TP240PhoneHome Reflection/Amplification DDoS Attack Vector
1–10 of 90 posts
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#2Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#3We're approaching the limits here, I think.
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#4Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#5Thats because typically any amplification vector doesn't allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#6Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#7We're approaching the limits here, I think.
Why would there be a theoretical limit?
This seems like it would exceed that in many cases, since 1 byte in => 4.2 gigabytes out. Which is roughly 33.6 gbps. Not sure many of these vulnerable boxes actually have that amount of outbound bandwidth to utilize.
(Please feel free to correct my quick math if I messed it up)
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#8Isn't a primary responsibility of government to protect its citizens and businesses from other states' militaries?
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#9Coordinated disclosure: https://blog.cloudflare.com/cve-2022-26143/
Info for Cloudflare customers: https://blog.cloudflare.com/cve-2022-26143-amplification-att...