ºÚȸ¹¥»÷£ºÉî¶È·ÖÎö²¢ËÝÔ´Dofloo½©Ê¬ÎïÁªÍø±³ºóµÄ¡°ºÚȸ¡±

°ä²¼¹¦·ò 2019-05-31


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2019Äê4ÔÂÆðÍ· £¬GA»Æ½ð¼×ADLab¹Û²ìµ½ConfluenceÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2019-3396±»Dofloo½©Ê¬ÍøÂç¼Ò×åÓÃÓÚ¹¥Õ¼É豸×ÊÔ´ £¬Confluence ÊÇÒ»¸öרҵµÄÆóҵ֪ʶÖÎÀíÓëЭͬÈí¼þ £¬³£ÓÃÓÚ¹¹½¨ÆóÒµwiki¡£±¾´Î·ì϶ÊÇÓÉÓÚConfluence Server ºÍConfluence DataÖеÄWidget Connector´æÔÚ·þÎñ¶ËÄ£°å×¢Èë·ì϶ £¬¹¥»÷Õß»ú¹ØÌض¨ÒªÇó¿ÉÔ¶³Ì±éÀú·þÎñÆ÷ËÁÒâÎļþ £¬ÉõÖÁʵÏÖÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£ÓÐÒâ˼µÄÊÇDofloo½©Ê¬ÍøÂç¼Ò×å²»½öÆðÍ·ÀûÓøßΣ·ì϶½øÐй¥»÷ £¬²¢ÇÒÆä±³ºóµÄºÚ¿Í»¹ÀûÓÃÒ»ÖÖ¸ü¾ßÓ°ÏìÁ¦µÄ¡°ºÚȸ¹¥»÷¡±À´ÈëÇÖ²úÒµÁ´ £¬ÒÔÕÆ¿ØÔ½·¢×³´óµÄÍøÂç¹¥»÷×ÊÔ´¡£¶øÔÚ´Ëǰ £¬ÎÒÃÇÒѾ­×öÁ˳¤¹¦·òµÄÓëDofloo½©Ê¬¼Ò×åºÚ¿Í²úÒµÁ´ÓйصÄ×êÑÐ £¬ÇÒÒѾ­È·¶¨ÁËÕâÖÔìձ鴿ÔÚÓÚDofloo¼Ò×åÖеġ°ºÚȸ¹¥»÷¾°Ïó¡± £¬²¢¶ÔÆäÖеġ°ºÚȸ¡±½øÐÐÁ˳־Ã×·×ÙÓë·ÖÎö¡£


´Ë´¦ £¬ÎÒÃÇËùÌá³ö¡°ºÚȸ¹¥»÷¡±²»½öÊÇÒ»ÖÖ¸ßЧµÄºÚ¿Í¹¥»÷¼¿Á© £¬²¢ÇÒ¸üÊÇÒ»ÖÖ²úÒµÁ´¼¶´ËÍâ¹¥»÷²½Öè £¬Í¨³£ÎªÐþÉ«²úÒµÁ´ÉÏÓκڿÍËùΪ¡£ºÚȸ¹¥»÷Ó빩¸øÁ´¹¥»÷ÓÐÒìÇúͬ¹¤Ö®Ãî £¬Ö»Êǹ¥»÷µÄÖ¸±ê²»ÊÇͨÀýµÄ²úÒµÁ´ £¬¶øÊǺڿͲúÒµÁ´£»Êܹ¥»÷Á´µÄ½áβҲ²»ÊÇͨ³£Óû§ £¬¶øÊǼ«¾ß·çÏÕÐԵĺڿÍȺÌå¡£ÔÚÍøÂ簲ȫÓëºÚ¿Í²úÒµÁ´µÄ³Ö¾ÃÆ¥µÐ £¬Ê¹µÃ¸Ã²úÒµÁ´ÈÕ½¥³ÉÊìÇÒ¸´ÔÓ £¬²¢ÐγÉÁËÒ»¸öÖØ´óµÄºÚ¿ÍÉú̬ϵͳ £¬¶øÔÚÀûÒæºÍÉú¼ÆÐèÒªµÄÇý²ßÏ £¬ºÚȸ¾°ÏóËÆºõÔì³ÉÁ˱ØÈ» £¬ÉõÖÁÔÚʳƷÁ´µÄÉ϶˽ø»¯³öÁ˺ÚȸÉú̬ £¬ÈçDeath½©Ê¬ÍøÂçµÄ¡°´óºÚȸ-ºÚȸ-ó«ò롱¡£


×ÔGA»Æ½ð¼×ADLabÓÚ2016ËêÊ×·¢ÏÖºÚȸ¹¥»÷²¢ÓÚ2017Äê1Ô°䲼¡¶ºÚȸ¹¥»÷-½ÒÃØDeath½©Ê¬ÍøÂç±³ºóµÄÖÕ¼«½ÚÔìÕß¡·Ö®ºó £¬»¹Ïà¼ÌÔÚ¶à¸ö¶ñÒâ´úÂë¼Ò×åÖз¢ÏÖÁ˺Úȸ¹¥»÷ £¬²¢°ä²¼ÁËÉî¶È·ÖÎö»ã±¨¡¶½ÒÃØBillgates½©Ê¬ÍøÂçÖеĺÚȸ¾°Ï󡷺͡¶ºÚȸ¹¥»÷£º½ÒÃØTF½©Ê¬ÎïÁªÍøºÚ¿Í±³ºóµÄºÚ¿Í¡·¡£ÔÚ´ËǰµÄºÚȸ·ÖÎöºÍ×·×ÙÖÐ £¬ÎÒÃǸ淢ÁËDeath½©Ê¬ÍøÂç±³ºóµÄÄǸö½ÚÔì×ÅÉÏǧ½©Ê¬×ÓÍøÂçµÄ³¬µÈºÚ¿Í £¬ÒÔ¼°Éî²ØÔÚBillgates½©Ê¬ÍøÂçºÍÎïÁªÍø½©Ê¬DDoSTF¼Ò×å±³ºóµÄºÚȸ¡£´Ë±íÎÒÃÇ»¹¾ßÌåÂÛÊöÁËÿ¸ö¼Ò×åÖÓ×°ºÚȸ¹¥»÷¡±µÄºÚ¿Íµµ´Î½á¹¹ £¬ÈçDeath½©Ê¬ÍøÂçµÄÈý¼¶ºÚ¿Í½á¹¹(´óºÚȸ-ºÚȸ-ó«òë) £¬BillgatesºÍTFµÄ¶þ¼¶ºÚ¿Í½á¹¹£¨ºÚȸ-ó«ò룩 £¬ÒÔ¼°¶ÔÓйصĴóºÚȸ¡¢ºÚȸºÍó«òë½øÐÐÁËÍøÂçÐÐΪ·ÖÎöºÍÉí·Ý¼ø±ð £¬²¢×öÁ˾«×¼µÄºÚ¿Í»­Ïñ¡£


