TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

TP240PhoneHome Reflection/Amplification DDoS Attack Vector

186 点作者 leohonexus大约 3 年前

10 条评论

api大约 3 年前
I&#x27;m really concerned that DDOS attacks are going to lead to the death of the open Internet and its balkanization and isolation behind walled gardens. If you look at where Cloudflare and some of the big clouds are going with their private networks, private backplanes, and &quot;secure your traffic by putting it all over our network&quot; zero trust plans it seems to be going that way.<p>If open peering and the open Internet are to survive I think serious work needs to be done to fight DDOS attacks. It needs to be an effort analogous to the &quot;war on spam&quot; in the late 1990s &#x2F; early 2000s. Unfortunately that war was sort of lost; e-mail is in practice barely an open protocol anymore and almost all e-mail is handled by a few giant companies that can leverage big data to filter spam. If you try to DIY a mail server you&#x27;ll be simultaneously hit by spam and have to constantly fight mistaken filtration by larger e-mail providers who tend to distrust small mail servers by default.<p>If the open Internet succumbs to DDOS &quot;spam,&quot; we will lose something really huge and important. It would be the ultimate casualty of what so far has been almost a law (with very few exceptions): all open systems are destroyed by abuse if they become sufficiently popular.<p>We also can&#x27;t just leave it to the free market because the only solution the market will likely come up with is walled gardens. It&#x27;s the easiest to engineer solution and the easiest to monetize.
评论 #30614525 未加载
评论 #30617236 未加载
评论 #30614707 未加载
jgrahamc大约 3 年前
220 billion percent! And other scary numbers!<p>Coordinated disclosure: <a href="https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;cve-2022-26143&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;cve-2022-26143&#x2F;</a><p>Info for Cloudflare customers: <a href="https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;cve-2022-26143-amplification-attack&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;cve-2022-26143-amplification-att...</a>
beeforpork大约 3 年前
On the bright side, we&#x27;re lucky they did not use a 64-bit int.
_joel大约 3 年前
Now that&#x27;s a ping of death!
StartupMemoryLn大约 3 年前
See: <a href="https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;cve-2022-26143&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;cve-2022-26143&#x2F;</a><p>or: <a href="http:&#x2F;&#x2F;archive.today&#x2F;TX3t7" rel="nofollow">http:&#x2F;&#x2F;archive.today&#x2F;TX3t7</a>
dschuetz大约 3 年前
We&#x27;re approaching the limits here, I think.
评论 #30614147 未加载
评论 #30618064 未加载
tgsovlerkhgsel大约 3 年前
Seems like a potential mitigation would be to send the affected devices a small stream of packets that tell them to generate traffic for e.g. an invalid IP, local IP, or their own public IP.<p>Once that hits, the device would then be sending the traffic harmlessly to &#x2F;dev&#x2F;null for the next 14 hours and be unavailable for attacks.<p>Not sure about the legal and ethical implications of that.
londons_explore大约 3 年前
Tracking down these systems is easy, so these issues can normally be solved pretty easily.<p>Thats because typically any amplification vector doesn&#x27;t allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.
评论 #30614215 未加载
评论 #30615610 未加载
评论 #30614307 未加载
评论 #30617532 未加载
评论 #30614201 未加载
operator1大约 3 年前
Does anyone have any data on what networks or organizations were on the receiving side of these attacks?
frays大约 3 年前
Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, &quot;Yeah, that&#x27;s just how it goes.&quot;<p>Isn&#x27;t a primary responsibility of government to protect its citizens and businesses from other states&#x27; militaries?
评论 #30614802 未加载
评论 #30614221 未加载
评论 #30614297 未加载
评论 #30614669 未加载
评论 #30614246 未加载
评论 #30616709 未加载
评论 #30614405 未加载
评论 #30615079 未加载
评论 #30615051 未加载
评论 #30614910 未加载
评论 #30614755 未加载
评论 #30614336 未加载
评论 #30614574 未加载
评论 #30614205 未加载
评论 #30618978 未加载
评论 #30614220 未加载
评论 #30615249 未加载
评论 #30615379 未加载