Upgrade to Pro — share decks privately, control downloads, hide ads and more …

DDoS attacks in 2016-2017: A Breakthrough

DDoS attacks in 2016-2017: A Breakthrough

In early 2016, DDoS attacks and security strategies against them looked so trivial, giving an impression of running their course. A year later, the situation changed dramatically. The speaker offers to discuss these changes, their causes, background and consequences, as well as their relationship with the development of IoT.

More Decks by Artyom "Töma" Gavrichenkov

Other Decks in Technology

Transcript

  1. 18

  2. • NTP • DNS • SNMP • SSDP • ICMP

    • NetBIOS • LDAP • RIPv1 • PORTMAP • CHARGEN • QOTD • Quake • Steam • … Vulnerable protocols
  3. • NTP • DNS • SNMP • SSDP • ICMP

    • NetBIOS • LDAP • RIPv1 • PORTMAP • CHARGEN • QOTD • Quake • Steam • … Vulnerable protocols Amplification can be identified by source port!*
  4. Wordpress Pingback GET /whatever User-Agent: WordPress/3.9.2; http://example.com/; verifying pingback from

    192.0.2.150 • 150 000 – 170 000 vulnerable servers at once • SSL/TLS-enabled
  5. Wordpress Pingback GET /whatever User-Agent: WordPress/3.9.2; http://example.com/; verifying pingback from

    192.0.2.150 • 150 000 – 170 000 vulnerable servers at once • SSL/TLS-enabled • Millions of vulnerable servers available in the Internet
  6. Internet of Things • Webcams, routers, smartphones, coffee makers •

    Cheap hardware and software • (Little to) NO software updates
  7. Internet of Things • Webcams, routers, smartphones, coffee makers •

    Cheap hardware and software • (Little to) NO software updates, including security fixes
  8. Internet of Things • Webcams, routers, smartphones, coffee makers •

    Cheap hardware and software • (Little to) NO software updates, including security fixes •Default logins/passwords
  9. Internet of Things • Webcams, routers, smartphones, coffee makers •

    Cheap hardware and software • (Little to) NO software updates, including security fixes •Default logins/passwords •Full Internet access
  10. Internet of Things • Webcams, routers, smartphones, coffee makers •

    Cheap hardware and software • (Little to) NO software updates, including security fixes •Default logins/passwords •Full Internet access •And all it takes – a crawler.
  11. 21:30:01.226868 IP 94.251.116.51 > 178.248.233.141: GREv0, length 544: IP 184.224.242.144.65323

    > 167.42.221.164.80: UDP, length 512 21:30:01.226873 IP 46.227.212.111 > 178.248.233.141: GREv0, length 544: IP 90.185.119.106.50021 > 179.57.238.88.80: UDP, length 512 21:30:01.226881 IP 46.39.29.150 > 178.248.233.141: GREv0, length 544: IP 31.173.79.118.42580 > 115.108.7.79.80: UDP, length 512
  12. 21:30:01.226868 IP 94.251.116.51 > 178.248.233.141: GREv0, length 544: IP 184.224.242.144.65323

    > 167.42.221.164.80: UDP, length 512 21:30:01.226873 IP 46.227.212.111 > 178.248.233.141: GREv0, length 544: IP 90.185.119.106.50021 > 179.57.238.88.80: UDP, length 512 21:30:01.226881 IP 46.39.29.150 > 178.248.233.141: GREv0, length 544: IP 31.173.79.118.42580 > 115.108.7.79.80: UDP, length 512
  13. Joomla RCE: CVE-2016-8870 • 28.10.2016: patchset released • First attempts

    to exploit: within 24 hours • After 36 hours: automated scans & pwn Source: Wallarm honeypots, https://wallarm.com/
  14. Akamai: CDN vs DDoSM aut-num: AS20940 as-name: AKAMAI-ASN1 org: ORG-AT1-RIPE

    mnt-by: AKAM1-RIPE-MNT mnt-routes: AKAM1-RIPE-MNT
  15. Akamai: CDN vs DDoSM aut-num: AS20940 as-name: AKAMAI-ASN1 org: ORG-AT1-RIPE

    mnt-by: AKAM1-RIPE-MNT mnt-routes: AKAM1-RIPE-MNT ASNumber: 32787 ASName: PROLEXIC- TECHNOLOGIES-DDOS- MITIGATION-NETWORK Ref: https://whois.arin.net/ rest/asn/AS32787
  16. Akamai: CDN vs DDoSM aut-num: AS20940 as-name: AKAMAI-ASN1 org: ORG-AT1-RIPE

    mnt-by: AKAM1-RIPE-MNT mnt-routes: AKAM1-RIPE-MNT ASNumber: 32787 ASName: PROLEXIC- TECHNOLOGIES-DDOS- MITIGATION-NETWORK Ref: https://whois.arin.net/ rest/asn/AS32787 https://www.peeringdb.com/asn/20940
  17. Akamai: CDN vs DDoSM aut-num: AS20940 as-name: AKAMAI-ASN1 org: ORG-AT1-RIPE

    mnt-by: AKAM1-RIPE-MNT mnt-routes: AKAM1-RIPE-MNT ASNumber: 32787 ASName: PROLEXIC- TECHNOLOGIES-DDOS- MITIGATION-NETWORK Ref: https://whois.arin.net/ rest/asn/AS32787 https://www.peeringdb.com/asn/20940