SlideShare uma empresa Scribd logo
1 de 2
Baixar para ler offline
New DDoS Attack Tools and the DDoS Marketplace

The DDoS-as-a-Service marketplace has expanded to include new distributed denial of service
(DDoS) attack tools. These new tools can discover the IP address of servers that can be used by
attackers to generate a type of DDoS attack called a reflection attack or DrDoS attack. An attacker
can use a scanner tool to make lists of thousands of vulnerable servers, and then load a list into a
DrDoS attack tool to launch attacks or sell the lists to others.

Although the existence of IP address scanner tools is not new, they are now available freely and
publicly. The widespread availability of scanner tools and the demand for lists of servers
specifically vulnerable to reflection attacks is unique to Q3 2013 – indicating a worrisome DDoS
attack trend.

Not surprisingly, the DrDoS attacks facilitated by these scanner tools are on the rise. In these
attacks, the attacker’s target is overwhelmed by traffic generated by common network protocols
on the vulnerable servers, such as DNS, SNMP and CHARGEN.

The use of the CHARGEN reflection attack has enjoyed a recent resurgence. CHARGEN is a legacy
protocol that was believed to be obsolete. Unfortunately, many servers running older Windows
operating systems still have the protocol enabled, which is unnecessary – and dangerous.
How a CHARGEN attack works

When CHARGEN is used in a DrDoS attack, the attacker sends a spoofed CHARGEN request to a
server, directing the output to the attacker’s target. The spoofing makes the vulnerable server,
which is called a victim (to distinguish it from the attacker’s ultimate target), respond not to the
attacker but to the target. The CHARGEN protocol sends lots of characters to the target. That’s
what CHARGEN was designed to do – generate characters for testing purposes. By exploiting
multiple servers with CHARGEN at once, the incoming flow of characters overwhelms the target.

Prolexic has mitigated DrDoS attacks involving servers participating in CHARGEN protocol attacks
from Africa, Asia, Australia, Canada, Europe, Latin America and the U.S. – every continent except
Antarctica!
What if your server were used by an attacker in a CHARGEN attack?

If your server were used in a CHARGEN attack, your server would send unwanted traffic to the
attacker’s target, probably without your knowledge. When combined with the output of other
vulnerable servers, the attack would likely result in an outage from denial of service at the target.
In addition, your server would perform poorly. Rather than spending its time processing your
requests, it would be busy sending unwanted characters to the attacker’s target.

1
How to disable CHARGEN on a Microsoft Windows server

If you have a server running and older version of a Windows server operating system – especially
NT through Windows 2008 R2 – it is likely vulnerable to becoming an unwilling participant in a
DrDoS attack. The following shows how to turn off CHARGEN on a Windows 2000 server:
Step 1
• Open the server configuration panel
• Select the Advanced drop
down menu
• Select Optional
Components
Step 2
• Select Networking Services
• Click Details
Step 3
• Uncheck Simple TCP/IP
Services
• Click OK

Steps 4-6
• Click Next, Next, and Finish.

Figure 1: Uncheck Simple TCP/IP Services in Step 3. This action
removes CHARGEN, Daytime, Discard, Echo and Quote of the Day.

Once you complete these steps, the CHARGEN protocol will be closed and will not respond to
requests. As a result, attackers can’t use your server to generate CHARGEN attack traffic.

Learn more in the Q3 2013 Global DDoS Attack Report

The Q3 2013 Global DDoS Attack Report includes:
• Why reflection attacks are increasingly popular
• Parts of a CHARGEN attack, step by step
• Details of specific CHARGEN attacks stopped by Prolexic
• Players in the reflection attack (DrDoS) marketplace
• How to turn off CHARGEN to protect your servers from being used in attacks

The more you know about DDoS attacks, the better you can protect your network against
cybercrime. Download the free report at www.prolexic.com/attackreports.

About Prolexic
Prolexic Technologies is the world’s largest and most trusted provider of DDoS protection and
mitigation services. Learn more at www.prolexic.com.

