Options

NTP-amplification DoS on game servers

lsud00dlsud00d Member Posts: 1,571
This is pretty crazy...I was reading about the game server attacks a few days ago (affected my beloved LoL! icon_mad.gif) and apparently it was carried out by DerpTrolling with an Ion Cannon (which is a generic DDoS tool) and called it the "Gaben Laser Beam" (after Valve founder Gabe Newell who I met this year at LinuxCON icon_cool.gif)
By manipulating the requests to make them appear as if they originated from one of the gaming sites, the attackers were able to vastly amplify the firepower at their disposal. A spoofed request containing eight bytes will typically result in a 468-byte response to a victim, a more than 58-fold increase.

"Prior to December, an NTP attack was almost unheard of because if there was one it wasn't worth talking about," Shawn Marck, CEO of DoS-mitigation service Black Lotus, told Ars. "It was so tiny it never showed up in the major reports. What we're witnessing is a shift in methodology."

...Correlating claims DERP Trolling made on Twitter with attacks Black Lotus researchers were able to observe, they estimated the attack gang had a maximum capacity of about 28Gbps.

DoS attacks that took down big game sites abused Web
Sign In or Register to comment.