AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

Ó¦¶ÔUDP·´Éä·Å´ó¹¥»÷µÄÎåÖÖ³£Ó÷À»¤Ë¼Ð÷

2020-08-10

±¾Ô£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©·¢³öÖÒÑÔ£¬³Æ·¢Ã÷¼¸ÖÖеÄÍøÂçЭÒé±»²»·¨·Ö×ÓÓÃÀ´·¢¶¯´ó¹æÄ£µÄÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷¡£ÖÒÑÔ°üÀ¨ÈýÖÖÍøÂçЭæÅºÍÒ»¿îWebÓ¦ÓóÌÐò¡£ÆäÖÐCoAP£¨ÊÜÔ¼ÊøµÄÓ¦ÓÃЭÒ飩¡¢WS-DD£¨Web·þÎñ¶¯Ì¬·¢Ã÷£©ºÍARMS£¨AppleÔ¶³ÌÖÎÀí·þÎñ£©ÕâÈýÖÖÍøÂçЭÒéÒÑÓÐýÌ屨µÀ£¬·¢Ã÷ÁËÔÚÏÖÊµÍøÂçÇéÐÎÖеÄÀÄÓÃÇéÐΡ£

FBI µÄ¹ÙÔ±ÌåÏÖ£¬ÕâЩÐÂÐÍDDoS¹¥»÷;¾¶ÒѾ­ÊÇÆÈÔÚü½ÞµÄÕæÊµÍþв¡£ÓÉÓÚËûÃǶÔÏà¹Ø×°±¸µÄÐëÒªÐÔ£¬³§ÉÌÄÑÒÔͨ¹ý½ûÓÃʵÏÖ¹¥»÷µÄ×èÖ¹¡£¶øÕâÎÞÒɸø´òÔì´ó¹æÄ£½©Ê¬ÍøÂ磬·¢¶¯¼«¾ßÆÆËðÐԵĠDDoS ¹¥»÷ÌṩÁ˱㵱¡£

ÕÒµ½ÓÐÓÃÇå¾²ÊֶεÄÌõ¼þ£¬ÊǶԹ¥»÷µÄ³ä·ÖÏàʶ¡£ÒÔÏÂÊÇAG¹«Ë¾¿Æ¼¼¶ÔÕâËÄÖÖÐÂÐÍ DDoS ¹¥»÷;¾¶µÄ½â¶Á£¬ÒÔ¼°½¹µãµÄ·À»¤Ë¼Ð÷·ÖÏí¡£

 CoAP£ºÔ¼ÊøÓ¦ÓÃЭÒ飨Constrained Application Protocol£©

CoAPÊÇÒ»ÖÖÇáÁ¿¼¶µÄ»úе¶Ô»úе(M2M)ЭÒ飬¿ÉÒÔÔÚÄÚ´æºÍÅÌËã×ÊԴϡȱµÄÖÇÄÜ×°±¸ÉÏÔËÐС£¼òÆÓÀ´Ëµ£¬CoAPÓëHTTPºÜÊÇÀàËÆ¡£µ«Ëü²»ÊÇÊÂÇéÔÚTCP°ü£¬¶øÊÇÔÚUDPÉÏ¡£¾ÍÏñHTTPÓÃÓÚÔÚ¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼ä´«ÊäÊý¾ÝºÍÏÂÁGET£¬POST£¬CONNECTµÈ£©Ò»Ñù£¬CoAPÒ²ÔÊÐíÏàͬµÄ¶à²¥ºÍÏÂÁî´«Ê书Ч£¬µ«²»ÐèÒªÄÇô¶àµÄ×ÊÔ´£¬ÕâʹËü³ÉΪÎïÁªÍø×°±¸µÄÀíÏëÑ¡Ôñ¡£È»¶ø£¬¾ÍÏñÆäËü»ùÓÚUDPµÄЭÒ飬CoAPÌìÉú¾ÍÈÝÒ×Êܵ½IPµØµãÓÕÆ­ºÍÊý¾Ý°ü·Å´óµÄÓ°Ï죬ÕâÒ²ÊÇËüÈÝÒ×±»DDoS¹¥»÷ÀÄÓõÄÖ÷ÒªÔµ¹ÊÔ­ÓÉ¡£

WS-DD£ºWeb·þÎñ¶¯Ì¬·¢Ã÷£¨Web Services Dynamic Discovery£©

WS-DDÊÇÒ»ÖÖ¾ÖÓòÍøÄڵķþÎñ·¢Ã÷¶à²¥Ð­Òé¡£µ«¾­³£ÓÉÓÚ×°±¸³§É̵ÄÉè¼Æ²»µ±£¬µ±Ò»¸öÕý³£µÄIPµØµã·¢ËÍ·þÎñ·¢Ã÷±¨ÎÄʱ£¬×°±¸Ò²»á¶ÔÆä¾ÙÐлØÓ¦¡£ÈôÊÇ×°±¸±»Ì»Â¶ÔÚ»¥ÁªÍøÉÏ£¬¼´¿É±»¹¥»÷ÕßÓÃÓÚDDoS·´Éä¹¥»÷¡£WSDЭÒéËù¶ÔÓ¦µÄ¶Ë¿ÚºÅÊÇ3702¡£Ä¿½ñ£¬ÊÓÆµ¼à¿Ø×°±¸µÄONVIF¹æ·¶ÒÔ¼°Ò»Ð©´òÓ¡»ú£¬¶¼¿ª·Å»òÔÚÕýÔÚʹÓÃWS-DD·þÎñ¡£×ÅʵÔçÔÚ2019Ä꣬AG¹«Ë¾¿Æ¼¼¸ñÎïʵÑéÊҾͶÔWS-DD¿É±»ÓÃÓÚ·´Éä¹¥»÷×ö³öÁËÆÊÎö¡£

http://blog.nsfocus.net/ws-discovery-reflection-attack-analysis/

ARMS£ºÔ¶³ÌÖÎÀí·þÎñ£¨Apple Remote Management Service£©

2019Ä꣬ÒÑÓв»·¨·Ö×ÓʹÓÃAppleÔ¶³ÌÖÎÀí·þÎñ£¨ARMS£©¼´AppleÔ¶³Ì×ÀÃæ£¨ARD£©¹¦Ð§µÄÒ»²¿·Ö£¬ÊµÑéÁËDDoS·Å´ó¹¥»÷¡£ARDÆôÓúó£¬ARMS·þÎñ×îÏÈÔÚ¶Ë¿Ú3283ÉÏÕìÌý´«Êäµ½Ô¶³ÌApple×°±¸µÄÈëÕ¾ÏÂÁ¹¥»÷Õß½ø¶ø¿ÉÒÔ·¢¶¯·Å´ó±¶ÊýΪ35.5µÄDDoS·Å´ó¹¥»÷¡£´ËÎó²îµÄȪԴÔÚÓÚARMS×ÔÉí·þÎñµÄÉè¼ÆÈ±ÏÝ¡£ÔÚʹÓÃUDP´«ÊäЭÒéµÄÇéÐÎÏ£¬¿Í»§¶ËÏònetAssistant·þÎñ¶Ë¿Ú£¨¼´3283¶Ë¿Ú£©·¢ËÍÒ»¸öUDP×îС°ü£¬netAssistant·þÎñ±ã»á·µ»ØÐ¯´øÓÐÖ÷»ú±êʶµÄ³¬´ó°ü£¬ÇëÇóÓëÏìÓ¦Ïà²îÊýÊ®±¶¡£ÓÉÓÚÆä²¢Î´ÑÏ¿áÏÞÖÆÇëÇóÓëÏìÓ¦±È£¬µ¼ÖÂ̻¶ÔÚ¹«ÍøÖпªÆônetAssistant·þÎñµÄÍøÂç×°±¸¾ùÓпÉÄܱ»¿´³É·´ÉäԴʹÓá£

Jenkins£º»ùÓÚ Web µÄ×Ô¶¯»¯Èí¼þ

JenkinsÊÇÒ»¸ö¿ªÔ´µÄ¡¢¿ÉÀ©Õ¹µÄÒ»Á¬¼¯³É¡¢½»¸¶¡¢°²ÅÅ£¨Èí¼þ/´úÂëµÄ±àÒë¡¢´ò°ü¡¢°²ÅÅ£©µÄ»ùÓÚWebµÄƽ̨¡£JenkinsÊÇÒ»¸öÖ´ÐÐ×Ô¶¯»¯Ê¹ÃüµÄ¿ªÔ´·þÎñÆ÷¡£Ê¹ÓÃJenkinsµÄÎó²î£¨ÈçCVE-2020-2100£©£¬¿ÉÒÔÓÃÀ´·¢¶¯ DDoS ¹¥»÷¡£Ö»¹ÜJenkins v2.219ÖÐÒѾ­ÐÞ¸´ÁËÕâ¸öÎó²î£¬¿ÉÊÇÐí¶àJenkin·þÎñÆ÷ÈÔÈ»»áÊܵ½Ó°Ïì¡£