2

Mais conteúdo relacionado

Último

Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
amitlee9823
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
Matteo Carbone
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Dipal Arora
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
lizamodels9
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
amitlee9823
 

Último (20)

M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear Regression
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdf
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdf
 

Destaque

Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Destaque (20)

PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 
Barbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy Presentation
 

New DDoS Attack Tools and the DDoS Marketplace

  • 1. New DDoS Attack Tools and the DDoS Marketplace The DDoS-as-a-Service marketplace has expanded to include new distributed denial of service (DDoS) attack tools. These new tools can discover the IP address of servers that can be used by attackers to generate a type of DDoS attack called a reflection attack or DrDoS attack. An attacker can use a scanner tool to make lists of thousands of vulnerable servers, and then load a list into a DrDoS attack tool to launch attacks or sell the lists to others. Although the existence of IP address scanner tools is not new, they are now available freely and publicly. The widespread availability of scanner tools and the demand for lists of servers specifically vulnerable to reflection attacks is unique to Q3 2013 – indicating a worrisome DDoS attack trend. Not surprisingly, the DrDoS attacks facilitated by these scanner tools are on the rise. In these attacks, the attacker’s target is overwhelmed by traffic generated by common network protocols on the vulnerable servers, such as DNS, SNMP and CHARGEN. The use of the CHARGEN reflection attack has enjoyed a recent resurgence. CHARGEN is a legacy protocol that was believed to be obsolete. Unfortunately, many servers running older Windows operating systems still have the protocol enabled, which is unnecessary – and dangerous. How a CHARGEN attack works When CHARGEN is used in a DrDoS attack, the attacker sends a spoofed CHARGEN request to a server, directing the output to the attacker’s target. The spoofing makes the vulnerable server, which is called a victim (to distinguish it from the attacker’s ultimate target), respond not to the attacker but to the target. The CHARGEN protocol sends lots of characters to the target. That’s what CHARGEN was designed to do – generate characters for testing purposes. By exploiting multiple servers with CHARGEN at once, the incoming flow of characters overwhelms the target. Prolexic has mitigated DrDoS attacks involving servers participating in CHARGEN protocol attacks from Africa, Asia, Australia, Canada, Europe, Latin America and the U.S. – every continent except Antarctica! What if your server were used by an attacker in a CHARGEN attack? If your server were used in a CHARGEN attack, your server would send unwanted traffic to the attacker’s target, probably without your knowledge. When combined with the output of other vulnerable servers, the attack would likely result in an outage from denial of service at the target. In addition, your server would perform poorly. Rather than spending its time processing your requests, it would be busy sending unwanted characters to the attacker’s target. 1
  • 2. How to disable CHARGEN on a Microsoft Windows server If you have a server running and older version of a Windows server operating system – especially NT through Windows 2008 R2 – it is likely vulnerable to becoming an unwilling participant in a DrDoS attack. The following shows how to turn off CHARGEN on a Windows 2000 server: Step 1 • Open the server configuration panel • Select the Advanced drop down menu • Select Optional Components Step 2 • Select Networking Services • Click Details Step 3 • Uncheck Simple TCP/IP Services • Click OK Steps 4-6 • Click Next, Next, and Finish. Figure 1: Uncheck Simple TCP/IP Services in Step 3. This action removes CHARGEN, Daytime, Discard, Echo and Quote of the Day. Once you complete these steps, the CHARGEN protocol will be closed and will not respond to requests. As a result, attackers can’t use your server to generate CHARGEN attack traffic. Learn more in the Q3 2013 Global DDoS Attack Report The Q3 2013 Global DDoS Attack Report includes: • Why reflection attacks are increasingly popular • Parts of a CHARGEN attack, step by step • Details of specific CHARGEN attacks stopped by Prolexic • Players in the reflection attack (DrDoS) marketplace • How to turn off CHARGEN to protect your servers from being used in attacks The more you know about DDoS attacks, the better you can protect your network against cybercrime. Download the free report at www.prolexic.com/attackreports. About Prolexic Prolexic Technologies is the world’s largest and most trusted provider of DDoS protection and mitigation services. Learn more at www.prolexic.com. 2