Akamai's content delivery network security group has identified an additional attack vector on the cups-browsed process, beyond its use as one of the links in an exploit that leads to code execution on the system. By sending requests to the cups-browsed process, which accepts connections on port 631 without restrictions, an attacker can send data to another host, potentially exceeding the original request size by up to 600 times. In comparison, the amplification factor for memcached can reach 10,000 to 50,000 times, NTP — 556 times, DNS — 28 to 54 times, RIPv2 — 21 times, and SNMPv2 — 6 times.
This feature allows systems with cups-browsed to be used as traffic amplifiers during DDoS attacks. The amplification attack method is based on the fact that requests from computers participating in DDoS attacks are routed not directly to the victim's system, but through an intermediate traffic amplifier. During network scanning, more than 198,000 vulnerable systems with CUPS were identified, of which 34% (58,000 systems) were found to be suitable for traffic amplification in a DDoS attack.
Unlike traffic amplification methods that require sending UDP packets with a spoofed return address of the victim, using cups-browsed allows this to be done without spoofing. The cups-browsed service has a native ability to load a PPD file from an arbitrary serverid in response to an unauthorized external request, during which the client transmits a URL, and cups-browsed attempts to load the PPD file from the specified server.
When sending a request to load a PPD file in cups-browsed, it is possible to attach additional padding to the "IPP URI" value, which can reach up to 989 bytes. In this case, the "IPP URI" value is duplicated in the initiated cups-browsed request — once in the HTTP header and a second time within the body of the POST request, and the requests are cyclically repeated after unsuccessful attempts to load and receiving serverilt a 404 error code.
62%-l (35,900) kontrollitud süsteemist saatis cups-browsed vähemalt 10 TCP/IPP/HTTP päringut rünnatavale süsteemile ühe algse UDP päringu vastusena. Keskmiselt 58,000 haavatava süsteemi puhul oli uute päringute arv 45. Optimaalses stsenaariumis, kui saadetakse üks 30-baidine algne päring 45 korduvkatsega, saadataks sihtsüsteemile 18,000 baidi andmeid, mis tähendab, et liiklus tugevneb 600 korda. Halvimal juhul on tugevus 108 korda.
Lisaks võib märkida, et Cloudflare'i poolt peegeldati rekordiline DDoS-rünnak, mille käigus suunati ohvrisse 3.8 terabitit sekundis (2.14 miljardit paketti sekundis). Rünnak oli korraldatud suure hulga kompromiteeritud koduteede ruuterite Asus ja Mikrotik, samuti DVR-seadmete ja veebiserverite abil, mille nõrkusest kasutas ära suhteliselt uusi haavatavusi.
Allikas: opennet.ru