ÏÖʵÉÏ£¬³ýÁËFBI Ìá¼°µÄÕâËÄÖÖÐÂÐÍ DDoS ¹¥»÷;¾¶£¬ÎÒÃÇ»¹Ó¦¹Ø×¢¸ü¶à¿ÉÓÃÓÚ·´Éä·Å´ó¹¥»÷ £¬ÊÂÇéÔÚUDP µÄЭÒé¡£ÈçSSDP¡¢QOTD¡¢SNMP¡¢CHARGEN¡¢LDAP¡¢MEMCACHE¡¢WS-DISCOVERY µÈ¡£8f337bf6ecb26782294b6c59512eaaf

UDP·´Éä·Å´ó¹¥»÷Êǽü¼¸Äê×î»ðÈÈ£¬±»Ê¹ÓÃ×î¶àµÄDDoS¹¥»÷·½·¨Ö®Ò»¡£UDPÊý¾Ý°üÊÇÎÞÁ´½Ó״̬µÄ·þÎñ£¬¹¥»÷Õß¿ÉÒÔС¼ÛÇ®µÄʹÓÃUDP Ð­ÒéÌØÕ÷¹¥»÷Ä¿µÄÖ÷»ú£¬Ê¹ÆäÎÞ·¨ÏìӦ׼ȷÇëÇó£¬ÒÔʵÏ־ܾø·þÎñ¡£

ÄÇô£¬ÎÒÃÇÓ¦¸ÃÔõÑùÓ¦¶ÔUDP·´Éä·Å´ó¹¥»÷ £¿±¾Îĸø³öÒÔÏÂ5ÖÖ³£ÓõķÀ»¤Ë¼Ð÷£º

1.      Ö¸ÎÆÑ§Ï°Ëã·¨£ºÑ§Ï°¼ì²éUDP±¨ÎÄÖеÄPayload£¬×Ô¶¯ÌáÈ¡¹¥»÷Ö¸ÎÆÌØÕ÷£¬»ùÓÚ¹¥»÷ÌØÕ÷×Ô¶¯¾ÙÐÐÑïÆú»òÕßÏÞËÙµÈÐж¯¡£

2.      Á÷Á¿²¨¶¯ÒÖÖÆËã·¨£º²úƷͨ¹ý¶ÔÕý³£µÄÓªÒµÁ÷Á¿¾ÙÐÐѧϰ½¨Ä££¬µ±Ä³ÀàÒì³£Á÷Á¿·ºÆð¿ìËÙÍ»ÔöµÄ²¨¶¯Ê±£¬×Ô¶¯ÅжÏÄÄЩÊÇÒì³£´Ó¶ø¾ÙÐÐÏÞËÙ/·â½û£¬ÒÔ×èÖ¹¶ÔÕý³£Á÷Á¿Ôì³ÉÓ°Ïì¡£

3.      »ùÓÚIPºÍ¶Ë¿ÚµÄÏÞËÙ£ºÍ¨¹ý¶ÔÔ´IP¡¢Ô´¶Ë¿Ú¡¢Ä¿µÄIP¡¢Ä¿µÄ¶Ë¿ÚµÄ¶àÖÖ´îÅä×éºÏ¾ÙÐÐÏÞËÙ¿ØÖÆ£¬ÊµÏÖÎÞаÓÐÓõķÀ»¤Õ½ÂÔ¡£

4.      ·þÎñ°×Ãûµ¥£º¹ØÓÚÒÑÖªµÄUDP·´ÉäЭÒ飬ÈçDNS·þÎñÆ÷µÄIPµØµãÌí¼ÓΪ°×Ãûµ¥£¬³ý´ËÖ®Í⣬ÆäËûÔ´IPµÄ53¶Ë¿ÚÇëÇó°ü£¬ËùÓзâ½û£¬Ê¹UDP·´Éä·Å´ó¹¥»÷µÄÓ°ÏìÃæ½µµÍ¡£

5.      µØÀíλÖùýÂËÆ÷£ºÕë¶ÔÓªÒµÓû§µÄµØÀíλÖÃÌØÕ÷£¬ÔÚÓöµ½UDP·´Éä¹¥»÷ʱ£¬ÓÅÏÈ´ÓÓû§Á¿×îÉÙµØÀíλÖõÄÔ´IP¾ÙÐзâ½û×è¶Ï£¬Ö±µ½½«Òì³£µØÀíλÖõÄÔ´IPÇëÇ´Ô𲿷â½û£¬Ê¹Á÷Á¿½µÖÁ·þÎñÆ÷¿É´¦Öóͷ£µÄ¹æÄ£Ö®ÄÚ£¬¿ÉÓÐÓüõÇá×ÌÈÅÁ÷Á¿¡£

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷

? 2025 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