Akamai's content delivery network security group has identified an additional attack vector on the cups-browsed process, beyond its use as one of the links in an exploit that leads to code execution on the system. By sending requests to the cups-browsed process, which accepts connections on port 631 without restrictions, an attacker can send data to another host, potentially exceeding the original request size by up to 600 times. In comparison, the amplification factor for memcached can reach 10,000 to 50,000 times, NTP â 556 times, DNS â 28 to 54 times, RIPv2 â 21 times, and SNMPv2 â 6 times.
This feature allows systems with cups-browsed to be used as traffic amplifiers during DDoS attacks. The amplification attack method is based on the fact that requests from computers participating in DDoS attacks are routed not directly to the victim's system, but through an intermediate traffic amplifier. During network scanning, more than 198,000 vulnerable systems with CUPS were identified, of which 34% (58,000 systems) were found to be suitable for traffic amplification in a DDoS attack.
Unlike traffic amplification methods that require sending UDP packets with a spoofed return address of the victim, using cups-browsed allows this to be done without spoofing. The cups-browsed service has a native ability to load a PPD file from an arbitrary serverilt in response to an unauthorized external request, during which the client transmits a URL, and cups-browsed attempts to load the PPD file from the specified server.
When sending a request to load a PPD file in cups-browsed, it is possible to attach additional padding to the "IPP URI" value, which can reach up to 989 bytes. In this case, the "IPP URI" value is duplicated in the initiated cups-browsed request â once in the HTTP header and a second time within the body of the POST request, and the requests are cyclically repeated after unsuccessful attempts to load and receiving serverilt a 404 error code.
62%-l (35,900) kontrollitud sĂŒsteemist saatis cups-browsed vĂ€hemalt 10 TCP/IPP/HTTP pĂ€ringut rĂŒnnatavale sĂŒsteemile ĂŒhe algse UDP pĂ€ringu vastusena. Keskmiselt 58,000 haavatava sĂŒsteemi puhul oli uute pĂ€ringute arv 45. Optimaalses stsenaariumis, kui saadetakse ĂŒks 30-baidine algne pĂ€ring 45 korduvkatsega, saadataks sihtsĂŒsteemile 18,000 baidi andmeid, mis tĂ€hendab, et liiklus tugevneb 600 korda. Halvimal juhul on tugevus 108 korda.
Lisaks vĂ”ib mĂ€rkida, et Cloudflare'i poolt peegeldati rekordiline DDoS-rĂŒnnak, mille kĂ€igus suunati ohvrisse 3.8 terabitit sekundis (2.14 miljardit paketti sekundis). RĂŒnnak oli korraldatud suure hulga kompromiteeritud koduteede ruuterite Asus ja Mikrotik, samuti DVR-seadmete ja veebiserverite abil, mille nĂ”rkusest kasutas Ă€ra suhteliselt uusi haavatavusi.
Allikas: opennet.ru
