Logo

DOSarrest Vulnerability Testing and Optimization
Navigation
  • Home
  • non gamstop casino

CLDAP reflection attacks may be the next big DDoS technique

on April 17, 2017 |
DDoS DDoS Attack Specialist DDoS Defense DDoS Protection Specialist Defend Against DDoS Denial of Service Stop DDoS

Security researchers discovered a new reflection attack method using CLDAP that can be used to generate destructive but efficient DDoS campaigns.

DDoS campaigns have been growing to enormous sizes and a new method of abusing CLDAP for reflection attacks could allow malicious actors to generate large amounts of DDoS traffic using fewer devices.

Jose Arteaga and Wilber Majia, threat researchers for Akamai, identified attacks in the wild that used the Connection-less Lightweight Directory Access Protocol(CLDAP) to perform dangerous reflection attacks.
“Since October 2016, Akamai has detected and mitigated a total of 50 CLDAP reflection attacks. Of those 50 attack events, 33 were single vector attacks using CLDAP reflection exclusively,” Arteaga and Majia wrote. “While the gaming industry is typically the most targeted industry for [DDoS] attacks, observed CLDAP attacks have mostly been targeting the software and technology industry along with six other industries.”

The CLDAP reflection attack method was first discovered in October 2016 by Corero and at the time it was estimated to be capable of amplifying the initial response to 46 to 55 times the size, meaning far more efficient reflection attacks using fewer sources.

The largest attack recorded by Akamai using CLDAP reflection as the sole vector saw one payload of 52 bytes amplified to as much as 70 times the attack data payload (3,662 bytes) and a peak bandwidth of 24Gbps and 2 million packets per second.

This is much smaller than the peak bandwidths of more than 1Tbps seen with Mirai, but Jake Williams, founder of consulting firm Rendition InfoSec LLC in Augusta, Ga., said this amplification factor can allow “a user with low bandwidth [to] DDoS an organization with much higher bandwidth.”

“CLDAP, like DNS DDoS, is an amplification DDoS. The attacker has relatively limited bandwidth. By sending a small message to the server and spoofing the source, the server responds to the victim with a much larger response,” Williams told SearchSecurity. “You can only effectively spoof the source of connectionless protocols, so CLDAP is obviously at risk.”

Arteaga and Majia said enterprises could limit these kinds of reflection attacks fairly easily by blocking specific ports.

“Similarly to many other reflection and amplification attack vectors, this is one that would not be possible if proper ingress filtering was in place,” Arteaga and Majia wrote in a blog post. “Potential hosts are discovered using internet scans, and filtering User Datagram Protocol destination port 389, to eliminate the discovery of another potential host fueling attacks.”

Williams agreed that ingress filtering would help and noted that “CLDAP was officially retired from being on the IETF standards track in 2003” but enterprises using Active Directory need to be aware of the threat.

“Active Directory supports CLDAP and that’s probably the biggest reason you’ll see a CLDAP server exposed to the internet,” Williams said. “Another reason might be email directory services, though I suspect that is much less common.”

Source: http://searchsecurity.techtarget.com/news/450416890/CLDAP-reflection-attacks-may-be-the-next-big-DDoS-technique

Quality content

  • Casino Non Aams
  • Non Gamstop Casinos
  • Casinos Not On Gamstop
  • Casino Sites Not On Gamstop
  • Non Gamstop Casino
  • Casino Sites Not On Gamstop
  • Best Online Casinos
  • Non Gamstop Casino Sites UK
  • Casino Sites Not On Gamstop
  • Non Gamstop Casinos
  • Meilleur Casino En Ligne
  • UK Casino Not On Gamstop
  • Non Gamstop Casinos
  • UK Casinos Not On Gamstop
  • Casino Online Non Aams
  • Casino Online
  • Best Online Casino Sites UK
  • Non Gamstop Casino
  • Casino Sites Not On Gamstop
  • Slot Sites Uk
  • UK Casinos Not On Gamstop
  • Slots Not On Gamstop
  • Non Gamstop Casino UK
  • Migliori Casino Non Aams
  • Gambling Sites Not On Gamstop
  • Casino Online Non Aams
  • Casino Non Aams
  • Migliori Casino Non Aams
  • Casino En Ligne
  • Site De Paris Sportif Belgique
  • Casino En Ligne
  • Migliori Casino Online
  • Casino En Ligne
  • 仮想通貨 カジノ 入金不要ボーナス
  • Casino Online Bonus Senza Documenti
  • Site Casino En Ligne
  • Meilleur Site De Casino En Ligne
  • Migliori Casino Online Italia
  • Siti Scommesse Nuovi
  • Casinò Online Non Aams
Share this story:
  • tweet

Recent Posts

  • Link11 Discovers Record Number of DDoS Attacks in First Half of 2021

    July 15, 2021 - 0 Comment
  • A New Wave of DDoS Extortion Campaigns by Fancy Lazarus

    June 16, 2021 - 0 Comment
  • ‘Fancy Lazarus’ Cyberattackers Ramp up Ransom DDoS Efforts

    June 12, 2021 - 0 Comment
Comments are closed.

Keep updated with the latest DDoS Attacks

RSSSubscribe
  • Home
  • Latest News
  • Contact
  • Sitemap
  • Casnio Not On Gamstop
  • Foods Of England
  • Casino Not On Gamstop
  • Casino Sites Not On Gamstop
  • Casinos Not Affected By Gamstop
© Copyright 2013. All Rights Reserved. Web Development by: 6folds Marketing