• About
  • Privacy & Policy
  • Contact
Today Headline
  • HOME
  • NEWS
    • POLITICS
  • FINANCE
  • Video
  • ENTERPRISE
  • TECHNOLOGY
  • HEALTH
  • ENTERTAINMENT
  • LIFESTYLE
    • TRAVEL
  • AUTOMOTIVE
  • SPORTS
  • HOME
  • NEWS
    • POLITICS
  • FINANCE
  • Video
  • ENTERPRISE
  • TECHNOLOGY
  • HEALTH
  • ENTERTAINMENT
  • LIFESTYLE
    • TRAVEL
  • AUTOMOTIVE
  • SPORTS
No Result
View All Result
TodayHeadline
No Result
View All Result
Home Enterprise

Windows RDP servers are being abused to amplify DDoS attacks

January 22, 2021
in Enterprise
0
Windows RDP servers are being abused to amplify DDoS attacks
0
SHARES
7
VIEWS
Share on FacebookShare on Twitter


DDoS botnet globe map

Cybercrime gangs are abusing Windows Remote Desktop Protocol (RDP) systems to bounce and amplify junk traffic as part of DDoS attacks, security firm Netscout said in an alert on Tuesday.

Not all RDP servers can be abused, but only systems where RDP authentication is also enabled on UDP port 3389 on top of the standard TCP port 3389.

Netscout said that attackers can send malformed UDP packets to the UDP ports of RDP servers that will be reflected to the target of a DDoS attack, amplified in size, resulting in junk traffic hitting the target’s system.

This is what security researchers call a DDoS amplification factor, and it allows attackers with access to limited resources to launch large-scale DDoS attacks by amplifying junk traffic with the help of internet exposed systems.

In the case of RDP, Netscout said the amplification factor is 85.9, with the attackers sending a few bytes and generating “attack packets” that are “consistently 1,260 bytes in length.”

An 85.9 factor puts RDP in the top echelon of DDoS amplification vectors, with the likes of Jenkins servers (~100), DNS (up to 179), WS-Discovery (300-500), NTP (~550), and Memcached (~50,000).

RDP servers already abused for real-world attacks

But the bad news don’t end with the amplification factor. Netscout said that threat actors have also learned of this new vector, which is now being heavily abused.

“As is routinely the case with newer DDoS attack vectors, it appears that after an initial period of employment by advanced attackers with access to bespoke DDoS attack infrastructure, RDP reflection/amplification has been weaponized and added to the arsenals of so-called booter/stresser DDoS-for-hire services, placing it within the reach of the general attacker population,” researchers said.

Netscout is now asking system administrators who run RDP servers exposed on the internet to take systems offline, switch them to the equivalent TCP port, or put the RDP servers behind VPNs in order to limit who can interact with vulnerable systems.

Currently, Netscout said it is detecting more than 14,000 RDP servers exposed online and running on UDP port 3389.

Since December 2018, five new DDoS amplification sources have come to light. These include the Constrained Application Protocol (CoAP), the Web Services Dynamic Discovery (WS-DD) protocol, the Apple Remote Management Service (ARMS), Jenkins servers, and Citrix gateways.

According to the FBI, the first four have been abused in real-world attacks.



Source link

 
 
   
Previous Post

Argos PS5 restock coming next? Latest PlayStation 5 stock updates and rumours | Gaming | Entertainment

Next Post

7 Democratic senators call for ethics probe on Cruz and Hawley

Next Post
7 Democratic senators call for ethics probe on Cruz and Hawley

7 Democratic senators call for ethics probe on Cruz and Hawley

  • Trending
  • Comments
  • Latest

Woman who thought her kitchen tiles were grey makes horrifying discovery thanks to 89p paste

February 25, 2021

Lin Wood says Jeffrey Epstein still alive in bizarre conspiracy tweets

February 25, 2021
Notorious gang leader shot dead and 400 inmates escape during prison break

Notorious gang leader shot dead and 400 inmates escape during prison break

February 27, 2021

Is PayPal secure? Here’s what you need to know

February 25, 2021

Best Amazon Echo Deals February 2021

February 25, 2021
DevOps and agile for all: technology professionals need to lead the way in the post-Covid era ahead

DevOps and agile for all: technology professionals need to lead the way in the post-Covid era ahead

February 27, 2021
James Bond movies: Get paid $1000 to watch every 007 film before No Time To Die releases | Films | Entertainment

James Bond movies: Get paid $1000 to watch every 007 film before No Time To Die releases | Films | Entertainment

February 27, 2021

Lockdown savings? Put them in an Isa while you can | Isas

February 27, 2021
Every NFL team’s most likely future Hall of Famer: Tom Brady, Aaron Donald among 17 ‘locks’

Every NFL team’s most likely future Hall of Famer: Tom Brady, Aaron Donald among 17 ‘locks’

February 27, 2021

Storm Brings Hail and Lightning to Seattle

February 27, 2021

About Us

Todayheadline the independent news and topics discovery
A home-grown and independent news and topic aggregation . displays breaking news linking to news websites all around the world.

Follow Us

Latest News

DevOps and agile for all: technology professionals need to lead the way in the post-Covid era ahead

DevOps and agile for all: technology professionals need to lead the way in the post-Covid era ahead

February 27, 2021
James Bond movies: Get paid $1000 to watch every 007 film before No Time To Die releases | Films | Entertainment

James Bond movies: Get paid $1000 to watch every 007 film before No Time To Die releases | Films | Entertainment

February 27, 2021
DevOps and agile for all: technology professionals need to lead the way in the post-Covid era ahead

DevOps and agile for all: technology professionals need to lead the way in the post-Covid era ahead

February 27, 2021
James Bond movies: Get paid $1000 to watch every 007 film before No Time To Die releases | Films | Entertainment

James Bond movies: Get paid $1000 to watch every 007 film before No Time To Die releases | Films | Entertainment

February 27, 2021

Lockdown savings? Put them in an Isa while you can | Isas

February 27, 2021
  • About
  • Privacy & Policy
  • Contact

© 2019 All rights are reserved Todayheadline

No Result
View All Result
  • About Us
  • Contact Us
  • Cookie policy (EU)
  • Home
  • Privacy Policy
  • Video

© 2019 All rights are reserved Todayheadline