The Insidexpress
  • Business
  • Lifestyle
    • Fashion
    • Beauty
    • Home Decor
    • Home
    • Interior Design
    • Foods & Culinary
    • Dating & Relationships
    • Health
    • Pets & Animals
    • Spirituality
    • Sports & Athletics
    • Travel
  • Entertainment
    • Celebrities
    • Gaming
    • Movies
    • Music
    • TV
  • Financial
    • Loans
    • Insurance
    • Stocks
  • Industrial
    • Auto & Motor
    • Career
    • Education
    • CBD
    • Construction
    • Real Estate
    • eCommerce
    • Legal
    • Essay Writing
    • Gambling
    • Vaping
  • Technology
    • Digital Marketing
    • SEO
    • Cryptocurrency
    • Software
    • Metaverse
    • NFT
    • Web Design
    • WordPress
  • News
    • Basketball
    • Golf
    • Horse Racing
The Insidexpress is a centralized magazine for Lifestyle, Fashion, Beauty, DIY, Interior Design, Health, Relationships, Travel, HowTo & more.
  • Business
  • Lifestyle
    • Fashion
    • Beauty
    • Home Decor
    • Home
    • Interior Design
    • Foods & Culinary
    • Dating & Relationships
    • Health
    • Pets & Animals
    • Spirituality
    • Sports & Athletics
    • Travel
  • Entertainment
    • Celebrities
    • Gaming
    • Movies
    • Music
    • TV
  • Financial
    • Loans
    • Insurance
    • Stocks
  • Industrial
    • Auto & Motor
    • Career
    • Education
    • CBD
    • Construction
    • Real Estate
    • eCommerce
    • Legal
    • Essay Writing
    • Gambling
    • Vaping
  • Technology
    • Digital Marketing
    • SEO
    • Cryptocurrency
    • Software
    • Metaverse
    • NFT
    • Web Design
    • WordPress
  • News
    • Basketball
    • Golf
    • Horse Racing
The Insidexpress
  • Business
  • Lifestyle
    • Fashion
    • Beauty
    • Home Decor
    • Home
    • Interior Design
    • Foods & Culinary
    • Dating & Relationships
    • Health
    • Pets & Animals
    • Spirituality
    • Sports & Athletics
    • Travel
  • Entertainment
    • Celebrities
    • Gaming
    • Movies
    • Music
    • TV
  • Financial
    • Loans
    • Insurance
    • Stocks
  • Industrial
    • Auto & Motor
    • Career
    • Education
    • CBD
    • Construction
    • Real Estate
    • eCommerce
    • Legal
    • Essay Writing
    • Gambling
    • Vaping
  • Technology
    • Digital Marketing
    • SEO
    • Cryptocurrency
    • Software
    • Metaverse
    • NFT
    • Web Design
    • WordPress
  • News
    • Basketball
    • Golf
    • Horse Racing
  • Technology

Cybercriminals Leverage VPNs for DDoS Amplification

  • March 30, 2021
  • 4 minute read
Cybercriminals Leverage VPNs for DDoS Amplification
Total
1
Shares
0
0
1
0
0
0
0

When it comes to the serious problems that companies can face, having too many willing customers isn’t one that too many business owners lose sleep over. While companies want to match demand with supply, having a large number of prospective customers showing interest in your service is far from the worst challenge a business can face.

At least, that’s assuming that all of the would-be customers are genuine.

This is the basis for Distributed Denial of Service (DDoS) attacks, in which attackers bombard victims with copious quantities of fraudulent traffic with the goal of bringing down a particular service or website. Picture it like directing too much vehicular traffic down a residential street: at a certain point, it’s total gridlock and even legitimate traffic that belongs on the road is unable to reach its destination.

DDoS amplification attacks are a nasty variation on DDoS, whereby the attacker exploits the vulnerabilities that exist in domain name system (DNS) servers so as to turn what are initially small queries into much bigger ones. By utilizing assorted amplification techniques to flood targets with massive numbers of User Datagram Protocol (UDP) packets, attackers are able to circumvent even robust infrastructure to knock victims’ servers offline. 

To those without the necessary anti-DDoS protection, such attacks can be devastating in their effect.

Amplification attacks increase scale

In this kind of amplification attack, the attacker sends a DNS request for service with a source IP that’s spoofed to look like the address of the victim. This causes the DNS resolver, a server that’s designed to receive queries from web browsers and applications, to return a DNS response. When multiple fake queries are sent, resulting in multiple DNS resolvers replying at the same time, networks can become overloaded with DNS responses. This is what risks slowing down a website or service or even driving it offline altogether.

In an amplification attack, DNS request messages of around 60 bytes can be turned into a response message in excess of 4,000 bytes — meaning an amplification factor of approximately 70:1. As such, amplification can vastly increase the scale of a DDoS attack.

Recently there has been a trend of cybercriminals leveraging virtual private networks (VPNs) for DDoS amplification attacks. Under usual circumstances, VPNs offer privacy, security, and anonymity to computer users through the use of a private network connection via a public network connection. VPNs can be used, for example, to access restricted websites that are geographically blocked in one particular area. To cyberattackers, however, they also open up new opportunities for causing problems.

Exploiting VPNs for DDoS amplification

In February, a security researcher by the name of Phenomite discovered how the operators of botnets — strings of internet-connected devices, frequently used to amplify DDoS attacks — have been increasingly using VPN servers as part of their attacks. According to Phenomite, one recent attack involves pinging the UDP port 20811 on Powerhouse VPN servers with a single byte request, which is then greatly amplified. 

