4 ms·
Very interesting (and frightening) about NTP, but I am afraid the first part of this claim about SNMP is not accurate: “Luckily, there are few open SNMP server
by nmc 13y ago
Very interesting (and frightening) about NTP, but I am afraid the first part of this claim about SNMP is not accurate:
“Luckily, there are few open SNMP servers on the Internet and SNMP usually requires authentication (although manly are poorly secured).”
A 2012 study revealed 13k+ open SNMP servers amongst 25 million Dutch IPs scanned [1].
[1] [Dutch] http://www.itsx.com/files/2012-11-SNMP-paper-v1.0.pdf http://www.itsx.com/files/2012-11-SNMP-paper-v1.0.pdf
- yourad_io 13y agoWell, yes and no. They could make the argument that in "internet scale" (sic) that still qualifies as "few" (at least when compared to the number of open DNS resolvers). On the other hand, the number of open DNS resolvers used in the attacks described in the presentation (slides 7/8) were around 30K, and with a much smaller amplification factor, so these numbers can still do some damage. It would be interesting to know if there have been "hybrid" DDOS attacks, utilizing multiple spoofed-origin+amplification methods.