Article 5DSW7 DDoSers are abusing the Plex Media Server to make attacks more potent

DDoSers are abusing the Plex Media Server to make attacks more potent

by
Dan Goodin
from Ars Technica - All content on (#5DSW7)
evil-packet-800x480.jpg

Enlarge (credit: Getty Images)

Distributed denial-of-service attackers have seized on a new vector for amplifying the junk traffic they lob at targets to take them offline: end users or networks using the Plex Media Server.

DDoS amplification is a technique that leverages the resources of an intermediary to increase the firepower of attacks. Rather than sending data directly to the server being targeted, machines participating in an attack first send the data to a third party in the form of a request for a certain service. The third party then responds with a much larger payload to the site the attackers want to take down.

So-called amplification attacks work by sending the third parties requests that are manipulated so they appear to have come from the target. When the third parties respond, the replies go to the target rather than the attacker device that sent the request. One of the most powerful amplifiers used in the past was the memcached database caching system, which can magnify payloads by a factor of 51,000. Other amplifiers include misconfigured DNS servers and the Network Time Protocol, to name only three.

Read 8 remaining paragraphs | Comments

index?i=a924-yUGJPE:H6aNhXIqfOk:V_sGLiPB index?i=a924-yUGJPE:H6aNhXIqfOk:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments