Memcached DDOS attacks raise from nowhere and made some record-breaking DDoS attacks. GitHub Hit With a massive 1.35 Tbps DDoS Attack and within 5 days an American firm hit with a records breaking 1.7 Tbps DDoS Attack.
Two Proof of concepts for the Memcache DDOS attacks has been published online. The written in C language and the scripts utilize a list of 17,000 vulnerable Memcached servers to launch a DDoS attack.
The second one built in python and it inherits Shodan API to find the list of vulnerable Memcached servers.
The PoC published online made the attack even worst, it allows even a script kiddle to launch a high volume Memcached DDoS Attack.
But here is the good news “Security researchers from Corero Network Security identified a kill switch” which sends a command back to attacker server to suppress the DDoS exploitation. Based on this finding a DDOS Mitigation tool dubbed Memfixed released.
Josh Lospinoso published a memcachedump tool for dumping the cache contents of the exposed Memcached servers, and according to the dump reports the number of exposed vulnerable servers is decreasing slowly.
The attack was primarily concentrated in United States, China (including Hong Kong, China), South Korea, Brazil, France, Germany, the United Kingdom, Canada, and the Netherlands.
According to netlab analysis via ddosmon within 7 days 10k attack events and 7131 unique victim IP addresses were logged.
The Memcached DDOS attacks having some interesting targets
The regular big players such as qq,360, Google, Amazon.etc
The game industry such as rockstargames.com, minecraft.net, playstation.net
The porn sites such as pornhub.com, homepornbay.com
The security industry such Avast.com, kaspersky-labs.com, 360.cn
The political related websites such as nra.org, nrafoundation.org, nracarryguard.com, epochtimes.com
And the guy who always gets to see the newest DDoS attack: krebsonsecurity.com 🙂
With the growing importance of security compliance for startups, more companies are seeking to achieve…
Two critical security flaws in IBM Storage Virtualize products could enable attackers to bypass authentication…
A newly disclosed path traversal vulnerability (CVE-2024-4885) in Progress Software’s WhatsUp Gold network monitoring solution…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on March 3,…
Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES) encryption…
Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in cyber…