¶ø±¾ÎĽ«»á¾ßÌåÂÛÊöºÚȸ¹¥»÷µÄ×îз¢ÏÖ¹ý³Ì £¬ÒÔ¼°Dofloo½©Ê¬ÍøÂç¼Ò×åÖÐËù´æÔڵġ°ºÚȸ¾°Ï󡱡£Í¨¹ý¶Ô¼Ò×å½øÐÐÈ«ÃæµÄ·ÖÎö»¹·¢ÏÖ £¬¸Ã½©Ê¬¼Ò×åµÄ×÷ÕßÔÚÔ콩ʬ¹ý³ÌÖоÍÁôÓкÚȸµÄ½Ó¿Ú £¬¹ÌÈ»ÉÙÁ¿¾«Ã÷µÄºÚ¿Í·¢ÏÖÁ˸ýӿڲ¢½øÐÐÁ˶ϸù £¬µ«ÊÇ´ó²¿ÃŵĺڿͳÉΪ±»¹¥»÷¶ÔÏó £¬±»Ö²ÈëÁ˺ÚȸºóÃÅ¡£±¾ÎÄÖÐÎÒÃÇ»¹»á¶ÔDofloo½©Ê¬ÍøÂç±³ºóµÄºÚȸ½øÐÐÉî¶ÈÍÚ¾òºÍ¶¨Î» £¬²¢·ÖÎö¸Ã¼Ò×åÓëÀàËÆ½©Ê¬¼Ò×åMrBlack¡¢DnsAmp¡¢Flood.AÖ®¼äµÄͬԴ¸öÐÔ¡£


1.Dofloo½©Ê¬¼Ò×å¼ò½é


Dofloo £¬±ðÃûSpikeºÍAES.DDoS £¬ÊÇÒ»¿îÖ§³ÖARM¡¢x86¡¢mipsdµÈ¶àCPU¼Ü¹¹µÄ½©Ê¬ÍøÂ編ʽ¡£Dofloo¼Ò×åÒò2014ÄêÕë¶Ô±±ÃÀÖÞºÍÑÇÖÞ¶à¸ö¹ú¶È½øÐиߴï215GbpsÁ÷Á¿µÄ¹¥»÷¶øÎÅÃû £¬¶ûºó³Ö¾ÃµÄ¹¥Õ¼ÎïÁªÍøÉ豸×ÊÔ´²¢ÆµÈԵؽøÐÐÍøÂç¹¥»÷»î¶¯¡£Æ¾¾ÝÈüÃÅÌú¿ËÔÚ2016Äê°ä²¼µÄ¡¶Internet Security Thread Report¡· £¬Dofloo½©Ê¬ÍøÂç¶ñÒⷨʽλÁÐ2015Äê¶ÈIoTÁìÓò¶ñÒⷨʽÍþвÅÅÐаñµÚ¶þÃû¡£


´Ë±í £¬Dofloo»¹ÔÚ2016Äê9ÔÂͬMirai½©Ê¬Ò»Â·²Î¼ÓÁËÔÆÍÆË㹫˾OVHµÄ¹¥»÷ £¬±¾´Î¹¥»÷µÄÁ÷Á¿³¬¹ýÁË1Tbps £¬´´ÏÂÁËÉ¢²¼Ê½»Ø¾ø·þÎñ¹¥»÷µÄº¹Çà¼Í¼ £¬¶øÍ¬ÄêµÄ10ÔÂÔٴβμÓÁËMiarai½©Ê¬Ö÷µ¼µÄ¶ÔÓòÃû·þÎñÉÌDynµÄ´ó¹æÄ£DDoS¹¥»÷ £¬ÒÔÖÁÕû¸öÃÀ¹ú¶«º£°¶µÄÍøÂç´¦ÓÚ¼«¶Ë̱»¾µÄ״̬¡£2019ÄêµÄ4ÆðÍ·ÀûÓÃ×îÐÂÅû¶µÄÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2019-3396½øÐдóÃæ»ý´«²¼ £¬¹¥Õ¼ÁËÏ൱ÊýÁ¿µÄÍøÂçÉ豸¡£ÏÂͼÊÇÎÒÃÇÆ¾¾ÝDofloo½©Ê¬ÍøÂçËùÖ´ÐеıÈÁ¦³ÁÒªµÄ¹¥»÷ÊÂÎñËù»æÔìµÄ¹¥»÷º¹Çàͼ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2.·¢ÏÖDofloo½©Ê¬ÖеĺÚȸ


Ôڳ־õĶԽ©Ê¬ÍøÂçµÄ×êÑÐÖÐ £¬DoflooÒ»ÏòÊÇÎÒÃÇ¼à¿ØµÄ¶ÔÏó¡£ÔÚ֮ǰµÄ×êÑÐÖÐ £¬Í¨¹ý×Ô¶¯»¯·ÖÎö¸Ã¼Ò×åµÄ¹ØÁªÑù±¾ £¬·¢ÏָüÒ×åµÄ´ó²¿ÃÅÑù±¾³ÇÊÐÆô¶¯Á½¸öÐµĹ¥»÷Ïß³Ì £¬²¢·¢ÏÖÕâÁ½¸öÏ̴߳æÔÚÒì³£ÐÐΪ¡£È磺²»½ö»áÉèÖÃÑÓ³¤Æô¶¯Ïß³Ì £¬»¹»á³¢ÊÔ¸úÁíÒ»¸öC&C½ÚÔì¶Ë½øÐÐÏνÓͨѶ¡£Òò¶ø £¬ÎÒÃǶÔÕâЩÑù±¾½øÐÐÁ˽øÒ»²½µÄ·ÖÎö £¬×îÖÕÈ·¶¨¸Ã½©Ê¬Éú̬Öб»Ö²ÈëÁ˺Úȸ¡£


