• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

A 1.3 Tbps DDoS attack courtesy of Memcached Servers

March 2, 2018Simeon Georgiev

The previous record for the largest DDoS attack was obliterated on Wednesday. It all started on a regular Wednesday night for a software development company. However, by night it was evident that something was looking to infiltrate its servers. It wasn’t long until hard statistics started coming in, which revealed some startling and surprising details. For example, at 1.3 Tbps this was the largest Distributed Denial-of-Server attack ever recorded.

The whole story was reported by GitHub first as it unfolded. It left many experts stunned and scrambling for solutions and answered as they saw history unfold. The ironic part is that the attack was carried out using the help of the Memcached servers that had been launched just a day earlier. While there had been reports that certain vulnerability exists in the servers, nobody expected such rapid exploitation. The attack’s central idea stems from the basic vulnerability that can be found in the UDP protocol implementation of the Memcached servers which usually amplify the incoming packets more than 50,000 times. This means that the vulnerable port on the victim’s side can receive the amplified packet sizes from the attackers’ side almost simultaneously. Memcache servers expose this particular port i.e. port 11211, even on default configuration.

And that’s not even the scariest part. As of right now, there are more than 93,000 Memcached servers that are connected online which sit completely vulnerable to DDoS attacks. An attack exactly of this nature is what seems to have been carried out on Wednesday. The positive news is a little relieving as thwarting such an attack is quite easy. All that a current or even a potential victim has to do is block any and all connections that are actively connected to port 11211 which is the DDoS primary reflection source.

The previous record for the heaviest DDoS attack was suffered by a Fresh hosting provider OVH in 2016. The magnitude of that particular attack was 1 Tbps and it was carried out with the first version of the Mirai IoT malware. Comparatively, it was a lot harder to contain as it had a greater number of varying packets which originated from multiple and random ports.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Twenty Three Thousand SSL certificates are to be revoked on March 1st, 2018. Next post New AdBlock feature allows Javascript caching

Related Articles

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

January 27, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

February 1, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

BitPaymer Ransomware Traced Back to Dridex Developers

February 1, 2018Simeon Georgiev
BitPaymer Ransomware Traced Back to Dridex Developers

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.