3 ms·
They have it set to port 80 because they are attacking a service at port 80. If there is a service listening there it will cause the packet buffers to overflow
by codexon 13y ago
They have it set to port 80 because they are attacking a service at port 80.
If there is a service listening there it will cause the packet buffers to overflow if the server doesn't drain it fast enough long before you flood their bandwidth capacity.
They could easily attack other ports.
- nknighthb 13y ago1) UDP port 80 is not widely used. NTP packets directed at port 80 will not affect webservers, which use TCP port 80. 2) There are way too many different IPs being attacked on 80 for this to be a targeted attack on a particular odd deployment.
- pixl97 13y agoIs this just a side effect of a common script/tool being used?, or I wonder if enough firewall rules do stupid things like "Allow 80 Both (tcp|udp)" that it was an effective means of increasing the efficacy of the attack?
- nknighthb 13y agoI'm sure it's some common script/tool/service, but there's either something entirely non-obvious going on, or the person responsible just doesn't know what they're doing. Not unusual for scriptkiddies. Big-boy firewalls I'm familiar with don't have a single command for doing such a thing, since it won't match their state machine (being obvious nonsense), and the people managing them are generally unlikely to set the weird multiple rules necessary to get such a behavior. Consumer GUIs sometimes make such rules easy for the clueless to create, but not many NTP servers are going to be behind such rules. Gaining access to that handful of servers will be a net loss because of the relative ease with which your packets can be filtered by even slightly clueful upstreams. Against DDoS targets, you have a similar issue. Targets will generally be servers on some sort of professional link that isn't heavily filtered by the provider (and if it were, again, this is an unlikely set of rules for a pro to create), so the packets will at least make it to the "end-user" equipment before hitting a firewall with such an odd rule, at which point you're already hitting the target's actual bottleneck (their uplink).