opportunityopenerdns
openerdns 时间:2021-05-02 阅读:(
)
1akamai's[stateoftheinternet]/SecurityBulletin11.
1OVERVIEW/PLXserthasbeenmonitoringanewtrendintheuseofDNSamplificationattacks.
AmplificationattacksarespecialtypesofDDoSattacksthataredesignedtogeneratelargeresponsepacketswithrelativelysmallrequests.
AttackersarecraftinglargeDNSTXT(text)recordstoincreaseamplification,magnifyingtheimpactoftheattack.
Forexample,severalcampaignsobservedsinceOctober4,2014containfragmentsoftexttakenfrompressreleasesissuedbytheWhiteHouse.
PLXsertsuspectsthattheDNSfloodertoolcontinuestobeusedinthesecampaigns.
BycraftingtheirownTXTrecords,attackerscanamplifyresponsesasdesiredanddirectthistraffictotargetedsites,including—butnotlimitedto—DNSservers.
Theamplifiedtrafficresponsecouldeventuallyoverwhelmthetargetedsiteandrenderitunabletorespondtoanyrequests.
AttackershaveusedlargeTXTrecordsinreflectionattacksinthepast.
PreviousvictimsofDNSamplificationattacksusingTXTrecordsincludesitessuchasisc.
organdmany.
govsites.
Withthisnewthreat,maliciousactorsarenowcraftingtheTXTrecordstoprovidethelargestresponsesizepossible,therebyhavingasmuchimpactaspossible.
TheTXTrecordsintheOctober2014attackshavebeenidentifiedasoriginatingfromtheguessinfosys.
comdomain.
1.
2HIGHLIGHTEDATTRIBUTESAttackstatistics§Peakbandwidth:4.
3Gigabitspersecond(Gbps)§Attackvectors:DNSreflectionandamplification§Sourceport(s):53§Destinationport(s):80,random1SECURITYBULLETIN:CRAFTEDDNSTEXTATTACKGSIID:1082TLP:GREEN11.
11.
14RISKFACTOR-MEDIUM2akamai's[stateoftheinternet]/SecurityBulletin2Primarytargets§Entertainment§Education§HightechconsultingSamplepayloads21:38:55.
972524IPX.
X.
X.
X.
53>X.
X.
X.
X.
52967:585613/0/3A50.
63.
202.
58,NSns71.
domaincontrol.
com.
,NSns72.
domaincontrol.
com.
,SOA,MXmailstore1.
secureserver.
net.
10,MXsmtp.
secureserver.
net.
0,TXT"PresidentObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigning13:43:36.
094522IPX.
X.
X.
X.
53>X.
X.
X.
X.
52506:1153210/13/16TXT"PresidenftxtObamaistakingaction",TXT[|domain]13:43:36.
094854IPX.
X.
X.
X.
53>X.
X.
X.
X.
5926:3540810/13/16TXT"Presidentalsooutlines""thedetailsaboutthetransmissionandtreatmentofEbola",TXT[|domain]2Figure1:TheentertainmentindustrywasthemaintargetoftheOctober2014DNSreflectionattacks.
3akamai's[stateoftheinternet]/SecurityBulletin33guessinfosys.
com.
85964INTXT"PresidentObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigningLegislationMyFrontPorchAmericansacrossthePresidentObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigningLe""gislationMyFrontPorchAmericansacrossthe"guessinfosys.
com.
85964INTXT"PresidentxtObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigningLegislationMyFrontPorchAmericansacrossthePresidentObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigning""LegislationMyFrontPorchAmericansacrossthe"guessinfosys.
com.
85964INTXT"PresidenftxtObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigningLegislationMyFrontPorchAmericansacrossthePresidentObamaistakingactiontohelpensureopportunityforallAmericans.
PresidentObamaSigning""LegislationMyFrontPorchAmericansacrossthe"guessinfosys.
com.
85964INTXT"InavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismornin""gInavideoreleasedthismorningInavideoreleasedthismorning,PresidentObamaaddressesthepeopleofWestAfricaabouttheEbolaoutbreakthatiscurrentlyaffectingthecountriesofLiberia,SierraLeone,Guinea,andNigeria.
ThePresidentreiterate""sinthevideothat,alongwithourpartnersaroundtheworld,theUnitedStatesisworkingwiththesecountries'governmentstohelpstopthedisease.
