sb-nz logo
Story image

Updated: Cyber attackers flood memcached servers with amplified DDoS attacks

02 Mar 2018

Misconfigured memcached servers on internet data center (IDC) networks are being increasingly abused to conduct amplification attacks around the globe, with many vulnerable servers across Asia Pacific, Europe and North America.

Security teams at Cloudflare, Qihoo and Arbor Networks picked up the increase in attacks using the memcached protocol, which are originating from UDDP port 11211.

On March 2, Akamai detected a 1.3Tbps DDoS attack against one of its customers as a result of memcached reflections - the largest the company has ever seen.

Arbor Networks defines memcached as an in-memory database caching system often deployed in IDC, cloud and Infrastructure-as-a-Service networks to improve performance of database-driven websites and other internet services.

Ideally memcached should not be exposed to public internet but there are many deployments that leave the systems open and with the default insecure configuration.

The attacks use the misconfigured servers to launch high-volume UDP reflection-amplification attacks. It does this by spoofing an IP and sending thousands of requests to a server. That host server cannot handle the requests and the process often crashes the server itself.

Those attacks are getting bigger, according to Arbor Networks, which says there has been in increased in memcached attacks, some reaching as much as 500gb/sec and larger.

“Amplification attacks are effective, because often the response packets are much larger than the request packets. A carefully prepared technique allows an attacker with limited IP spoofing capacity (such as 1Gbps) to launch very large attacks (reaching 100s Gbps) "amplifying" the attacker's bandwidth,” Cloudflare explains further.

In some cases, a request of just 15 bytes triggered a response of 750kB – an amplification of 51,000 times.

Cloudflare has registered 260Gbps of inbound UDP memcached traffic, a figure the company describes as a ‘massive’ amplification vector.

Arbor believes that while memcached attacks may have been the work of skilled hackers in the past, they have now been weaponised and made available through the use of DDoS for hire botnets so attackers of all skill levels can now take advantage.

“Due to the nature of both the memcached service/protocol implementation as well as the prevalence and high bandwidth typically available to memcached reflectors/amplifiers, it is critical that network operators take proactive measures to ensure they are prepared to detect, classify, traceback, and mitigate these attacks, as well as ensure that any memcached installations on their networks and/or networks of their end-customers cannot be exploited as reflectors/amplifiers,” Arbor explains.

Cloudflare warns developers to stop using UDP. If there is a need for it, developers should not enable UDP be default. System administrators should ensure memcached servers are firewalled from the internet.

Cloudflare is also calling on internet service providers to help track attackers by finding out where the queries came from.

Akamai says it is working with peers and industry partners to help organisations use Best Common Practices and memcached remediation to reduce the risk to the internet.

Story image
Video: 10 Minute IT Jams - Who is Vectra AI?
Today, Techday spoke with Vectra AI head of security engineering Chris Fisher, who discusses the company's key products and offerings, updates on its operations in the A/NZ region, and the latest improvements on its products.More
Story image
75% of IT execs 'worried' about being targeted in cyber-attack
A new report from ConnectWise has shed light on the widespread concern about cyber-attacks, with 91% of SMB executives considering a move to an MSP if it provided the 'right' solution.More
Story image
Exabeam and Code42 partner up to launch insider threat solution
The solution will give customers a fuller picture of their environment, and will leverage automated incident response to obstruct insider threat before data loss occurs.More
Story image
Metallic adds data management and GDPR compliance
Now GDPR compliant, additions to the portfolio include eDiscovery features and support for Microsoft Hyper-V and Azure Blob and File storage.More
Link image
Webinar: Best practices for keeping your video chats secure
Video collaboration providers nowadays operate exclusively on a multi-tenant, public cloud - and security and privacy concerns have come into the spotlight. Here's how to secure your communications.More
Story image
Check Point acquires Odo Security to bolster remote security offering
The deal will integrate Odo’s remote access software with Check Point’s Inifinity architecture, bolstering the latter company’s remote security capabilities in a time where working and learning from home has become the norm, and looks to largely remain that way in the near future.More