opportunityopenerdns
openerdns 时间:2021-05-02 阅读:(
)
1akamai's[stateoftheinternet]/SecurityBulletin11.
1OVERVIEW/PLXserthasbeenmonitoringanewtrendintheuseofDNSamplificationattacks.
AmplificationattacksarespecialtypesofDDoSattacksthataredesignedtogeneratelargeresponsepacketswithrelativelysmallrequests.
AttackersarecraftinglargeDNSTXT(text)recordstoincreaseamplification,magnifyingtheimpactoftheattack.
Forexample,severalcampaignsobservedsinceOctober4,2014containfragmentsoftexttakenfrompressreleasesissuedbytheWhiteHouse.
PLXsertsuspectsthattheDNSfloodertoolcontinuestobeusedinthesecampaigns.
BycraftingtheirownTXTrecords,attackerscanamplifyresponsesasdesiredanddirectthistraffictotargetedsites,including—butnotlimitedto—DNSservers.
Theamplifiedtrafficresponsecouldeventuallyoverwhelmthetargetedsiteandrenderitunabletorespondtoanyrequests.
AttackershaveusedlargeTXTrecordsinreflectionattacksinthepast.
PreviousvictimsofDNSamplificationattacksusingTXTrecordsincludesitessuchasisc.
organdmany.
govsites.
Withthisnewthreat,maliciousactorsarenowcraftingtheTXTrecordstoprovidethelargestresponsesizepossible,therebyhavingasmuchimpactaspossible.
TheTXTrecordsintheOctober2014attackshavebeenidentifiedasoriginatingfromtheguessinfosys.
comdomain.
1.
2HIGHLIGHTEDATTRIBUTESAttackstatistics§Peakbandwidth:4.
3Gigabitspersecond(Gbps)§Attackvectors:DNSreflectionandamplification§Sourceport(s):53§Destinationport(s):80,random1SECURITYBULLETIN:CRAFTEDDNSTEXTATTACKGSIID:1082TLP:GREEN11.
11.
14RISKFACTOR-MEDIUM2akamai's[stateoftheinternet]/SecurityBulletin2Primarytargets§Entertainment§Education§HightechconsultingSamplepayloads21:38:55.
972524IPX.
X.
X.
X.
53>X.
X.
X.
X.
52967:585613/0/3A50.
63.
202.
58,NSns71.
domaincontrol.
com.
,NSns72.
domaincontrol.
com.
,SOA,MXmailstore1.
secureserver.
net.
10,MXsmtp.
secureserver.
net.
0,TXT"PresidentObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigning13:43:36.
094522IPX.
X.
X.
X.
53>X.
X.
X.
X.
52506:1153210/13/16TXT"PresidenftxtObamaistakingaction",TXT[|domain]13:43:36.
094854IPX.
X.
X.
X.
53>X.
X.
X.
X.
5926:3540810/13/16TXT"Presidentalsooutlines""thedetailsaboutthetransmissionandtreatmentofEbola",TXT[|domain]2Figure1:TheentertainmentindustrywasthemaintargetoftheOctober2014DNSreflectionattacks.
3akamai's[stateoftheinternet]/SecurityBulletin33guessinfosys.
com.
85964INTXT"PresidentObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigningLegislationMyFrontPorchAmericansacrossthePresidentObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigningLe""gislationMyFrontPorchAmericansacrossthe"guessinfosys.
com.
85964INTXT"PresidentxtObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigningLegislationMyFrontPorchAmericansacrossthePresidentObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigning""LegislationMyFrontPorchAmericansacrossthe"guessinfosys.
com.
85964INTXT"PresidenftxtObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigningLegislationMyFrontPorchAmericansacrossthePresidentObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigning""LegislationMyFrontPorchAmericansacrossthe"guessinfosys.
com.
85964INTXT"InavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismornin""gInavideoreleasedthismorningInavideoreleasedthismorning,PresidentObamaaddressesthepeopleofWestAfricaabouttheEbolaoutbreakthatiscurrentlyaffectingthecountriesofLiberia,SierraLeone,Guinea,andNigeria.
ThePresidentreiterate""sinthevideothat,alongwithourpartnersaroundtheworld,theUnitedStatesisworkingwiththesecountries'governmentstohelpstopthedisease.
Thefirststepinthisfight,however,isknowingthefacts--whichiswhythePresidentalsooutlines""thedetailsaboutthetransmissionandtreatmentofEbola"guessinfosys.
com.
85964INTXT"InavideorInavideoreleasedthismorningeleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismornin""gInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorning"guessinfosys.
com.
85964INTXT"InaviddeorInavideoreleasedthismorningeleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorni""ngInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorning"guessinfosys.
com.
85964INTXT"InaviddeofrInavideoreleasedthismorningeleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorn""ingInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorning"Maliciousrequestsforguessinfosys.
comcanbeobservedinthewildonanongoingbasis.
Theserequestsattempttouseopenresolversasintermediatevictimstoreflectattacktrafficbacktoatarget.
Forthemostpart,theusefulnessofthesemaliciousdomainsdropsoffafterafewdaysasserveradminsbegintoblockofftherequests.
Figure2:Digresultsforguessinfosys.
comTXTrecordsshowmultipleTXTstringsliftedfromWhiteHousepressreleases4akamai's[stateoftheinternet]/SecurityBulletin4418:11:32.
433099IPX.
X.
X.
X.
16484>X.
X.
X.
X.
53:37834+[1au]ANYguessinfosys.
com.
(45).
.
.
.
E.
.
Ib.
.
.
.
.
.
.
Ma.
.
.
.
Fx@d.
5.
5.
guessinfosys.
com.
1.
3MITIGATION/DNSreflectionandamplificationattacksmakeuseofthesametacticsusedbyothertypesofreflectioncampaigns,suchasSNMP,SSDPorCHARGEN.
Theprimaryimpacttothetargetedserviceistheoverallbandwidthgenerated.
DNSreflectionattackscanbemitigatedsuccessfullyatthenetworkedge.
Anaccesscontrollist(ACL)wouldsufficebutonlyincaseswhereavailablebandwidthexceedsattacksize.
SomeDNSserverswillattempttoretrytheresponseusingTCP,butwhentherequestissenttothetargethost,notransferwilloccurandtheattemptwillfail.
DDoScloud-basedprotectionservicessuchastheoneprovidedbyAkamaiTechnologiesarerecommended.
Status:PLXsertiscurrentlymonitoringongoingcampaigns.
Futureadvisoriesandupdateswillbeprovidedifwarranted.
Figure3:Aguessinfosys.
comrequestattemptingtoreflecttrafficoffacustomerDNSserverFigure4:TheOctober2014craftedDNSTXTamplificationattackslastedmorethanfivehoursduringeachattackandpeakedatmorethan15hoursonOctober245akamai's[stateoftheinternet]/SecurityBulletinTheProlexicSecurityEngineeringandResearchTeam(PLXsert)monitorsmaliciouscyberthreatsgloballyandanalyzestheseattacksusingproprietarytechniquesandequipment.
Throughresearch,digitalforensicsandpost-eventanalysis,PLXsertisabletobuildaglobalviewofsecuritythreats,vulnerabilitiesandtrends,whichissharedwithcustomersandthesecuritycommunity.
Byidentifyingthesourcesandassociatedattributesofindividualattacks,alongwithbestpracticestoidentifyandmitigatesecuritythreatsandvulnerabilities,PLXserthelpsorganizationsmakemoreinformed,proactivedecisions.
Akamaiisaleadingproviderofcloudservicesfordelivering,optimizingandsecuringonlinecontentandbusinessapplications.
Atthecoreofthecompany'ssolutionsistheAkamaiIntelligentPlatformprovidingextensivereach,coupledwithunmatchedreliability,security,visibilityandexpertise.
Akamairemovesthecomplexitiesofconnectingtheincreasinglymobileworld,supporting24/7consumerdemand,andenablingenterprisestosecurelyleveragethecloud.
TolearnmoreabouthowAkamaiisacceleratingthepaceofinnovationinahyperconnectedworld,pleasevisitwww.
akamai.
comorblogs.
akamai.
com,andfollow@AkamaionTwitter.
AkamaiisheadquarteredinCambridge,MassachusettsintheUnitedStateswithoperationsinmorethan40officesaroundtheworld.
OurservicesandrenownedcustomercareenablebusinessestoprovideanunparalleledInternetexperiencefortheircustomersworldwide.
Addresses,phonenumbersandcontactinformationforalllocationsarelistedonwww.
akamai.
com/locations2014AkamaiTechnologies,Inc.
AllRightsReserved.
Reproductioninwholeorinpartinanyformormediumwithoutexpresswrittenpermissionisprohibited.
AkamaiandtheAkamaiwavelogoareregisteredtrademarks.
Othertrademarkscontainedhereinarethepropertyoftheirrespectiveowners.
Akamaibelievesthattheinformationinthispublicationisaccurateasofitspublicationdate;suchinformationissubjecttochangewithoutnotice.
Published10/14.
5ABOUTPROLEXICSECURITYENGINEERING&RESEARCHTEAM(PLXSERT)/PLXsertmonitorsmaliciouscyberthreatsgloballyandanalyzestheseattacksusingproprietarytechniquesandequipment.
Throughresearch,digitalforensicsandpost-eventanalysis,PLXsertisabletobuildaglobalviewofsecuritythreats,vulnerabilitiesandtrends,whichissharedwithcustomersandthesecuritycommunity.
Byidentifyingthesourcesandassociatedattributesofindividualattacks,alongwithbestpracticestoidentifyandmitigatesecuritythreatsandvulnerabilities,PLXserthelpsorganizationsmakemoreinformed,proactivedecisions.
ABOUTAKAMAI/Akamaiistheleadingproviderofcloudservicesfordelivering,optimizingandsecuringonlinecontentandbusinessapplications.
AtthecoreoftheCompany'ssolutionsistheAkamaiIntelligentPlatformprovidingextensivereach,coupledwithunmatchedreliability,security,visibilityandexpertise.
Akamairemovesthecomplexitiesofconnectingtheincreasinglymobileworld,supporting24/7consumerdemand,andenablingenterprisestosecurelyleveragethecloud.
TolearnmoreabouthowAkamaiisacceleratingthepaceofinnovationinahyperconnectedworld,pleasevisitwww.
akamai.
comorblogs.
akamai.
com,andfollow@AkamaionTwitter.
spinservers是Majestic Hosting Solutions LLC旗下站点,主要提供国外服务器租用和Hybrid Dedicated等产品的商家,数据中心包括美国达拉斯和圣何塞机房,机器一般10Gbps端口带宽,高配置硬件,支持使用PayPal、信用卡、支付宝或者微信等付款方式。目前,商家针对部分服务器提供优惠码,优惠后达拉斯机房服务器最低每月89美元起,圣何塞机房服务器最低每月...
2021年6月底,raksmart开发出来的新产品“cloud-云服务器”正式上线对外售卖,当前只有美国硅谷机房(或许以后会有其他数据中心加入)可供选择。或许你会问raksmart云服务器怎么样啊、raksm云服务器好不好、网络速度快不好之类的废话(不实测的话),本着主机测评趟雷、大家受益的原则,先开一个给大家测评一下!官方网站:https://www.raksmart.com云服务器的说明:底层...
LOCVPS(全球云)发布了新上韩国机房KVM架构主机信息,提供流量和带宽方式,适用全场8折优惠码,优惠码最低2G内存套餐月付仅44元起。这是一家成立较早的国人VPS服务商,目前提供洛杉矶MC、洛杉矶C3、和香港邦联、香港沙田电信、香港大埔、日本东京、日本大阪、新加坡、德国和荷兰等机房VPS主机,基于KVM或者XEN架构。下面分别列出几款韩国机房KVM主机配置信息。韩国KVM流量型套餐:KR-Pl...
openerdns为你推荐
布局css企业建网站我想建立一个企业网站,需要多少钱??企业电子邮局企业邮箱怎么使用?95188是什么电话95188是什么号码我刚收到短信是什么支付宝的验证码zhuo爱作文:温暖的( )佛山海虹海虹蒸多长时间网上支付功能怎样开通网上支付功能?引擎收录搜索引擎的收录和索引是什么意思localsettingsLocal Settings这个文件夹是干什么的?上传软件如何将手机软件传给另外一个手机
如何注册域名 中文国际域名 欧洲欧洲vps a5域名交易 香港加速器 免备案空间 京东商城双十一活动 gg广告 域名转向 cdn加速是什么 河南移动m值兑换 支持外链的相册 华为云盘 厦门电信 万网空间管理 dnspod 卡巴斯基官网下载 阿里云邮箱个人版 服务器防御 服务器托管价格 更多