In addition to Weibo, there is also WeChat
Please pay attention
WeChat public account
Shulou
2025-04-11 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Network Security >
Share
Shulou(Shulou.com)05/31 Report--
This article introduces you how to achieve nuclear bomb-level DDoS attacks in Memcache-DRDos, the content is very detailed, interested friends can refer to, hope to be helpful to you.
We've all heard of DOS attacks, DDOS attacks, so what is DRDos attacks? R means reflection.
Here we will practice the DDoS attack based on Memcache as the DRDoS reflection amplifier.
Photo Source: thehackernews
Experimental environment:
1. Memcache enables udp snooping
2. Memcache does not enable authentication
Install Memcache first
Install memcached
Start the memcached service. The default port of the memcached service is 11211, which can be customized. Set it to 6666 here.
Start the service
The memcache module of python is needed here. Install it first and install it with pip.
Install python-memcached
First turn on debugging of memcache, then insert some data
Insert Data
Let's take a look at the gap between the generated data and the returned data, and build the request to send it out.
Occurrence data
Server side
You can see that 16 bytes are sent out, but the bytes returned are 1937 bytes
1937T 16x 121.0625
Isn't it big enough? then have a big one.
Occurrence data
Server side
Send 58 bytes and receive 543224 bytes
5432240.58mm 9365.93 times
This one is so powerful, if there are more, the consequences can be imagined.
There are hundreds of thousands of Memcache open in the world.
Repair recommendations:
1. Disable UDP
2. Prohibit access to the public network
3. Enable authorized access
On how to achieve nuclear bomb-level DDoS attacks in Memcache-DRDos to share here, I hope the above content can be of some help to you, can learn more knowledge. If you think the article is good, you can share it for more people to see.
Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.
Views: 0
*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.
Continue with the installation of the previous hadoop.First, install zookooper1. Decompress zookoope
"Every 5-10 years, there's a rare product, a really special, very unusual product that's the most un
© 2024 shulou.com SLNews company. All rights reserved.