Live data from Hacker News

TP240PhoneHome Reflection/Amplification DDoS Attack Vector

akamai.com

1–10 of 90 posts

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#5
Tracking down these systems is easy, so these issues can normally be solved pretty easily.

Thats because typically any amplification vector doesn't allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#7
post #3
post #2

We're approaching the limits here, I think.

Why would there be a theoretical limit?

Limit would end up being when you send 1 byte of traffic to a box and that box amplifies it to whatever its own max outbound bandwidth rate is.

This seems like it would exceed that in many cases, since 1 byte in => 4.2 gigabytes out. Which is roughly 33.6 gbps. Not sure many of these vulnerable boxes actually have that amount of outbound bandwidth to utilize.

(Please feel free to correct my quick math if I messed it up)

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#8
Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes."

Isn't a primary responsibility of government to protect its citizens and businesses from other states' militaries?

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#10
post #3

Earlier quoted context omitted.

Why would there be a theoretical limit?

because that value is a physical limit

How so? If I find a vector that triggers the remote system to `cat /dev/random | netcat $target` then there's no limit for how much traffic my refelection generates, no?
Post reply on HN