Live data from Hacker News

TP240PhoneHome Reflection/Amplification DDoS Attack Vector

akamai.com

71–80 of 90 posts

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#71

Earlier quoted context omitted.

In principle, that's what the NSA would be doing. When DES was developed and standardized in 1976, the NSA had input in selecting some of the constants that were chosen for it [0]. It wasn't until the late 80s when independent development of differential cryptanalysis [1] came out, and people realized that the DES constants were deliberately chosen to be resistant to this attack. The NSA has since turned away from th…

Or maybe the choice of Dual EC DRBG constants are intended to protect against a new cryptanalysis technique known only to the NSA

internal documents leaked by Snowden and reported by the NYT confirmed the intent of the program

https://en.m.wikipedia.org/wiki/Bullrun_(decryption_program)

stop simping for the nsa

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#72

Tracking down these systems is easy, so these issues can normally be solved pretty easily. Thats because typically any amplification vector doesn't allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.

Your comment underestimates the task of remediation. Sure, we can very easily get a list of DDoS source IP addresses. Any decent network operator can get a list of flows matching some DDoS criteria and generate a report of IP addresses.

In the case of this TP240 attack, you're talking about ~2600 independent businesses across the world. Assuming you are able to determine the actual source of the traffic and work with a vendor to patch it, you're still tasked with somehow getting 2600 businesses to patch their systems or modify firewall rules.

In the case of the memcached amplification attack, Cloudflare saw upwards of 5800 source IPs in the attacks, and Shodan reported nearly 88000 IPs responding on port 11211 [1]. Tracking down the owners of 88k installations across public clouds, businesses, probably some residential networks, is a monumental task. There's nothing easy about it.

[1] https://blog.cloudflare.com/memcrashed-major-amplification-a...

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#73
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

Yes, it's walmart responsibility to protect their customers. It's their responsibility that their supply chain is not hacked to say distribute poison, it's their responsibility that the cameras they use in store are theirs and only they have access, it's their responsibility that the card I use in their terminal is safe. The example you gave won't be hurting the people, otherwise yes if they want to gain trust in dan…

23 people were killed and 23 more injured in a Walmart in El Paso in 2019 in a mass shooting. Is it your position that Walmart has sole responsibility for failing to prevent those deaths?

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#75
post #45
post #13

Earlier quoted context omitted.

It could be easily solved by the operator, but that doesn't mean it's easy for the victims to get the operators to fix their stuff. These amplifiers are already run by people who ignored the software manufacturer's directions. What are the odds they will actually install the new version that's harder to abuse?

Usually[0] contacting the operator's ISP and informing them of the situation will get said ISP to contact said operator. All that outbound traffic does represent a cost to the ISP, after all. A call from your ISP usually gets a bit more respect than a call from some random person. [0]- In the US; I don't know about anywhere else

It really depends on the ISP. After spending some time trying to get phishing sources taken down and not getting anywhere, I wouldn't be hopeful about DDoS (reflection) sources being taken down either. When I was running servers that were getting DDoSed frequently (but thankfully for short intervals and not with tons of bandwidth), trying to get chargen servers or wordpress servers fixed didn't even seem like an option. Just make sure my servers wouldn't fall over, or at least would fall over gracefully.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#76
post #36

Earlier quoted context omitted.

A failure to defend yourself is not aiding the enemy. That is insane. The government provides for the common security. That's one of it's most fundamental jobs. Imagine if your house was destroyed by a Russian drone and you were thrown in jail for not having enough "defense in depth" against drone strikes.

> A failure to defend yourself is not aiding the enemy. That is insane. Let's say you are the leader of a border post, and you leave your post unmanned allowing the enemy in - of course you will be held accountable. Exposing stuff to the Internet despite the manufacturer warning against it is at least grossly negligent and should be punished. We are at war with Russia and China on a nation-state level and on top of t…

"We are at war with Russia and China on a nation-state level"

Not aware of any country in the world that is currently in a declared state of war with Russia and China.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#77
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

What I find much more crazy is how this is made out as "state-sponsored hacking", even tho the article doesn't mention with a single sentence who or what the attackers are.

In that context instantly jumping to "state-sponsored!" strikes me not only as a needless, but particularly dangerous escalation.

It's like people forget that "cyber" is most of all asymmetrical and attribution is usually more of a guessing game than an exact science.

Yet nearly every larger hack is very quickly labeled as some kind of "state sponsored offense!" to serve foreign policy narratives, and most of all; Excuse the incompetence that often enabled such attacks in the very first place.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#78

Tracking down these systems is easy, so these issues can normally be solved pretty easily. Thats because typically any amplification vector doesn't allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.

Your comment underestimates the task of remediation. Sure, we can very easily get a list of DDoS source IP addresses. Any decent network operator can get a list of flows matching some DDoS criteria and generate a report of IP addresses. In the case of this TP240 attack, you're talking about ~2600 independent businesses across the world. Assuming you are able to determine the actual source of the traffic and work with…

> you're talking about ~2600 independent businesses across the world. Assuming you are able to determine the actual source of the traffic and work with a vendor to patch it, you're still tasked with somehow getting 2600 businesses to patch their systems or modify firewall rules.

You can be sure that by only null-routing their entire C-class, adjacent customers will loudly complain to the operator who will quickly identify the source and disconnect it. The best way to deploy fixes on the net has always been to first disconnect them. This way you don't have to convince anyone, it's done the other way around. Typically the CEO will instantly throw all the phones to the trash to get the net opened again.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#79
post #29

I'm really concerned that DDOS attacks are going to lead to the death of the open Internet and its balkanization and isolation behind walled gardens. If you look at where Cloudflare and some of the big clouds are going with their private networks, private backplanes, and "secure your traffic by putting it all over our network" zero trust plans it seems to be going that way. If open peering and the open Internet are t…

> If you try to DIY a mail server you'll be simultaneously hit by spam and have to constantly fight mistaken filtration by larger e-mail providers who tend to distrust small mail servers by default.

I have managed my own e-mail server for around 20 years.

Filtering spam has never been a problem.

On the other hand your second problem has indeed existed, i.e. with various large e-mail providers which either blocked completely my e-mail messages without signalling any error, or they delayed for 1 day or 2 my messages, or they required many resendings of a message until really passing it to the destination.

Fortunately such cases seem to have become much more seldom during the last couple of years.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#80
post #29

I'm really concerned that DDOS attacks are going to lead to the death of the open Internet and its balkanization and isolation behind walled gardens. If you look at where Cloudflare and some of the big clouds are going with their private networks, private backplanes, and "secure your traffic by putting it all over our network" zero trust plans it seems to be going that way. If open peering and the open Internet are t…

> If you try to DIY a mail server you'll be simultaneously hit by spam and have to constantly fight mistaken filtration by larger e-mail providers who tend to distrust small mail servers by default. I have managed my own e-mail server for around 20 years. Filtering spam has never been a problem. On the other hand your second problem has indeed existed, i.e. with various large e-mail providers which either blocked com…

I've seen hideously inconvenient email pauses between Office365 and a massive NGO, so it's not just little mail servers.
Post reply on HN