• Latest
  • Trending
  • All
Citrix devices are being abused as DDoS attack vectors | ZDNet

Citrix devices are being abused as DDoS attack vectors | ZDNet

December 24, 2020
Pennsylvania Lawmaker Played Key Role in Trump’s Plot to Oust Acting Attorney General

Pennsylvania Lawmaker Played Key Role in Trump’s Plot to Oust Acting Attorney General

January 24, 2021
Pentagon Confirms Protection of Disputed Islands to Japan

Pentagon Confirms Protection of Disputed Islands to Japan

January 24, 2021
What is Conor McGregor’s net worth?

What is Conor McGregor’s net worth?

January 24, 2021
‘We’ve had a good run’: Pineapple Hooper on track for defeat in Rockhampton

‘We’ve had a good run’: Pineapple Hooper on track for defeat in Rockhampton

January 24, 2021
Man Threatened to Assassinate Alexandria Ocasio-Cortez, Officials Say

Man Threatened to Assassinate Alexandria Ocasio-Cortez, Officials Say

January 24, 2021
Saturday Night Owls: Black mayors push police reform

Saturday Night Owls: Black mayors push police reform

January 24, 2021
Coronavirus live news: US nears 25m cases as three infections linked to Australian Open confirmed as UK strain

Coronavirus live news: US nears 25m cases as three infections linked to Australian Open confirmed as UK strain

January 24, 2021
US to reform Trump’s ‘draconian’ immigration regime, Biden tells Mexican president

US to reform Trump’s ‘draconian’ immigration regime, Biden tells Mexican president

January 24, 2021
Ted Thompson, Who Helped Revive the Packers, Is Dead at 68

Ted Thompson, Who Helped Revive the Packers, Is Dead at 68

January 24, 2021
Grand Prairie ISD Removes Newsletter Photo Of Teachers Wearing ‘Chucks & Pearls’ After Complaints From Staff

Grand Prairie ISD Removes Newsletter Photo Of Teachers Wearing ‘Chucks & Pearls’ After Complaints From Staff

January 24, 2021
Tunisians question whether life is better after Arab Spring

Tunisians question whether life is better after Arab Spring

January 24, 2021
U.F.C. 257 Live Updates: Conor McGregor vs. Dustin Poirier

U.F.C. 257 Live Updates: Conor McGregor vs. Dustin Poirier

January 24, 2021
  • Home
  • Privacy Policy
  • Terms & Condition
  • Contact us
Sunday, January 24, 2021
NWS100
  • Home
  • News
    • USA
    • Asia Pacific
    • Middle East
    • Europe
    • Africa
  • Politics
  • Business
  • Technology
  • Health
  • Sports
  • Lifestyle
  • Entertainment
  • Education
  • Travel
No Result
View All Result
NWS100
No Result
View All Result
Home Technology

Citrix devices are being abused as DDoS attack vectors | ZDNet

by news100
December 24, 2020
in Technology
0
Citrix devices are being abused as DDoS attack vectors | ZDNet
493
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Citrix

Images: Citrix // Composition: ZDNet

Threat actors have discovered a way to bounce and amplify junk web traffic against Citrix ADC networking equipment to launch DDoS attacks.

While details about the attackers are still unknown, victims of these Citrix-based DDoS attacks have mostly included online gaming services, such as Steam and Xbox, sources have told ZDNet earlier today.

The first of these attacks have been detected last week and documented by German IT systems administrator Marco Hofmann.

Hofmann tracked the issue to the DTLS interface on Citrix ADC devices.

DTLS, or Datagram Transport Layer Security, is a more version of the TLS protocol implemented on the stream-friendly UDP transfer protocol, rather than the more reliable TCP.

Just like all UDP-based protocols, DTLS is spoofable and can be used as a DDoS amplification vector.

What this means is that attackers can send small DTLS packets to the DTLS-capable device and have the result returned in a many times larger packet to a spoofed IP address (the DDoS attack victim).

How many times the original packet is enlarged determines the amplification factor of a specific protocol. For past DTLS-based DDoS attacks, the amplification factor was usually 4 or 5 times the original packet.

But, on Monday, Hofmann reported that the DTLS implementation on Citrix ADC devices appears to be yielding a whopping 35, making it one of the most potent DDoS amplification vectors.

Citrix confirms issue

Earlier today, after several reports, Citrix has also confirmed the issue and promised to release a fix after the winter holidays, in mid-January 2020.

The company said it’s seen the DDoS attack vector being abused against “a small number of customers around the world.”

The issue is considered dangerous for IT administrators, for costs and uptime-related issues rather than the security of their devices.