This attack vector has reportedly already been weaponized, with real-world attacks reaching as high as 22 gigabytes-per-second (Gbps) in their assault on targets. Furthermore, additional scans by Phenomite show that upwards of 1,500 Powerhouse servers leave the UDP port 20811 exposed. This, in turn, opens up the possibility of other similar attacks taking place until Powerhouse VPN provides a fix to the problem.

DDoS attacks can be exceedingly damaging to targets, and have brought down some major players, in addition to smaller businesses and other targets. Previous targets have included major banks, code repository Github, Sony, EA, Steam, and many others. Negative effects of DDoS attacks can include lost revenue due to unasked-for time offline, along with dented customer loyalty, and more.

Protecting against amplified DDoS attacks is essential. Some of the ways to mitigate the devastating effects of DNS amplification attacks include rate limiting, blocking specific DNS servers, or tightening up security for DNS servers. But these won’t stop attacks from taking place, and may have other damaging impacts such as hurting genuine DNS communication.

Protecting against attacks

Fortunately, the tools are there to help. Modern cybersecurity tools for anti-DDoS measures are able to scrub massive DDoS attacks, giving would-be targets the ability to handle even the biggest volumetric attack. They can also identify amplified traffic and block it, protecting systems from being victimized by such attacks. They are able to block this bad traffic effectively, while continuing to allow through genuine traffic. As a result, services do not suffer as a result of DDoS attacks in progress.

These kinds of cyberattacks are not going away any time soon. The damage they can cause, coupled with the increasingly low barrier to entry when it comes to launching them, makes them irresistible to cyber attackers wanting to cause maximum damage. But by deploying the right tools, you can comprehensively safeguard against them. Employing these countermeasures proactively also means not having to wait on bug fixes that may not arrive in a timely fashion. 

Getting the right tools and strategy in place is one of the best cybersecurity moves any business or organization can make today.



The Insidexpress is now on Telegram and Google News. Join us on Telegram and Google News, and stay updated.
Total
1
Shares
Share 0
Tweet 0
Pin it 1
Share 0
Share 0
Share 0
Share 0
Related Topics
  • Business
  • cyber crime
  • ddos
  • DNS
Clair Iden

You May Also Like
View Article
  • 5 min
  • Technology

“ChatGPT discusses Impostor Syndrome in The Atlantic article”

  • March 30, 2023
View Article
  • 5 min
  • Technology

“Benefits of Choosing an ERP System for SEO”

  • March 30, 2023
View Article
  • 3 min
  • Technology

AI Critics Call for 6-Month Pause in Development Due to Fear of Losing Control

  • March 30, 2023
View Article
  • 7 min
  • Technology

Vintage Handbags Make a Comeback – The Atlantic

  • March 30, 2023
View Article
  • 5 min
  • Technology

“Startup Banking: Factors to Consider When Choosing a Bank”

  • March 29, 2023
View Article
  • 2 min
  • Technology

IBM File Exchange Bug Exploited by Ransomware Criminals with High Severity Score

  • March 29, 2023
View Article
  • 5 min
  • Technology

“Others also fell for the fake pope coat”

  • March 29, 2023
View Article
  • 5 min
  • Technology

“Business Travel: Impact, Benefits and Growth”

  • March 28, 2023

Leave a Reply Cancel reply

You must be logged in to post a comment.

Top Web Hosting

  1. Siteground
  2. Bluehost
  3. Namecheap
  4. Dreamhost
  5. Cloudways
  6. InterServer

Top Website Builders

  1. Wix
  2. Ucraft
  3. Strikingly
  4. Site123
  5. Webnode

Top SEO Tools

  1. SEMrush

Top Marketing Tools

  1. ActiveCampaign
  2. Aweber
  3. GetResponse
  4. Moosend
  5. Pabbly
  6. Fiverr
  7. ClickFunnels
Featured Articles
  • Play’s Impact on Business Culture: The Power of Fun and Games
    • 2 min
  • “Reclaiming Control: A Guide to Mastering Technology”
    • 2 min
  • Boost Easter Sales and Clients with SEO
    • 5 min
About Insidexpress

The Insidexpress is a centralized magazine for Business, Lifestyle, Fashion, Beauty, Entertainment, Culture, Living, Travel, Health, How-To, Technology, World News & more.

Things you might like
  • Although the owner of gambling sites is not on gamstop UK www.newonline-casinos.co.uk, his sites are successful and attract players. They have many slot machines and live sections; you can enjoy bonuses, especially free spins for new and popular slot online
  • List of non uk casinos accepting uk players newukcasino.uk
  • Best bonuses at european casinos that accept uk players with big wins
  • Visit Best CSGO Gambling to gather the latest gambling guides.
  • We have the best-reviewed crypto casinos at CryptoCasinos.com
Recent Posts
  • “Mastering the Long Game of Acting” 1
    “Mastering the Long Game of Acting”
    • 31.03.23
    • 8 min
  • LFO Singer Brizz Dead: Confirmed by Bandmate 2
    LFO Singer Brizz Dead: Confirmed by Bandmate
    • 31.03.23
    • 3 min
  • Play’s Impact on Business Culture: The Power of Fun and Games
    • 31.03.23
    • 2 min
  • “Veteran Players of Resident Evil 4 Mislead Newbies into Killing Leon”
    • 31.03.23
    • 2 min
The Insidexpress
  • Home
  • Contact Us

Input your search keywords and press Enter.

Go to mobile version