HomeinetDRDOS attacks via BitTorrent

DRDOS attacks via BitTorrent

DRDOS (Distributed Reflective Denial of Service). Mr. Florian Adamsky from the University of London published a research paper in which he details the family of protocols used by BitTorrent clients that can be abused to carry out DRDOS attacks.

DRDOS hacker

Most of us have a basic idea of ​​what a DDOS attack is, but a DRDOS attack is a little different.

While in a DDOS attack a hacker controls a series of zombie computers that create excessive traffic to a target, causing the target to become "clogged" and no longer accessible by third parties, in a DRDOS, the attacker creates traffic on legitimate network equipment (called a mirror), from which he then relays the traffic to the victim.

The traffic sent to the mirror is forged and contains the victim's IP address as the source of the packet, and when the mirror (or reflector if you like) follows the general rules of Internet protocols and tries to establish a connection, it does so with the victim's IP, instead of the attacker's.

Also beyond sending traffic to a mirror, attackers have devised ways to use the mirror to amplify traffic.

The protocols commonly used in DRDOS attacks are TCP, DNS, and NTP. Mr. Adamsky's research paper shows how many protocols from the BitTorrent family can be used in DRDOS attacks, even with the ability to boost traffic

According to Adamsky, the affected BitTorrent protocols are: UTP (Micro Transport Protocol), DHT (Distributed Hash Table), and MSE (Message Stream Encryption). These are the protocols used in the BitTorrent, uTorrent, and Vuze applications.

Additionally, the BTSync synchronization protocol used with the BitTorrent Sync file sharing application is also vulnerable.

“Our experiments show that BitTorrent has a bandwidth amplification factor (BAF) of 50 times greater and in the case of BTSync it is up to 120 times greater,” said Florian Adamsky.

But the bad news doesn't stop there. In addition to boosting traffic, DRDOS attacks carried out via BitTorrent are detectable by regular firewalls due to "the range of dynamic ports and encryption during the handshake."

Mitigation services for this type of attack would likely require Deep Packet Inspection (DPI), a solution that is resource-intensive for most server infrastructures.

As TorrentFreak reports, BitTorrent has patched some of these issues in a recent beta release, while Vuze and uTorrent are still vulnerable.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS