HomeSecurityNew 'Loop DoS' attack affects hundreds of thousands of systems

New 'Loop DoS' attack affects hundreds of thousands of systems

A new denial-of-service (DoS) attack, known as Loop DoS, has been found to target application-layer protocols based on the User Datagram Protocol (UDP), potentially putting hundreds of thousands of hosts at risk.

See also: Cisco patches critical vulnerabilities in IOS XR software

Loop DoS attack

Loop DoS attacks combine “ servers of these protocols in such a way that they communicate with each other endlessly ,” said researchers from the CISPA Helmholtz-Center for Information Security.

UDP, by design, is a connectionless protocol that does not validate source IP addresses, which makes it vulnerable to IP spoofing.

So, when attackers create many UDP packets that include the victim's IP address, the server responds to the victim (instead of the threat actor), creating a reflexive denial of service (DoS) attack.

See also: D-Link WiFi: Vulnerable to command injection attacks

The latest study has shown that some UDP protocol implementations, such as DNS, NTP, TFTP, Active Users, Daytime, Echo, Chargen, QOTD, and Time, can be used as weapons to create a self-perpetuating Loop DoS attack.

Simply put, when two application servers are running a vulnerable version of the protocol, a threat actor can initiate communication with the first server, spoofing the address of the second server, causing the first server to respond to the victim (i.e., the second server) with an error message.

The victim will then exhibit similar behavior, sending an error message back to the first server, effectively exhausting their resources and rendering services .

New 'Loop DoS' attack affects hundreds of thousands of systems

According to CISPA, approximately 300,000 hosts and their networks can be abused to conduct Loop DoS attacks.

Although there is currently no evidence that the attack has been actively used, the researchers warned that the exploit is simple and that many products from Broadcom, Cisco, Honeywell, Microsoft, MikroTik, and Zyxel are affected.

See also: SonicWall: Thousands of firewalls vulnerable to DoS and RCE attacks

What are the techniques for protecting against DoS attacks?

One of the most effective ways to protect against DoS attacks, such as Loop DoS, is to use an intrusion detection and prevention system (IDS/IPS). These systems monitor network traffic for unusual patterns or behaviors that may indicate a DoS attack. Using a DoS attack management system (DOSM) can also help. Implementing a consumption policy response system can also be useful. This means that network resources are distributed in such a way that no single user can take up all the bandwidth or processing power. Finally, using an authentication system can help protect against DoS attacks.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS