Live data from Hacker News

Increase in Protocol 47 (GRE) traffic since end of December 2016

isc.sans.edu

1–10 of 13 posts

Re: Increase in Protocol 47 (GRE) traffic since end of December 2016

#5
There is a probably a consumer device that has a GRE listener running, and it is possible to send it a small packet, and it will return back some sort of error response. So classic amplification.

Thought given the moderate amount of traffic, maybe it isn't a hugely effective DDoS method.

Even if a consumer device doesn't use GRE, it doesn't mean it isn't there. GRE is often included in Linux kernels.

Re: Increase in Protocol 47 (GRE) traffic since end of December 2016

#6

There is a probably a consumer device that has a GRE listener running, and it is possible to send it a small packet, and it will return back some sort of error response. So classic amplification. Thought given the moderate amount of traffic, maybe it isn't a hugely effective DDoS method. Even if a consumer device doesn't use GRE, it doesn't mean it isn't there. GRE is often included in Linux kernels.

If that's the case it's possible they're just testing it out right now to figure out a good way to use it. Be interesting to watch this unfold.
Post reply on HN