Black Nurse attack is a new-threat emerging on it’s horizon, it can be launched from a single laptop which is capable of bringing server/firewalls to their knees.
ICMP is an very commonly used protocol to identify live hosts, It is used by network devices like switches, Routers for sending error messages and operational information’s, for instance service is not available OR the host/server is reachable.You find the most detailed and types of ICMP code’s here.
Most ICMP attacks based on Type 8 Code 0 also called ping flood attack. Blacknurse is based on ICMP with Type 3 Code 3 packets.We know that when a user has allowed ICMP Type 3 Code 3 to outside interfaces, the BlackNurse attack becomes highly effective even at low bandwidth.
This attack will be more effective even with the Low bandwidth(15-18Mbit/s). When the attack in progress the users from the LAN network will not able to send/receive over the Internet. All the firewalls/router will recover will recover once the attack stops.
Different firewalls would have different implementation for handling this type of attack,this even applied to customers with large internet uplinks and large enterprise firewalls in place.
You can implement the test with WAN area of the firewall and at the time of attack try to surf some pages in and out of Internet.The tests also showed that a single attacking machine running hping3 could, on its own, produce enough ICMP type 3 code 3 packets to consume pretty much all the firewall’s resources.
hping3 –icmp -C 3 -K 3 -i u200 [target]
hping3 –icmp -C 3 -K 3 –flood [target]
Here -i u200 orders hping3 to send packets every 200microseconds and few minutes later they upped the packet rate, by using the “–flood” argument.
Based on the research, this vulnerability or misconfiguration of some firewalls is easy to misuse.Impact can be high for those that allow ICMP to the firewall’s outside interface. Having high bandwidth is no guarantee that this DOS/DDOS attack will not work.Impact can be different from network to network depends on what the network is covering. It’s recommend to test your network.
Recent research has revealed that a Russian advanced persistent threat (APT) group, tracked as "GruesomeLarch"…
Microsoft's Digital Crimes Unit (DCU) has disrupted a significant phishing-as-a-service (PhaaS) operation run by Egypt-based…
The Russian threat group TAG-110, linked to BlueDelta (APT28), is actively targeting organizations in Central…
Earth Kasha, a threat actor linked to APT10, has expanded its targeting scope to India,…
Raspberry Robin, a stealthy malware discovered in 2021, leverages advanced obfuscation techniques to evade detection…
Critical infrastructure, the lifeblood of modern society, is under increasing threat as a new report…
View Comments