HomeSecurityPlex Media Servers Used for DDoS Attacks

Plex Media Servers Used for DDoS Attacks

As security firm Netscout reported , malicious actors have found a new way to use Plex Media servers to push unwanted traffic and enhance distributed denial-of-service (DDoS) attacks .

Plex Media

The company is warning owners of devices that shipped with Plex Media Server, a web application for Windows, Mac , and Linux that is typically used to stream video or audio and manage media assets.

The application can be installed on regular web servers or is typically included in network attached storage (NAS) systems, digital media players, or other types of media streaming IoT devices.

Netscout says that when a server/device running a Plex Media Server application is started and connected to a network, it will initiate a local scan for other compatible devices via the Simple Service Discovery Protocol (SSDP).

The issue occurs when a Plex Media Server discovers a local router that has SSDP support enabled. When this happens, Plex Media Server will add a NAT forwarding rule to the router, exposing the Plex Media SSDP (PMSSDP) service directly to the Internet over UDP port 32414.

Since the SSDP protocol has been known for years to be a perfect vehicle for amplifying DDoS attacks, this makes Plex Media servers an attractive and unexploited source of DDoS bots for DDoS-for-hire.

Ddos

Netscout says that attackers first scan the Internet for devices that have this port enabled and then abuse them to boost the number of requests they send to a DDoS attack victim.

According to Netscout, the amplification factor is approximately 4.68, with a Plex Media server amplifying incoming PMSSDP packets from 52 bytes to up to 281 bytes, before sending the packet to the victim.

The security firm said it discovered 27,000 Plex Media servers exposed to the internet that could be exploited for DDoS attacks. Additionally, some of the servers had already been exploited.

According to Netscout, previous PMSSDP attacks have reached around 2-3 Gbps, but the servers could be combined with other actors for much larger attacks.

This is the company's second warning about a new DDoS attack vector discovered online this year. In January, the company warned that Windows Remote Desktop Protocol (RDP) were also being abused for DDoS attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS