IoT home routers used to launch application-level DDoS attack

IoT home routers used to launch application-level DDoS attack

Eight brands of IoT home routers were compromised and used to create botnets that launched an application- against a website's multiple servers.

Eight different brands of Internet of Things (IoT) home routers were compromised and used to create botnets that launched an application-level distributed-denial-of-service (DDoS) attack against a website's multiple servers.

The application-level DDoS, or Layer 7 HTTPS flood attack, was discovered by security firm Sucuri.

The campaign generated more than 120,000 HTTPS requests per second (RPS) using 47,000 IP addresses, according to a blog post by Securi founder and CTO Daniel Cid. “While we have seen routers being used maliciously in the past, we have never seen them used at this scale,” wrote Cid.

The attack leveraged multiple router providers, including 6,015 router devices manufactured by Huawei Enterprise routers (device versions HG8245H, HG658d, and HG531), 2,119 Mikro RouterOS devices, and 245 AirOS router devices manufactured by Ubiquiti Networks.


NuCom 11N Wireless Routers, Dell SonicWalls, VodaFone, Netgear, and Cisco-IOS routers were also were exploited and used in the attack.

Last week, Level 3 Threat Research Labs and Flashpoint discovered IoT devices targeted by the Lizkebab family of malware (also known as Bashlite, Torlus, or gafgyt) in order to create DDoS botnets.

This article originally appeared at scmagazineuk.com

Source: Copyright © SC Magazine, UK edition

See more about:  ddos  |  home routers  |  internet of things  |  iot
 
 

Readers of this article also read...

Tim Berners-Lee: How we can win back the web 

Tim Berners-Lee: How we can win back the web

 
New law will force some (but not all) organisations to reveal data breache 

New law will force some (but not all) organisations to reveal data breache

 
Gallery: The PCs of PAX Australia 2016 

Gallery: The PCs of PAX Australia 2016

 
How should we teach our kids to use digital media? 

How should we teach our kids to use digital media?

 
Report identifies path from online gaming to cyber-criminality 

Report identifies path from online gaming to cyber-criminality

 

Latest Comments

From our Partners

PC & Tech Authority Downloads