The group responsible for the security of the Akamai content delivery network has identified an additional attack vector on the cups-browsed process, aside from its role as one of the links in an exploit that leads to code execution on the system. By sending requests to the cups-browsed process, which accepts connections on port 631 without restrictions, it is possible to send data to another host, exceeding the original request size by up to 600 times. In comparison, the amplification ratio for memcached can reach 10,000 to 50,000 times, NTP can reach 556 times, DNS can reach 28-54 times, RIPv2 can reach 21 times, and SNMPv2 can reach 6 times.
This feature allows systems with cups-browsed to be used as traffic amplifiers during DDoS attacks. The amplification attack method is based on directing requests from the computers participating in the DDoS attack not directly to the victim system, but through an intermediate traffic amplifier. During a network scan, more than 198,000 vulnerable systems with CUPS were found, of which 34% (58,000 systems) were suitable for traffic amplification in a DDoS attack.
Unlike traffic amplification methods that require sending UDP packets with a spoofed return address of the victim, the use of cups-browsed allows for bypassing spoofing. The cups-browsed service has a built-in capability to load a PPD file from any location in response to an unauthorized external request, during which the client sends a URL, and cups-browsed attempts to load the PPD file from the specified server. server When sending a request to load a PPD file in cups-browsed, it is possible to attach additional padding to the 'IPP URI' value, which can reach up to 989 bytes. In this case, the 'IPP URI' value is duplicated in the HTTP header and again within the body of the POST request, while the requests are cyclically repeated after failed attempts to load and receiving a
404 error code. proxy server 404 error code.
On 62% (35,900) of checked systems, cups-browsed sent at least 10 TCP/IPP/HTTP requests to the attacked system in response to one originating UDP request. On average, for 58,000 vulnerable systems, the number of retries amounted to 45. In the optimal scenario, sending a single 30-byte originating request with 45 retries would result in sending 18,000 bytes of data to the target system, meaning there would be a traffic amplification of 600 times. In the worst-case scenario, the amplification factor is 108.
Additionally, it should be noted that Cloudflare reflected a record DDoS attack, during which a flow of 3.8 terabits per second (2.14 billion packets per second) was directed at the victim's system. It is reported that the attack was organized using a large number of compromised home routers from Asus and Mikrotik, as well as DVR devices and web servers, which were hacked among other things using relatively recent vulnerabilities.
Source: opennet.ru