Thefirststepinthisfight,however,isknowingthefacts--whichiswhythePresidentalsooutlines""thedetailsaboutthetransmissionandtreatmentofEbola"guessinfosys.
com.
85964INTXT"InavideorInavideoreleasedthismorningeleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismornin""gInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorning"guessinfosys.
com.
85964INTXT"InaviddeorInavideoreleasedthismorningeleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorni""ngInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorning"guessinfosys.
com.
85964INTXT"InaviddeofrInavideoreleasedthismorningeleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorn""ingInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorningInavideoreleasedthismorning"Maliciousrequestsforguessinfosys.
comcanbeobservedinthewildonanongoingbasis.
Theserequestsattempttouseopenresolversasintermediatevictimstoreflectattacktrafficbacktoatarget.
Forthemostpart,theusefulnessofthesemaliciousdomainsdropsoffafterafewdaysasserveradminsbegintoblockofftherequests.
Figure2:Digresultsforguessinfosys.
comTXTrecordsshowmultipleTXTstringsliftedfromWhiteHousepressreleases4akamai's[stateoftheinternet]/SecurityBulletin4418:11:32.
433099IPX.
X.
X.
X.
16484>X.
X.
X.
X.
53:37834+[1au]ANYguessinfosys.
com.
(45).
.
.
.
E.
.
Ib.
.
.
.
.
.
.
Ma.
.
.
.
Fx@d.
5.
5.
guessinfosys.
com.
1.
3MITIGATION/DNSreflectionandamplificationattacksmakeuseofthesametacticsusedbyothertypesofreflectioncampaigns,suchasSNMP,SSDPorCHARGEN.
Theprimaryimpacttothetargetedserviceistheoverallbandwidthgenerated.
DNSreflectionattackscanbemitigatedsuccessfullyatthenetworkedge.
Anaccesscontrollist(ACL)wouldsufficebutonlyincaseswhereavailablebandwidthexceedsattacksize.
SomeDNSserverswillattempttoretrytheresponseusingTCP,butwhentherequestissenttothetargethost,notransferwilloccurandtheattemptwillfail.
DDoScloud-basedprotectionservicessuchastheoneprovidedbyAkamaiTechnologiesarerecommended.
Status:PLXsertiscurrentlymonitoringongoingcampaigns.
Futureadvisoriesandupdateswillbeprovidedifwarranted.
Figure3:Aguessinfosys.
comrequestattemptingtoreflecttrafficoffacustomerDNSserverFigure4:TheOctober2014craftedDNSTXTamplificationattackslastedmorethanfivehoursduringeachattackandpeakedatmorethan15hoursonOctober245akamai's[stateoftheinternet]/SecurityBulletinTheProlexicSecurityEngineeringandResearchTeam(PLXsert)monitorsmaliciouscyberthreatsgloballyandanalyzestheseattacksusingproprietarytechniquesandequipment.
Throughresearch,digitalforensicsandpost-eventanalysis,PLXsertisabletobuildaglobalviewofsecuritythreats,vulnerabilitiesandtrends,whichissharedwithcustomersandthesecuritycommunity.
Byidentifyingthesourcesandassociatedattributesofindividualattacks,alongwithbestpracticestoidentifyandmitigatesecuritythreatsandvulnerabilities,PLXserthelpsorganizationsmakemoreinformed,proactivedecisions.
Akamaiisaleadingproviderofcloudservicesfordelivering,optimizingandsecuringonlinecontentandbusinessapplications.
Atthecoreofthecompany'ssolutionsistheAkamaiIntelligentPlatformprovidingextensivereach,coupledwithunmatchedreliability,security,visibilityandexpertise.
Akamairemovesthecomplexitiesofconnectingtheincreasinglymobileworld,supporting24/7consumerdemand,andenablingenterprisestosecurelyleveragethecloud.
TolearnmoreabouthowAkamaiisacceleratingthepaceofinnovationinahyperconnectedworld,pleasevisitwww.
akamai.
comorblogs.
akamai.
com,andfollow@AkamaionTwitter.
AkamaiisheadquarteredinCambridge,MassachusettsintheUnitedStateswithoperationsinmorethan40officesaroundtheworld.
OurservicesandrenownedcustomercareenablebusinessestoprovideanunparalleledInternetexperiencefortheircustomersworldwide.
Addresses,phonenumbersandcontactinformationforalllocationsarelistedonwww.
akamai.
com/locations2014AkamaiTechnologies,Inc.
AllRightsReserved.
Reproductioninwholeorinpartinanyformormediumwithoutexpresswrittenpermissionisprohibited.
AkamaiandtheAkamaiwavelogoareregisteredtrademarks.
Othertrademarkscontainedhereinarethepropertyoftheirrespectiveowners.
Akamaibelievesthattheinformationinthispublicationisaccurateasofitspublicationdate;suchinformationissubjecttochangewithoutnotice.
Published10/14.
5ABOUTPROLEXICSECURITYENGINEERING&RESEARCHTEAM(PLXSERT)/PLXsertmonitorsmaliciouscyberthreatsgloballyandanalyzestheseattacksusingproprietarytechniquesandequipment.
Throughresearch,digitalforensicsandpost-eventanalysis,PLXsertisabletobuildaglobalviewofsecuritythreats,vulnerabilitiesandtrends,whichissharedwithcustomersandthesecuritycommunity.
Byidentifyingthesourcesandassociatedattributesofindividualattacks,alongwithbestpracticestoidentifyandmitigatesecuritythreatsandvulnerabilities,PLXserthelpsorganizationsmakemoreinformed,proactivedecisions.
ABOUTAKAMAI/Akamaiistheleadingproviderofcloudservicesfordelivering,optimizingandsecuringonlinecontentandbusinessapplications.
AtthecoreoftheCompany'ssolutionsistheAkamaiIntelligentPlatformprovidingextensivereach,coupledwithunmatchedreliability,security,visibilityandexpertise.
Akamairemovesthecomplexitiesofconnectingtheincreasinglymobileworld,supporting24/7consumerdemand,andenablingenterprisestosecurelyleveragethecloud.
TolearnmoreabouthowAkamaiisacceleratingthepaceofinnovationinahyperconnectedworld,pleasevisitwww.
akamai.
comorblogs.
akamai.
com,andfollow@AkamaionTwitter.
vollcloud LLC首次推出6折促销,本次促销福利主要感恩与回馈广大用户对于我们的信任与支持,我们将继续稳步前行,为广大用户们提供更好的产品和服务,另外,本次促销码共限制使用30个,个人不限购,用完活动结束,同时所有vps产品支持3日内无条件退款和提供免费试用。需要了解更多产品可前往官网查看!vollcloud优惠码:VoLLcloud终生6折促销码:Y5C0V7R0YW商品名称CPU内存S...
Fiberia.io是个新站,跟ViridWeb.com同一家公司的,主要提供基于KVM架构的VPS主机,数据中心在荷兰Dronten。商家的主机价格不算贵,比如4GB内存套餐每月2.9美元起,采用SSD硬盘,1Gbps网络端口,提供IPv4+IPv6,支持PayPal付款,有7天退款承诺,感兴趣的可以试一试,年付有优惠但建议月付为宜。下面列出几款主机配置信息。CPU:1core内存:4GB硬盘:...
火数云怎么样?火数云主要提供数据中心基础服务、互联网业务解决方案,及专属服务器租用、云服务器、专属服务器托管、带宽租用等产品和服务。火数云提供洛阳、新乡、安徽、香港、美国等地骨干级机房优质资源,包括BGP国际多线网络,CN2点对点直连带宽以及国际顶尖品牌硬件。专注为个人开发者用户,中小型,大型企业用户提供一站式核心网络云端服务部署,促使用户云端部署化简为零,轻松快捷运用云计算!多年云计算领域服务经...
openerdns为你推荐
yw372:Com帮个忙 这个视频源地址怎么找http://video.kuaiji.com/congye/diansuanhua/372/3097servererror电脑连接路由登录提示server error:401 N/A,如何处理?wordpress模板wordpress后台默认模板管理在哪里?360和搜狗360搜索和搜狗搜索谁好谁流量大?为什么我在网上搜索到的数据有一定矛盾?做广告推广哪个好呢?企业建网站一般中小型企业建立网站需要多少费用?多大的空间?cisco2960思科2960如何划分vlan?360公司迁至天津奇虎360公司在哪?河南省全民健康信息平台建设指引(试行)刚刚网刚刚网上刷单被骗了5万多怎么办啊 报警有用吗12306.com12306身份信息待核验要多久?审核要多久
网站空间租用 个人注册域名 hawkhost winhost ssh帐号 全能主机 500m空间 免费mysql 怎么测试下载速度 135邮箱 稳定免费空间 申请网页 域名dns ebay注册 美国盐湖城 阿里云免费邮箱 论坛主机 永久免费空间 数据湾 葫芦机 更多