Õë¶ÔÎÒÃÇÍøÂçµ½µÄ1200¸ö½©Ê¬Ñù±¾ £¬»æÔìÑù±¾µÄÉÏÏ߯µ¶ÈÕ¼ºÃ±ÈÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´ÓÉÏͼÄܹ»¿´³ö £¬ÓÐÈý¸öµØÖ·µÄÉÏÏ߯µ¶ÈÔ¶¸ßÓÚÆäËûµÄC&C¡£½áºÏÑù±¾·ÖÎö·¢ÏÖ £¬ÉÏÏßµ½ÕâÈý¸öC&CµØÖ·µÄÑù±¾ÏÕЩ¶¼ÓÐÁ½¸ö¶ÀÁ¢½ÚÔìµÄC&C £¬²¢ÇÒ½©Ê¬»ØÁ¬ÕâÈý¸öC&CµØÖ·¶¼ÊÇͨ¹ý´´½¨×ÓÏ̵߳ķ½Ê½½øÐÐ £¬¶øÆä¹ØÁªµÄÑù±¾µÄÁí±íÒ»¸öC&CÈ´ÊÇÔÚÖ÷Ïß³ÌÖнøÐлØÁ¬¡£Òò¶ø £¬Í¨¹ý¸Ã½©Ê¬µÄÕ⼸¸ö¸öÖ°Äܹ»Åж¨ÆäÖÐ×¢¶¨´æÔÚºÚȸ¹¥»÷µÄ¾°Ïó £¬¶øÕâÈý¸öC&CµØÖ·¾ÍÊÇDofloo½©Ê¬Éú̬ÖеĺÚȸC&CµØÖ· £¬ÓëºÚȸC&CµØÖ·ÓйØÁªµÄÆäËûC&CµØÖ·¾ÍÊÇDofloo½©Ê¬Éú̬ÖÐó«òëºÚ¿ÍµÄC&CµØÖ·¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÎÒÃǶÔÕâÈý¸öºÚȸC&CµØÖ·ÓйØÁªµÄó«òëC&C×öÁË·ÖÀàͳ¼Æ £¬ÈçϱíËùʾ£º


C&CµØÖ·

ó«òë½©Ê¬ÍøÂçÊýÁ¿

183.60.149.199

189

118.193.217.144

282

aaa.tfddos.net

85


¿É¼û £¬ºÚȸC&C 118.193.217.144ÕÆ¿ØÁË×î¶àµÄó«òë½©Ê¬ÍøÂç £¬ÔÚ¶ûºóµÄ·ÖÎöÖÐ £¬Í¨¹ýËÝÔ´È·¶¨ÁËÕâÈý¸öºÚȸC&CÊÜͳһ¸öºÚ¿Í½ÚÔì¡£


3.Dofloo½©Ê¬ºÚȸËÝÔ´Óë»­Ïñ


ͨ¹ý¶ÔÑù±¾µÄ·ÖÎö £¬½áºÏÑù±¾Öеĺ¯Êý¶¨Ãûϰ¹ß¡¢¹¥»÷Á÷Á¿Ìص㡢±äÖÖÔ´Âë×¢½âÒÔ¼°Ñù±¾·¢×÷´«²¼Ê±ÓÃÀ´É¢²¥Ñù±¾µÄHFSÃæ°å˵»°µÈÌØµã £¬ÎÒÃÇÅж¨¸Ã¼Ò×åÓɹúÄڵĺڿͱàд¡£Òò¶øÎÒÃÇËÝÔ´Ö¸±êËø¶¨ÔÚ¹úÄÚ £¬Í¨¹ý¶ÔºÚȸÓòÃû¡°aaa.tfddos.net¡±ÖйؼüÐÅÏ¢¡±tfddos¡± £¬ÎÒÃǹØÁªµ½Ò»¿îÃûΪ¡°Ì¨·çDDoS¡±µÄ½©Ê¬Èí¼þ¡£²¢ÇÒͨ¹ý½øÒ»²½·ÖÎö·¢ÏÖ £¬¸Ã½©Ê¬Èí¼þµÄÄ£°åÑù±¾ÓëDofloo½©Ê¬ÓµÓм«ÎªÀàËÆµÄÐÐΪºÍÍøÂç¸öÐÔ¡£´Ë±í £¬¡°Ì¨·çDDoS¡±Ôںڿͼä»îÔ¾µÄ¹¦·òͬDofloo·¢×÷¹¦·ò¾ùÔÚ2014Äꡣƾ¾ÝÒÔÉÏһϵÁеÄÖ¤¾ÝÖ¤Ã÷ËûÃÇÖ®¼ä´æÔڿ϶¨Í¬Ô´ÐÔ¡£ÎªÁ˽øÒ»²½È·ÈÏËûÃÇΪͳһ¿î½©Ê¬·¨Ê½ £¬ÎÒÃÇ»¹ÀûÓÃbindiff¶Ô¡°Ì¨·çDDoS¡±½ÚÔì¶ËÌìÉúµÄ½©Ê¬ÓëDoflooµÄÑù±¾½øÐÐÁËÀàËÆ¶È±È¶Ô £¬·¢ÏÖÁ½Õß´úÂëÀàËÆ¶ÈΪ100%µÄ´úÂëÕ¼±È³¬¹ý98% £¬Òò¶øÄܹ»È·¶¨¡°Ì¨·çDDoS¡±¾ÍÊÇDofloo¼Ò×åµÄÒ»¸öÖ÷¿Ø¡£¶Ô±ÈͼÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý¶ÔÔçÆÚµÄ¡°Ì¨·çDDoS¡±µÄ½©Ê¬Ä£°å·¨Ê½·ÖÎö·¢ÏÖÓëDoflooºÚȸC&CÒ»ÑùµÄºóÃÅC&C£º183.60.149.199¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´Ë±í £¬Í¨¹ý¶Ô¡°Ì¨·çDDoS¡±µÄËÝÔ´·¢ÏÖ £¬ÆäÔøÔÚÍøÕ¾tfddos.comÉÏ×÷Ϊ¹Ù·½Èí¼þ±»¹«¿ªÊÛÂô £¬¸ÃÍøÕ¾¹ÌȻѡȡÁËÓëDoflooºÚȸÓòÃû¡°aaa.tfddos.net¡±²»Ò»ÑùµÄÓòÃû £¬µ«ËûÃǶ¼Ê¹ÓÃÁË¡°tfddos¡±×÷ΪÓòÃûµÄ¹Ø¼ü×Ö £¬Ò²¼´ÊÇ¡°tai£¨Ì¨£© feng£¨·ç£© ddos¡±¡£Òò¶øÎÒÃÇÒÔΪºóÃÅC&C£º183.60.149.199Óëaaa.tfddos.netΪͳһºÚ¿Í»òÕߺڿÍ×éÖ¯ËùΪ¡£


