HomeSecurityCUPS vulnerability can be used in DDoS attacks

CUPS vulnerability can be used in DDoS attacks

A recently disclosed vulnerability in the open-source printing system Common Unix Printing System (CUPS) can be exploited by hackers to launch DDoS attacks, with a amplification factor of 600x.

See also: Variant of XWorm Delivered via Windows Script File

CUPS DDoS vulnerability

Distributed Denial of Service (DDoS) attacks are one of the most common forms of cyberattacks today. During a DDoS attack, a large number of computers, usually infected with malware, are used to flood a network or server with an unusually high number of requests. The goal of such an attack is to overload the target's resources, making it impossible for legitimate users to access it . This can create significant disruptions, delays, and even complete shutdowns of an organization's services, causing significant revenue and reputational losses.

As Akamai security researchers discovered , a security flaw CVE-2024-47176 in the cups-browsed daemon, which can be combined with three other flaws to achieve remote code execution on Unix-like systems via a single UDP packet, can also be exploited to amplify DDoS attacks.

The vulnerability is triggered when an attacker sends a specially crafted packet, tricking a CUPS server into treating a target as a printer to be added.

Each packet sent to vulnerable CUPS servers prompts them to generate larger IPP/HTTP aimed at the device. This impacts both the target and the CUPS server, consuming bandwidth and CPU resources.

See also: GorillaBot emerged as the "king" of DDoS attacks

To launch a DDoS attack, a malicious actor only needs to send a single packet to an exposed and vulnerable CUPS service. Akamai researchers estimate that approximately 58,000 servers, out of the 198,000 exposed devices, could be recruited for DDoS attacks.

CUPS vulnerability can be used in DDoS attacks

Additionally, hundreds of vulnerable devices experienced an "infinite loop" of requests, with some CUPS servers sending repeated requests after receiving an initial probe, and some servers entering an endless loop in response to certain HTTP/404 errors.

Many of these vulnerable machines were running outdated versions of CUPS (from 2007), which are easy targets for cybercriminals who can exploit them to create botnets via the RCE chain or use them to amplify DDoS attacks.

This DDoS amplification attack also requires minimal resources and a short amount of time to execute. Akamai warns that a hacker could easily take control of any exposed CUPS service on the Internet within seconds.

Administrators are advised to deploy CVE-2024-47176 patches or disable the running of the cups browsing service to block potential attacks to mitigate the risk of their servers being added to a botnet or used in DDoS attacks.

See also: DDoS attacks on government services are increasing

As Cloudflare revealed this week, its DDoS defenses had to protect customers from a wave of hyper-volume L3/4 DDoS attacks that reached 3.8 terabits per second (Tbps), the largest such attack ever recorded.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS