9 ms·
TP240PhoneHome Reflection/Amplification DDoS Attack Vector
- dschuetz 5y agoWe're approaching the limits here, I think.
- zaik 5y agoWhy would there be a theoretical limit?
- pickledcods 5y agobecause that value is a physical limit
- black_puppydog 5y agoHow so? If I find a vector that triggers the remote system to `cat /dev/random | netcat $target` then there's no limit for how much traffic my refelection generates, no?
- pickledcods 5y agolook at the binary, it's an overflow value. Like it didn't fit the spreadsheet.
- nostoc 5y agoI assume by limit OP means the remote system's bandwidth. at 4 billion to 1, there's in practice very little difference between CVE-2022-26143 and what you describe. Both will be capped at the same number by the bandwidth available to the offending system.
- nathanyz 5y agoLimit would end up being when you send 1 byte of traffic to a box and that box amplifies it to whatever its own max outbound bandwidth rate is. This seems like it would exceed that in many cases, since 1 byte in => 4.2 gigabytes out. Which is roughly 33.6 gbps. Not sure many of these vulnerable boxes actually have that amount of outbound bandwidth to utilize. (Please feel free to correct my quick math if I messed it up)
- jwilk 5y agoWhy do you want to send everything in one second?
- nathanyz 5y agoThis is a good point, but then you need more boxes to perform the DDOS as the reason they are effective is overwhelming the packets per second or bandwidth per second of the receiving networks. So it definitely does allow for a sustained attack by a single box with limited outbound bandwidth, but that blunts the usual reasoning for why the amplification is so dangerous. Another interesting impact of this is that the higher the amplification, the more likely it is noticeable by the server that is being abused. I mean if you clog the outbound network for a company they will notice and try to resolve immediately. Versus some milder amplification where it can go under the radar, or at least the business impact urgency radar of a company much longer.
- supertrope 5y agoAt least it was a 32-bit integer, not 64
- londons_explore 5y agoTracking down these systems is easy, so these issues can normally be solved pretty easily. Thats because typically any amplification vector doesn't allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.
- egberts1 5y agounless the amplifier mechanism is widespread.
- DFHippie 5y agoConcerning this particular vector: > Approximately 2,600 of these systems have been incorrectly provisioned so that an unauthenticated system test facility has been inadvertently exposed to the public internet
- sp332 5y agoIt could be easily solved by the operator, but that doesn't mean it's easy for the victims to get the operators to fix their stuff. These amplifiers are already run by people who ignored the software manufacturer's directions. What are the odds they will actually install the new version that's harder to abuse?
- amalcon 5y agoUsually[0] contacting the operator's ISP and informing them of the situation will get said ISP to contact said operator. All that outbound traffic does represent a cost to the ISP, after all. A call from your ISP usually gets a bit more respect than a call from some random person. [0]- In the US; I don't know about anywhere else
- bombcar 5y agoIn the past what usually happens is the ISP disconnects you until you prove you've fixed whatever it was (sometimes they're nice and block just part of the connection, or give you a warning). Surprisingly enough, the ISP often has no real way of contacting anyone; the easiest is to cut the connection and wait for a complaint.
- beeforpork 5y agoOn the bright side, we're lucky they did not use a 64-bit int.
- frays 5y agoIs it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses from other states' militaries?
- tyingq 5y agoI guess it depends on the analogy, and whether physical location means anything for the internet. Piracy of commercial ships, for example.
- avereveard 5y agoso, china's internet? because that's what you're actually asking when you ask a policed internet.
- black_puppydog 5y agoSorry but Walmart has cameras, guards, and most importantly locked windows and doors. Just because nobody has figured out (or bothered to invest into) building the equivalent of basic security doesn't mean it's the state's responsibility. It is the government's responsibility to make sure companies take their responsibilities of protecting their customers' data, and the internet more broadly from the impact of the company's decisions.
- jgrahamc 5y ago220 billion percent! And other scary numbers! Coordinated disclosure: https://blog.cloudflare.com/cve-2022-26143/ https://blog.cloudflare.com/cve-2022-26143/ Info for Cloudflare customers: https://blog.cloudflare.com/cve-2022-26143-amplification-attack/ https://blog.cloudflare.com/cve-2022-26143-amplification-att...
- api 5y agoI'm really concerned that DDOS attacks are going to lead to the death of the open Internet and its balkanization and isolation behind walled gardens. If you look at where Cloudflare and some of the big clouds are going with their private networks, private backplanes, and "secure your traffic by putting it all over our network" zero trust plans it seems to be going that way. If open peering and the open Internet are to survive I think serious work needs to be done to fight DDOS attacks. It needs to be an effort analogous to the "war on spam" in the late 1990s / early 2000s. Unfortunately that war was sort of lost; e-mail is in practice barely an open protocol anymore and almost all e-mail is handled by a few giant companies that can leverage big data to filter spam. If you try to DIY a mail server you'll be simultaneously hit by spam and have to constantly fight mistaken filtration by larger e-mail providers who tend to distrust small mail servers by default. If the open Internet succumbs to DDOS "spam," we will lose something really huge and important. It would be the ultimate casualty of what so far has been almost a law (with very few exceptions): all open systems are destroyed by abuse if they become sufficiently popular. We also can't just leave it to the free market because the only solution the market will likely come up with is walled gardens. It's the easiest to engineer solution and the easiest to monetize.
- smasher164 5y agoIt's interesting that you say that, because we've already sort of balkanized around ISPs. However, CDNs and DDOS protection popped up around services that ISPs couldn't provide. Maybe the dream is for ISPs to provide these services as well, making it more tenable for regular users to self-host.
- throw0101a 5y ago> If you look at where Cloudflare and some of the big clouds are going with their private networks, private backplanes, and "secure your traffic by putting it all over our network" zero trust plans it seems to be going that way. All the networks of the Internet are already private, just like the networks of AOL and CompuServe were private back in the day: your ISP's network is private, YouTube's network is private, AWS' network is private. It's just that those private networks agree to talk to each other. Otherwise your ISP would have to re-create YouTube and Reddit/forums and eBay/marketplace and…, and YouTube would have to buildout (inter)national network to connect their video services to people's homes. Just like AOL and CompuServe had to build out information services and a connectivity infrastructure back in the day. Now each of the previously walled gardens (messaging, forums, marketplaces, connectivity, etc) is done by its own entity, each taking a slice of the monetary pie for the service(s) they provide. The Internet is a 'network of networks', but it is also an agreement: an agreement for everyone to talk to everyone else.
- _joel 5y agoNow that's a ping of death!
- StartupMemoryLn 5y agoSee: https://blog.cloudflare.com/cve-2022-26143/ https://blog.cloudflare.com/cve-2022-26143/ or: http://archive.today/TX3t7 http://archive.today/TX3t7
- deleted 5y ago[deleted]
- operator1 5y agoDoes anyone have any data on what networks or organizations were on the receiving side of these attacks?
- tgsovlerkhgsel 5y agoSeems like a potential mitigation would be to send the affected devices a small stream of packets that tell them to generate traffic for e.g. an invalid IP, local IP, or their own public IP. Once that hits, the device would then be sending the traffic harmlessly to /dev/null for the next 14 hours and be unavailable for attacks. Not sure about the legal and ethical implications of that.