¶ÔÓÚºÚȸIP£º118.193.217.144µÄ·´²é·¢ÏÖ £¬ÔÚ2017Äê £¬ÓòÃûwap.tfddos.netºÍaaa.tfddos.netÓë¸ÃIPµØÖ·½øÐÐÁ˳־õİ󶨡£


´ÓÒÔÉÏ·ÖÎöÄܹ»¿´³öÈý¸öºÚȸC&C£¨183.60.149.199¡¢118.193.217.144¡¢aaa.tfddos.net£©ÊµÔòΪͳһ¸öºÚ¿Í»òÕߺڿÍ×éÖ¯Ëù½ÚÔ졣ΪÁ˸üÇ峺µÄÃèÊöÕâЩIPºÍÓòÃûÖ®¼äµÄÁªÏµ £¬×ܽá³ö¹ØÏµÍ¼ÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ΪÁË×·×ÙDofloo½©Ê¬ÍøÂç±³ºóµÄºÚȸ £¬ÎÒÃÇÏÈÍøÂçÁËC&CÓйصÄÐÅÏ¢²¢½øÐÐÁË·ÖÎö¡£ÆäÖÐͨ¹ýIP£º183.60.149.199¹ØÁª³öÀ´µÄÓйØÓòÃû´ó²¿Ãű»×÷ΪɫÇéÍøÕ¾»ò²©²ÊÍøÕ¾Ê¹Óà £¬²¢ÎÞ¿ÉÓÃÏßË÷¡£¶øtfddos.comºÍtfddos.net¶¼²ÉÈ¡ÒþÖÔ±£»¤¹æ»® £¬ÎÞ·¨½øÇ°½øÒ»²½µÄ×·Òä¡£


ÐÒÔ˵ÄÊÇÎÒÃÇÔÚ¡°Ì¨·çDDoS¡±µÄÊÛÂôº¹Çà¼Í¼Öз¢ÏÖһ·ڲƭÊÂÎñ £¬ÊÂÎñÖÐһλ²É°ìÕßÅû¶ÁË··ÂôÈËÔ±µÄQQºÅÂëºÍÖ§¸¶±¦Õ˺Å¡£Í¨¹ý½øÒ»²½·ÖÎö £¬ÎÒÃÇ×îºóÈ·ÈÏÁ˸÷·ÂôÈËÔ±µÄQQ¾ÍÊÇ¡°Ì¨·çDDoS¡±¿ª·¢ÕßµÄÊÂʵ¡£´Ë±íÎÒÃÇ»¹Í¨¹ý¸ÃQQµÄ¹ØÁªÐÅÏ¢ÍøÂçµ½¸ÃÈËÔ±ÓжàÄêºÚ²ú´ÓÒ·úÊ·£ºÈçÆä´Ó2011ÄêÆðÍ·±àдDDoSÈí¼þ £¬²¢´´½¨¡°Ì¨·ç¹¤×÷ÊÒ¡±£»Í¬Ê±Æä»¹´ÓÊÂÓëDDoSÓйصĺڲúÒµÎñ £¬²¢Í¨¹ý··Âô¶ñÒâ¹¥»÷Èí¼þºÍ·¢ÆðDDoS¹¥»÷À´Ä±È¡·¸·¨ÊÕÒæ¡£¶ø´ËºÚ¿Í¾ÍÊÇÎÒÒªËÝÔ´µÄDofloo½©Ê¬ÍøÂç±³ºóµÄºÚȸ,Æä³ýÁË¿ª·¢ÓÓװ̨·çDDoS¡±½©Ê¬Èí¼þ±í £¬»¹¿ª·¢¶à¿îDDoS¹¥»÷¹¤¾ßÈ磺ѪÐÈDDoS¡¢ÐײÐDDoSºÍ±©ÓêDDoSµÈ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý¶ûºó³Ö¾ÃµÄËÝÔ´·ÖÎö £¬ÎÒÃÇ»¹×·×Ùµ½Á˸úÚȸÔÚÏÖʵÊÀ½çÖеÄÉí·ÝÐÅÏ¢¡£´ËºÚȸÊǺÓÄÏÄÏÑôÁ½¼Ò¿Æ¼¼¹«Ë¾µÄ¼àÊ £¬²¢ÇÒÒÔ80ÍòÔªÈϽÉ×ʽð³ÖÓÐÆäÖÐÒ»¼Ò¿Æ¼¼¹«Ë¾10%µÄ¹É·Ý £¬±³µØÀï´Óʺڲú»î¶¯¡£


ƾ¾ÝÎÒÃǶÔÑù±¾·ÖÎöºÍËÝÔ´»ñÈ¡µ½µÄÐÅÏ¢ £¬Õû¶ÙºÍ×ۺϺó £¬×ܽᲢ»æÔì³öºÚȸµÄ»­ÏñÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4.Dofloo½©Ê¬µäÐÍÑù±¾·ÖÎö


ÓÉÓÚDoflooÖ§³Ö¶àÖÖCPU¼Ü¹¹ £¬ÎÒÃÇÔÚ¶ÔÕâЩƽ̨µÄÑù±¾·ÖÎöÖз¢ÏÖ £¬ËùÓÐDoflooÖ§³ÖµÄ¼Ü¹¹ £¬¶¼´æÔÚºÚȸ¾°Ïó¡£µ«Êǽ©Ê¬×÷Õß¶Ô·ÖÆçµÄ¼Ü¹¹µÄºÚȸC&C´¦ÖÃÂÔÓÐ·ÖÆç £¬Õâ¶Ô×Ô¶¯»¯·ÖÎöÒ²Ôì³ÉÁ˿϶¨µÄÓ°Ïì¡£ÎÒÃǶԱ¾´ÎÍøÂçµÄ¹²¼Æ1200¸öÑù±¾µÄ¼Ü¹¹ËùÕ¼±ÈÀý½øÐÐÁËͳ¼Æ £¬»æÔì³ÉͼÈçÏ£º
 
GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

CPU¼Ü¹¹µÄÉ¢²¼Í¼ £¬¿Ï¶¨Ë®Æ½ÉÏҲ˵ÁËÈ»¸Ã¼Ò×åÈëÇÖÉ豸ÀàÐ͵ÄÉ¢²¼ £¬Äܹ»¿´µ½ARMÉ豸µÄ±ÈÀý¼«¶È¸ß £¬ÕâÒ²×¢Ã÷ARMϵÄÉ豸Êܵ½ºÚȸ½ÚÔìµÄ±ÈÀý±ÈÁ¦¸ß¡£


½ÓÏÂÀ´ÎÒÃǶÔDofloo¼Ò×åµÄµäÐÍÑù±¾½øÐÐÁ˾ßÌåµÄ·Ö½â £¬²¢ÇÒÆ¾¾Ý´óÁ¿Ñù±¾ÌáÈ¡×ۺϳöµäÐ͵ÄͨѶÁ÷Á¿ºÍ¹¥»÷Á÷Á¿Ìصã,²¢¶ÔDofloo¼Ò×å½øÐÐÁËͬԴÐÔ·ÖÎö¡£


4.1 ×°ÖûúÔì


Dofloo½©Ê¬·¨Ê½µÄ×°ÖûúÔìÓУº½©Ê¬·¨Ê½ÔÚËÞÖ÷»úµÄÓÆ¾Ã»¯ÉèÖᢹý³ÌΨһÐÔÅжϺÍÊØ»¤¹ý³ÌÉèÖá£


½©Ê¬·¨Ê½Í¨¹ýдÈ뿪»ú×ÔÆôºÅÁîʵÏÖÓÆ¾Ã»¯¡£½©Ê¬·¨Ê½ÔÚÆô¶¯ºó £¬»áÊ×ÏȲ鳭Æô¶¯µÄºÅÁîÐвÎÊý, ÈôÊÇ·¢ÏÖûÓвÎÊý £¬ÄÇô¶ñÒⷨʽ»áĬÈÏÊÇÔÚ¸ÃÉ豸µÄµÚÒ»´ÎÔËÐÐ,´Ëʱ»áŲÓá°autoboot¡±º¯Êý¡£Ôڸú¯ÊýÖÐ £¬Å²Óá°system¡±º¯ÊýÖ´ÐÐϱíÖеĺÅÁî £¬ÒÔÈ·±£¶ñÒⷨʽÔÚ¸ÃÉ豸³ÁÆôºóÈÔ¿ÉÄÜÆô¶¯ÔËÐС£ÕâÒ²ÊÇDofloo¶ñÒⷨʽÔÚËÞÖ÷É豸ʵÏÖÓÆ¾Ã»¯µÄΨһ²½Öè¡£


sed -i -e '/exit/d'  /etc/rc.local
sed -i -e '/^\r\n|\r|\n$/d' /etc/rc.local
sed -i -e '/%s/d' /etc/rc.local
sed -i -e '2 i%s/%s' /etc/rc.local
sed -i -e '2 i%s/%s start'  /etc/rc.d/rc.local

sed -i -e '2 i%s/%s start'  /etc/init.d/boot.local


½©Ê¬·¨Ê½Í¨¹ý¶Ô±ÈϵͳÖÐÔËÐеĹý³ÌÃûÀ´È·±£ÔËǰ¹ý³ÌµÄΨһÐÔ £¬²¢Å²ÓÃforkº¯Êý´´½¨ÊØ»¤¹ý³Ì¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4.2 ÉÏÏß»úÔì


ÔÚ×°ÖûúÔìÉèÖýáÊøºó £¬½©Ê¬·¨Ê½Óë½ÚÔì¶ËC&C½øÐÐÏνÓ¡£´Ëʱ¶ñÒⷨʽ»áÍøÂç±»ÈëÇÖÉ豸µÄϵͳÐÅÏ¢ £¬²¢°ÑÕâЩÐÅÏ¢×÷ΪÉÏÏß°üµÄÄÚÈÝ·¢Ë͵½½ÚÔì¶Ë´¦¡£Õâ¸öÉÏÏß°üµÄÄÚÈÝÔ̺¬Äں˰汾¡¢CPUƵÂÊ¡¢×ÜÄÚ´æ´óÓס¢Íø¿Ú´ø¿íÒÔ¼°Ò»Ð©Ó²±àÂë×Ö·û´® £¬ºÃ±È¡°VERSONEX¡±ºÍ´óÁ¿Ñù±¾ÖгöÏֵġ°Hacker¡±¡£ÔÚºÚȸµÄÏß³ÌÖÐ £¬ÆäÉÏÏß»úÔìµÄÖ÷ÌåÖ°ÄÜÓëó«òëÏ̴߳¦µÄÖ°ÄÜÀàËÆ¶È¼«¸ß¡£·ÖÆçµÄÊÇ £¬ºÚȸÏ̻߳áÑÓ³¤15Ó×ʱºÍ40·ÖÖÓÉÏÏß £¬ÕâÍùÍù»á¹Æ»ó·ÖÎöÈËÔ±²¢¿ÉÄÜÌÓ±Ü×Ô¶¯»¯É³ÏäµÄ¼ì²â £¬Ê¹µÃºÚȸC&CÒþÄäÔÚ´óÁ¿µÄÒªÇóÖÐ £¬Ï÷¼õ±»·¢ÏֵĿÉÄÜ¡£Í¨¹ý¶Ô´óÁ¿Ñù±¾µÄ·ÖÎö £¬ÎÒÃÇ·¢ÏÖÉÏÏß°üµÄ¹Ì¶¨´óÓ×Ϊ0x400×Ö½Ú £¬²¢¶ÔÉÏÏß°üÌåʽ½âÎö¡¢ÌáÈ¡ºó×ÛºÏÕû¶Ù³öÕæÊµµÄÊý¾Ý½á¹¹ £¬ÆäÔÚÄÚ´æÖеÄÉ¢²¼ÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4.3 ÐÄÌø»úÔì


½©Ê¬·¨Ê½ÔÚSendInfoÏß³ÌʵÏÖÁË×ÔÉíµÄÐÄÌø»úÔì¡£Õâ¸öÏ̵߳ÄÖØÒªÖ°ÄÜÊÇÏòó«òë½ÚÔì¶ËºÍºÚȸ½ÚÔì¶Ë·¢ËÍÐÄÌø°ü £¬ÐÄÌø°üÄÚÈÝÔ̺¬µ±Ç°CPUʹÓÃÂʺÍÍøÂç¿ìÂÊÐÅÏ¢ £¬Í¨¹ýÒÔÏÂ2¸ö²½Öè»ñÈ¡µ½ÕâЩÄÚÈÝ£º


£¨1£© ²é³­¡°eth0¡±µ½¡°eth9¡±ÁìÓòÄÚÒÔÌ«Íø¿ÚµÄifconfigÐÅÏ¢¡£²¢Í¨¹ý¶ÁÈ¡/proc/net/dev Ŀ¼ÐÅÏ¢À´ÍÆËãÍøÂç¿ìÂÊ¡£


