Connect with us

Hi, what are you looking for?

ELECTRONICS

4 million Universal Plug and Play devices vulnerable to DDoS attacks

A new advisory alerts the security community, device vendors, Internet service providers and enterprises to the risk of massive DDoS attacks involving Universal Plug and Play (UPnP) devices.

LTE TV. Smart Communications Inc. (Smart) taps the evolved Multimedia Broadcast Multicast Services (eMBMS) technology to multicast live video content on this TV equipped with a device that converts data received by an LTE SIM. The live content is also streamed on an LTE-capable handset.

That smart TV or web camera you are using can be used by cybercriminals to launch distributed denial of service (DDoS) attacks. A new advisory alerts the security community, device vendors, Internet service providers and enterprises to the risk of massive DDoS attacks involving Universal Plug and Play (UPnP) devices.

Issued by the Prolexic Security Engineering & Response Team, the advisory has observed the use of a new reflection and amplification DDoS attack that deliberately misuses communications protocols that come enabled on millions of home and office devices, including routers, media servers, web cams, smart TVs and printers.

The protocols allow devices to discover each other on a network, establish communication and coordinate activities. DDoS attackers have been abusing these protocols on Internet-exposed devices to launch attacks that generate floods of traffic and cause website and network outages at enterprise targets.

“Malicious actors are using this new attack vector to perform large-scale DDoS attacks. PLXsert began seeing attacks from UPnP devices in July, and they have become common,” said Stuart Scholly, senior vice president and general manager, Security Business Unit, Akamai. “The number of UPnP devices that will behave as open reflectors is vast, and many of them are home-based Internet-enabled devices that are difficult to patch. Action from firmware, application and hardware vendors must occur in order to mitigate and manage this threat.”

Advertisement. Scroll to continue reading.

PLXsert found 4.1 million Internet-facing UPnP devices are potentially vulnerable to being employed in this type of reflection DDoS attack – about 38 percent of the 11 million devices in use around the world. PLXsert will share the list of potentially exploitable devices to members of the security community in an effort to collaborate with cleanup and mitigation efforts of this threat.

“These attacks are an example of how fluid and dynamic the DDoS crime ecosystem can be,” explained Scholly. “Malicious actors identify, develop and incorporate new resources and attack vectors into their arsenals. It’s predictable that they will develop, refine and monetize these UPnP attack payloads and tools in the near future.”

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

The cybersecurity landscape is fast changing, and businesses across all industries as well as consumers are facing evolving threats to their data and privacy....

HEADLINES

Pondering on the significant events and trends that shaped the financial threats’ sector in 2021, Kaspersky researchers have forecasted several important tendencies expected to...

HEADLINES

As organizations worldwide slow down for the holidays as well as find themselves in work environment transitions - with many returning to pre-pandemic in-office...

HEADLINES

Deep learning models have reached the point where they can train themselves to enable security systems to predict threats before they happen.

SOFTWARE

MicroWorld's latest offering aims to reinvent cybersecurity in the face of an ever-evolving threat landscape, especially in light of the ongoing pandemic. The cyber...

HEADLINES

When you compare the immense financial losses that a breached company suffers with the much smaller-scale financial transactions taking place on these criminal forums,...

HEADLINES

The vast majority (70%) of all IT teams said the number of phishing emails hitting their employees increased during 2020. This rose to 82%...

HEADLINES

According to WorldRemit, there are four industry-wide scams that Filipinos should be aware of this 2021: “email scams, online dating scams, shopping scams and...

Advertisement