As attackers abuse a Citrix ADC device, they might end up exhausting its upstream bandwidth, creating additional costs and blocking legitimate activity from the ADC.

Until Citrix readies officials mitigations, two temporary fixes have emerged.

The first is to disable the Citrix ADC DTLS interface if not used. 

Citrix ADC

If you are impacted by this attack you can disable DTLS to stop it. Disabling the DTLS protocol will lead to limited performance degradation, a short freeze and to a fallback.

Run following CLI command on Citrix ADC: 
set vpn vserver <vpn_vserver_name> -dtls OFF https://t.co/Tpdnp8k9y3

— Thorsten E. (@endi24) December 24, 2020

If the DTLS interface is needed, forcing the device to authenticate incoming DTLS connections is recommended, although it may degrade the device’s performance as a result.

If you are making use of Citrix ADC and have enabled DTLS/EDT (UDP via port 443) you might need to run this command: “set ssl dtlsProfile nsdtls_default_profile -helloVerifyRequest ENABLED”. This will prevent you from future UDP amplification attacks. #NetScaler #CitrixADC

— Anton van Pelt (@AntonvanPelt) December 21, 2020

Actually the vast majority of deploys will become unstable with that. To be safe until January, better block UDP.

— Thorsten Rood (@ThorstenRood) December 22, 2020





Source link

Share197Tweet123Share49
news100

news100

  • Trending
  • Comments
  • Latest
Legendary Twin Cities Sports Journalist Tom Hanneman Dies

Legendary Twin Cities Sports Journalist Tom Hanneman Dies

December 18, 2020
Woman falls to death from high-rise in Dubai’s JLT

Woman falls to death from high-rise in Dubai’s JLT

November 22, 2020
BREAKING UPDATE: Judge Timothy Batten Issues Order to Freeze All Dominion Machines in Georgia!

BREAKING UPDATE: Judge Timothy Batten Issues Order to Freeze All Dominion Machines in Georgia!

November 29, 2020
Georgia Lawsuit: Witness Testifies About Use of Different Paper For ‘Counterfeit’ Ballots, ‘Watermark Solid Grey Instead of Transparent’ – 100% For Joe Biden

Georgia Lawsuit: Witness Testifies About Use of Different Paper For ‘Counterfeit’ Ballots, ‘Watermark Solid Grey Instead of Transparent’ – 100% For Joe Biden

November 26, 2020
Pennsylvania Lawmaker Played Key Role in Trump’s Plot to Oust Acting Attorney General

Pennsylvania Lawmaker Played Key Role in Trump’s Plot to Oust Acting Attorney General

0
Spring Cleaning: The Non-Toxic Way

Spring Cleaning: The Non-Toxic Way

0
8 Easy Ways To Lower Your EMF Exposure

8 Easy Ways To Lower Your EMF Exposure

0
Is Your Sunscreen Doing More Harm Than Good?

Is Your Sunscreen Doing More Harm Than Good?

0
Pennsylvania Lawmaker Played Key Role in Trump’s Plot to Oust Acting Attorney General

Pennsylvania Lawmaker Played Key Role in Trump’s Plot to Oust Acting Attorney General

January 24, 2021
Pentagon Confirms Protection of Disputed Islands to Japan

Pentagon Confirms Protection of Disputed Islands to Japan

January 24, 2021
What is Conor McGregor’s net worth?

What is Conor McGregor’s net worth?

January 24, 2021
‘We’ve had a good run’: Pineapple Hooper on track for defeat in Rockhampton

‘We’ve had a good run’: Pineapple Hooper on track for defeat in Rockhampton

January 24, 2021
https://youtu.be/an34QPraXlA
Resurge
NWS100

https://somarts.org/video-ufc-11.html
https://somarts.org/video-ufc-12.html
http://www.ksvroeselare.be/video-ufc-22.html
http://www.ksvroeselare.be/video-ufc-23.html Copyright © 2020 NEWS100. studycomets.net

All the latest breaking news on News100

  • Home
  • Privacy Policy
  • Terms & Condition
  • Contact us

Follow Us

No Result
View All Result
  • Home
  • News
    • USA
    • Europe
    • Africa
    • Middle East
    • Asia Pacific
  • Politics
  • Business
  • Health
  • Entertainment
  • Technology
  • Education
  • Lifestyle
  • Travel

https://somarts.org/video-ufc-11.html
https://somarts.org/video-ufc-12.html
http://www.ksvroeselare.be/video-ufc-22.html
http://www.ksvroeselare.be/video-ufc-23.html Copyright © 2020 NEWS100. studycomets.net