£¨2£©Í¨¹ý¶ÁÈ¡/proc/statĿ¼ÏµÄÐÅÏ¢ £¬»ñÈ¡cpuÊýÁ¿ £¬ÍÆËãÕ¼ÓðٷֱÈ¡£


¾­¹ýÖ¸¶¨Ìåʽƴ½Óºó £¬»áÑ­»·²»Ðݵķ¢ËÍÐÅÏ¢µ½C&C¶Ë¡£ÏÂͼΪ·¢Ë͵ÄÐÄÌø°üÐÅÏ¢£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±ÈÁ¦ÓÐȤµÄÊÇ £¬ÏÂÓεĺڿÍÔÚ·¢ÆðDDoS¹¥»÷µÄʱ³½ £¬¿ÉÄܵ××Ó²»»áÏëµ½ £¬Ö÷¿ØÖÐÏÔʾµÄ¶ñÒⷨʽµÄ¹¥»÷Á÷Á¿¿ìÂÊÏÕЩ¶¼ÊÇαÔìµÄ¡£ÎÒÃÇÔÚSendInfoÏß³ÌÖз¢ÏÖ £¬µ±¶ñÒⷨʽִÐÐDDoS¹¥»÷ʱ £¬»áŲÓá°fake_net_speed¡±º¯Êý £¬¸Ãº¯Êý»áƾ¾Ý·ÖÆçµÄDDoS¹¥»÷µÄģʽ £¬ÔÚÒ»¸ö¹Ì¶¨µÄÁìÓòÄÚαÔì¹¥»÷Á÷Á¿¿ìÂÊ¡£ÏÂͼΪ¶Ô²¿ÃÅÍÆËãËæ»úÁ÷Á¿µÄ½ØÍ¼£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½©Ê¬·¨Ê½Î±ÔìµÄ¹¥»÷Á÷Á¿Êý¾ÝÁìÓòÈçϱíËùʾ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4.4 ½ÚÔìÖ¸Áî½âÎöÓëDDoS¹¥»÷


·¢ËÍÍêÉÏÏß°üÖ®ºó £¬´Ëʱ½©Ê¬·¨Ê½»áÆÚ´ý½Ó¹Ü½ÚÔì¶ËµÄ½ÚÔìÖ¸Áî¡£Dofloo»áÊ×ÏȰѽÚÔìÖ¸Áî°üµÄǰËĸö×Ö½Ú×÷ΪģʽָÁîÂë½øÐнâÎö £¬ÓÉ´ËÀ´ÅжϽÓÏÂÀ´Òª½øÐеIJÙ×÷ £¬ÖØÒªÖ§³ÖµÄ²Ù×÷ÓÐÈýÖÖ:


£¨1£©Ö¸ÁîÂëΪ0x5ʱ £¬½øÈëCmdShellº¯Êý £¬¸Ãº¯ÊýÄÚ²¿Å²ÓÃÁËsystemº¯Êý £¬¿É×÷ΪԶ¿ØÀ´ÏÂÔØ»òÖ´ÐÐÆäËûÖ¸¶¨ÊýÁî¡£
£¨2£©Ö¸ÁîÂëΪ0x6ʱ £¬½øÈëDealwithDDoSº¯Êý £¬´Ëº¯ÊýΪDDoS¹¥»÷º¯Êý £¬ËùÓÐÖ´Ðй¥»÷µÄÅжϺÍÂß¼­¶¼Ôڴ˺¯ÊýÖС£

£¨3£©Ö¸ÁîÂëΪ0x7ʱ³½ £¬Å²ÓÃkillº¯Êý £¬ÖÕÖ¹¹ý³Ì¡£


ͬʱDofloo¼Ò×å¶Ô½ÚÔìÖ¸Áî½øÐÐÁË128λµÄAES¼ÓÃÜ £¬Õâ¸ö¸öÐÔ´ó´óÔö³¤ÁË¶ÔÆä½ÚÔìÖ¸ÁîÁ÷Á¿¼à¿ØºÍʶ´ËÍâÄѶÈ¡£ÎÒÃǶÔÍøÂçµ½µÄÑù±¾½øÐзÖÎöºó·¢ÏÖ £¬ËùÓмܹ¹Ï½©Ê¬·¨Ê½ÓÃÀ´½âÃܵÄKEY¶¼ÊÇÒ»ÑùµÄ £¬ÕâÒ²×¢Ã÷»¥ÁªÍøÖÐDofloo½©Ê¬¼Ò×åµÄÑù±¾¶¼À´×Ôͳһ¸öÄ£°æ¡£KEYÈçÏÂËùʾ£º


unsignedcharaes_key[] = { 0x2b, 0x7e, 0x15, 0x16, 0x28,  0xae, 0xd2, 0xa6, 0xab, 0xf7, 0x15, 0x88, 0x9, 0xcf, 0x4f, 0x3c };


ÎÒÃÇ·ÂÕÕÁËδ¼ÓÃܵĽÚÔìÖ¸Á³ýȥǰ4¸ö×÷ΪģʽָÁîÂëµÄ×Ö½Ú£©ÔÚÄÚ´æÖеIJ¼¾Ö,Æä½ÚÔìÖ¸ÁîµÄ¸÷¸ö×ֶεÄÔ¢ÒâÈçÏÂͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µ±½øÈëµ½DealwithDDoSº¯Êýʱ £¬½©Ê¬·¨Ê½Æ¾¾ÝÖ¸Áî £¬Æô¶¯·ÖÆçµÄ¹¥»÷Ï̡߳£Dofloo¼Ò×å²»½öÓµÓÐSYN¡¢HTTPµÈ´«Í³µÄ¹¥»÷²½Öè £¬»¹ÓµÓÐÀûÓÃUDPºÍ̸µÄ·´Éä·Å´óµÄ¹¥»÷·½Ê½ £¬ºÃ±ÈDNS·Å´ó¹¥»÷¡£ÏÂͼΪDofloo¿ÉÌáÒéµÄµäÐ͵ÄDDoS¹¥»÷µÄ²½Ö裺


