malicious actors as the number of vulnerable network appliances and servers has grown.

While DrDoS attack tactics have been used successfully for more than a decade, their popularity and effectiveness has increased during the past year. Specific DrDoS attacks target IP-based devices – printers, cameras, routers, hubs, sensors and other network devices – to take advantage of inherent vulnerabilities in standard network protocols, coopt the devices, and transform them into malicious bots.

"Protocol reflection attacks are a serious problem, but system administrators can help protect their organization and the Internet community by taking steps to avoid participating in these types of DrDoS attacks," said Stuart Scholly, Prolexic President. "Unfortunately, the protocols were written with functionality, not security, in mind. The Internet used to be a safer place than it is now."

DrDoS attacks using these protocols can be difficult to trace back to the malicious actor because they often involve spoofing, or faking, the origin of the attack.

In the new DrDoS white paper, the Prolexic Security Engineering & Response Team (PLXsert) explains how malicious actors leverage three common network protocols inherent in network servers and devices:

Simple Network Management Protocol (SNMP), used to communicate with IP-based devices, such as routers

Network Time Protocol (NTP), used to synchronize time and date information across the network

Character Generation Protocol (CHARGEN), used to test and debug network connections

The white paper, second in the DrDoS series, explains the protocol vulnerabilities and how they are used in DDoS attacks. It also identifies actions system administrators can take to reduce, or mitigate, the vulnerability of their network devices and servers.

The SNMP, NTP, CHARGEN Reflection Attacks white paper by PLXsert is available free of charge at www.prolexic.com/drdos.

About the Prolexic Security Engineering & Response Team (PLXsert)

PLXsert monitors malicious cyber threats globally and analyzes DDoS attacks using proprietary techniques and equipment. Through data forensics and post attack analysis, PLXsert is able to build a global view of DDoS attacks, which is shared with customers. By identifying the sources and associated attributes of individual attacks, the PLXsert team helps organizations adopt best practices and make more informed, proactive decisions about DDoS threats.

Details of Prolexic's DDoS mitigation activities and insights into the latest tactics, types, targets and origins of global DDoS attacks are provided in quarterly reports published by the company. A complimentary copy of Prolexic's most recent Global DDoS Attack Report is available at www.prolexic.com/attackreports.

About Prolexic

Prolexic is the world's largest, most trusted Distributed Denial of Service (DDoS) mitigation provider. Able to absorb the largest and most complex attacks ever launched, Prolexic restores mission-critical Internet-facing infrastructures for global enterprises and government agencies within minutes. Ten of the world's largest banks and the leading companies in e-Commerce, SaaS, payment processing, travel/hospitality, gaming and other at-risk industries rely on Prolexic to protect their businesses. Founded in 2003 as the world's first in-the-cloud DDoS mitigation platform, Prolexic is headquartered in Hollywood, Florida, and has scrubbing centers located in the Americas, Europe and Asia. To learn more about how Prolexic can stop DDoS attacks and protect your business, please visit www.prolexic.com, follow us on LinkedIn, Facebook, Google+, YouTube, and @Prolexic on Twitter.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9398
PUBLISHED: 2020-02-25
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.
CVE-2015-5201
PUBLISHED: 2020-02-25
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows r...
CVE-2019-4000
PUBLISHED: 2020-02-25
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.
CVE-2015-0565
PUBLISHED: 2020-02-25
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
CVE-2020-9393
PUBLISHED: 2020-02-25
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.