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²¢ÇÒÎÒÃǶÔDoflooµÄ¹¥»÷²½Öè½øÐÐÁË·ÖÎö×ܽá £¬²¢¶Ô²¿ÃŹ¥»÷²½ÖèµÄÁ÷Á¿ÌØµã½øÐÐÁËÌáÈ¡ £¬Ôì×÷Á÷Á¿Ìصã±íÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÎÒÃÇÔÚ·ÖÎö¹¥»÷Ï̵߳Äʱ³½ £¬·¢ÏÖARM¼Ü¹¹µÄ¶ñÒâÑù±¾Ã¿´Î¹¥»÷´´½¨µÄ¹¥»÷Ï̼߳«¶È¶à £¬µ¥´Î¹¥»÷Ö¸Áî¿É´´½¨¼¸ÖÖÉõÖÁÊ®¼¸ÖÖ·ÖÆçÀàÐ͵Ĺ¥»÷Ï̡߳£½áºÏÑù±¾CPUµÄÉ¢²¼ £¬ÎÒÃÇÄܹ»µÃÖªARMÉ豸ϵÄDofloo¶ñÒⷨʽÊǸý©Ê¬¼Ò×åµÄÖ÷Á¦ £¬ÔÚDDoS¹¥»÷ÖÐÌṩÁËÖØÒªµÄÁ÷Á¿Ö§³Ö¡£


ͬʱƾ¾Ý¼à¿Øµ½Dofloo¹¥»÷º¹Çà £¬·¢ÏָüÒ×åÖØÒªµÄ¹¥»÷·½Ê½ÒÔUDP Flood ΪÖ÷ £¬½üÄêÀ´ºÚ¿ÍÒ²Ô½À´Ô½Ï²»¶DNSºÍNTPµÈ·´Éä·Å´ó¹¥»÷¼¿Á©À´¶Ô·þÎñÆ÷½øÇ°½ø¹¥  £¬DoflooµÄ¹¥»÷·½Ê½Õ¼±ÈÒ²Ó¡Ö¤ÁËÕâÒ»µã¡£Í¬Ê±ÎÒÃÇÒ²Äܹ»¿´µ½Layer7²ãµÄCC_FloodºÍLayer4²ãµÄTCP_Flood¡¢SYN Flood×÷Ϊ´«Í³µÄDDoSµÄ¹¥»÷·½Ê½ £¬ÆäÕ¼±ÈÒ²Ò»Ïò½ÏΪ²»±ä¡£²¢ÇÒÎÒÃÇÆ¾¾ÝÓйصĵý±¨Êý¾ÝµÃÖª £¬DoflooµÄ¹¥»÷Á¿Ïà¶ÔÓÚÆäËûµÄ¼Ò×å½ÏÉÙ £¬ÎÒÃÇ·ÖÎö´§Ä¦Doflooÿ´Î·¢Æð¹¥»÷ʱ¿ªÆôÁË´óÁ¿µÄ¹¥»÷Ïß³Ì £¬ÕâÑùÄܼӴ󷢰üÁ¿ £¬¼±¾çµ¼ÖÂÖ¸±ê·þÎñÆ÷å´»ú¡£


ÏÂͼΪDofloo½©Ê¬¼Ò×å¹¥»÷·½Ê½Õ¼±Èͼ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4.5 ͬԴÐÔ·ÖÎö


ÎÒÃǹ۲쵽ºÃ¶àɱ¶¾Èí¼þ¶ÔDofloo¼Ò×巨ʽÓÐ·ÖÆçµÄ¶¨Ãû·½Ê½ £¬ÉõÖÁ¼ø±ðΪÆäËû¼Ò×åµÄ·¨Ê½ £¬Òò¶øÎªÁËÈ·¶¨Dofloo¼Ò×åµÄÔ´Âë×é³É £¬ÎÒÃÇ¶ÔÆä½øÐÐÁËͬԴÐÔ·ÖÎö¡£


ͨ¹ý¶ÔDofloo½©Ê¬ÍøÂç½øÐÐͬԴÐÔ·ÖÎö £¬·¢ÏÖDofloo½©Ê¬ÍøÂç¼Ò×åͬMr.Black½©Ê¬ÍøÂç¼Ò×å¡¢Flood.AÒÔ¼°DnsAmp½©Ê¬¼Ò×åÓкܸߵÄÀàËÆ¶È¡£Ê×ÏÈ £¬ÎÒÃǶÔMr.Black¼Ò×åÖеĵäÐÍÑù±¾ºÍDofloo¼Ò×åµÄµäÐÍÑù±¾½øÐÐÁ˶ԱÈ £¬·¢ÏÖÕâÁ½¸ö¼Ò×åµÄÕûÌåÁ÷³ÌºÍ²¿ÃÅ´úÂë¸ß¶ÈÀàËÆ £¬ºÃ±ÈÏÂͼÖеÄÉÏÏß»úÔ첿ÃÅ £¬Í¨¹ý¶Ô±ÈÄܹ»¿´µ½ £¬ÉÏÏß°üµÄÄÚÈݺÍÌåʽҲ¼«ÎªÀàËÆ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²¢ÇÒ»¹Äܹ»¿´µ½Mr.BlackͬÑùÓÐͬÃûµÄ £¬ÌáÒéDDoS¹¥»÷µÄº¯ÊýDealWithDDoS £¬ÆäÌáÒé¹¥»÷µÄ½ÚÔìÖ¸Áî±àÂëÒ²Ò»Ñù¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ö»²»ÍâMr.BlackÖнöÓÐ5ÖÖDDoS¹¥»÷·½Ê½¡£Í¨¹ý²éÔÄMr.BlackµÄÔ´Âë £¬·¢ÏÖMr.BlackÔ´ÂëÖв¢Ã»ÓкÚȸºóÃÅÏ̺߳ÍAES¼ÓÃÜ £¬Ã»ÓÐÔ¶¿Ø²¿ÃÅ £¬½öÄÜÌáÒéDDoS¹¥»÷¡£Òò¶ø´§Ä¦DoflooΪ²Î¿¼Mr.Black´úÂë¸ü¸ÄºóµÄ±äÖÖ¡£


¶øºóͨ¹ýFlood.AͬMr.BlackºÍDofloo¼Ò×å½øÐжԱÈ £¬·¢ÏÖFlood.A¼Ò×å½ÏMr.Black¼Ò×åÐÂÔö¡°SynFLood_Message¡±ºÚȸºóÃÅÏß³Ì £¬¡°DealwithDDoS¡±º¯ÊýÖÐÔö³¤Layer7²ãµÄHTTPºéË®¹¥»÷ £¬Ã»ÓÐAES¼ÓÃܺÍÔ¶¿ØÖ°ÄÜ £¬ÓëMr.Black¼Ò×å½ÏΪÀàËÆ,²¿ÃŶԱÈͼÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚDnsAmpÓëDofloo¼Ò×åµÄ¶Ô±ÈÖÐ £¬ÎÒÃÇ·¢ÏÔìä´úÂë²î¾à½Ï´ó £¬µ«ÊÇÖØÒª¹¥»÷´úÂëÒÔ¼°·¨Ê½ÕûÌåÉè¼ÆË¼Â·±ÈÁ¦ÀàËÆ¡£ÔÚDnsAmp¼Ò×åÖÐ £¬Óƾû¯ÒÀÈ»ÊÇͨ¹ýÉèÖá°/etc/rc.d/rc.local¡±À´Î¬³Ö¿ª»ú×ÔÆô £¬²¢ÇÒÔÚÆô¶¯ºóͬDoflooÒ»Ñù £¬»áÊ×ÏÈÈ·¶¨¹ý³ÌµÄΨһÐÔ¡£¶øËüµÄ¹¥»÷Ï̡߳°AttackWorker¡±ÖÐ £¬ÎÒÃÇ·¢ÏÖͬDoflooÒ»ÑùÓµÓÐͬÃûµÄ¹¥»÷º¯Êý¡°DealwithDDoS¡± £¬Ö»²»Íâ½öÓÐ4ÖÖ¹¥»÷·½Ê½ £¬±ðÀëΪudp £¬icmp £¬dnsAmp,syn¹¥»÷¡£¹ÌÈ»DnsAmpÓëDoflooÕûÌå´úÂëÀàËÆ¶È²»ÊÇÌ«¸ß £¬µ«ÊÇÆ¾¾ÝÆäÖØÒª¹¥»÷´úÂëºÍ·¨Ê½ÕûÌåµÄÉè¼ÆË¼Â· £¬ÎÒÃÇ´§Ä¦¶þÕßÓµÓйØÁªÐÔ £¬ÖÁÉÙDnsAmpΪ²Î¿¼Dofloo´úÂë¶ø²úÉúµÄÀàËÆ±äÖÖ¡£²¿ÃŶԱÈͼÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Òò¶ø £¬ÎÒÃÇ´óÌåÄܹ»´§Ä¦³öÈçÏµĹØÏµ£ºMrBlack¿ÉÄÜΪԭʼ¶ñÒⷨʽ £¬Flood.AΪÆä±äÖÖ £¬ÖØÒªÔö³¤µÄÖ°ÄÜÓкóÃźÚȸÏ̺߳ÍHTTPºéË®¹¥»÷£»Dofloo¿ÉÄÜΪMr.Black»òFlood.AµÄ±äÖÖ £¬ÖØÒªÐÂÔöµÄ¸öÐÔÓз¨Ê½Óƾû¯ÉèÖà £¬½ÚÔìÖ¸ÁîAES¼ÓÃÜ £¬ÒÔ¼°Ôö³¤¶àÖÖDDoS¹¥»÷²½Ö裻´§Ä¦DnsAmpΪDoflooµÄ±äÖÖ £¬Ëü²Î¿¼ÁËDoflooµÄ²¿ÃÅ´úÂëºÍÉè¼ÆË¼Â·¡£ÎÒÃÇ×ܽáÆäËÄÕߵĹØÏµÍ¼ÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


5.×Ü ½á


±¾Æª»ã±¨³Áµã¶ÔDofloo½©Ê¬ÍøÂç¼Ò×åÖдæÔڵĺÚȸ¾°Ïó½øÐÐÁË·ÖÎöÅû¶ £¬²¢ËÝÔ´×·×ÙºÚȸ £¬²ú³öºÚȸ»­Ïñ¡£Í¬Ê±¶ÔµäÐ͵Ľ©Ê¬Ñù±¾½øÐÐÁË·ÖÎö £¬ÌáÈ¡×ۺϳöÉÏÏß¡¢ÐÄÌø¡¢½ÚÔìÖ¸ÁîºÍÌáÒé¹¥»÷µÄÁ÷Á¿Ìåʽ¡£


ͬʱ £¬Í¨¹ý¶ÔºÚȸºÍó«òëµÄ·ÖÎö £¬Ö¤ÊµÁ˺Úȸ¹¥»÷Ëù´æÔÚµÄDZÔÚ¾Þ´ó·çÏÕ¡£Ö»¹Ü²¿Ãźڿͳ¢ÊÔÈ¥µôÆäºÚȸÏ̲߳¢³Áд«²¼ £¬µ«¾ø´óÎÞÊýµÄDofloo½©Ê¬Ñù±¾ÒÀÈ»ÁôÓдËÀàºóÃÅ £¬Ò²ÓкڿÍÔÚÈ·ÈϺÚȸIP»òÓòÃûʧЧºó½µµÍÁ˾¯ÌèÐÔ £¬µ«ÊÇÎÒÃÇ·¢ÏÖÓв¿ÃźÚȸÓòÃûÔÚÂñ·üÒ»¶Î¹¦·òºó £¬ÈÔ»áżȻ½âÎöÉÏÏß £¬¶Ôó«òë½øÐÐÒ»²¨ÊոËùÒÔ £¬×ÛºÏÅжϸúÚȸ½©Ê¬×ÊÔ´·á˶¡¢ÊµÁ¦Ç¿º·¡£´Ë±í £¬Í¨¹ý¿í·ºµÄ·ÖÎö·¢ÏÖ £¬ÕâÖÖ¹¥»÷·½Ê½»¹´óÁ¿´æÔÚÓÚÆäËû½©Ê¬·¨Ê½¡¢WEB Sehll¹¥»÷¹¤¾ß¼°È䳿ľÂí¹¥»÷¹¤¾ß £¬Õâ»òÐí±ØÒª¿í´ó°²È«×êÑÐÈËÔ±ºÍ°²È«»ú¹¹¹²Í¬×¢Òâ´ËÀ๥»÷µÄÄ»ºóºÚȸ £¬Æ÷³Á¸ÃÀàÍþв¿ÉÄÜÔì³ÉµÄ¾Þ´ó·çÏÕ £¬ÊµÊ±·¢ÏÖ²¢¶Ï¸ùÒþÄäÓÚÍøÂçÖеÄÒ»´óÍþв¡£


²Î¿¼Îļþ£º


1¡¢DDoS-Capable IoT Malwares: Comparative Analysis and Mirai Investigation

https://www.hindawi.com/journals/scn/2018/7178164/


2¡¢2017 Global botnet DDoS attack threat report

http://www.antiy.net/p/2017-global-botnet-ddos-attack-threat-report


3¡¢Internet Security Threat Report

https://www.insight.com/content/dam/insight-web/en_US/article-images/whitepapers/partner-whitepapers/Internet%20Security%20Threat%20Report.pdf


4¡¢Tango down report of OP China ELF DDoS'er
http://blog.malwaremustdie.org/2014/09/tango-down-report-of-op-china-elf-ddoser.html