Blacknurse – Low bandwidth ICMP firewall attack
blacknurse.dk
blacknurse.dk
[1] https://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html
Also - PoC is for IPv4; does anyone know if systems fail in a similar manner if ICMP6 Destination Unreachable / Port unreachable (ICMP6 T:3, C:4) is being used? (https://tools.ietf.org/html/rfc4443#section-3.1)
I can only guess that it's a play on "black hat" hacking as opposed to "white hat"[1].
Since ICMP messages are related to network "health" by way of pinging & diagnostics, a good "white nurse" would use that to monitor the health of the patient. However, an evil "black nurse" would use the ICMP protocol against the patient to kill it.
[1]https://en.wikipedia.org/wiki/White_hat_(computer_security)
Well, there are a lot of racist black metal musicians.
Just because you don't see something as problematic doesn't mean that it isn't.
The political correction you ask for is USA-centric. I don’t know if the people behind blacknurse.dk are American, but, if the domain is an indication, they may not be.
The fact is that most sites work only with some kind of caching in front of them at any scale; my guess would be on a site by site basis there will be a slow performing piece of code somewhere that can be exploited with low resources on the part of the attacker.
In a lot of cases, simply creating a session a couple of 100000 in a short enough space of time, would be enough to overload the majority of sites...
We should be geared up to fix stuff like this via quick patching. This stuff shouldn't be terribly surprising. I think the idea of "install and forget" for any internet enabled device is a dangerous line of thinking, especially for firewalls.
Isn't rate limiting a thing anymore? Especially for packets that should not be coming at this rate. 40k-50k pps? Who gets that amount of ICMP type 3 code 4 as a baseline to consider it normal? Also, many networks out there "deprioritize" ICMP packets.
I see how (mainly) Cisco seems to have screwed up on their ASAs, but in all honesty they've never been the paradigm of firewall security. Before the -X line, which is when I was a very active user of ASAs, the interface buffers of almost any ASA up to the 5580 were insufficient for some kinds of traffic that generated high pps with not so huge bandwidth.
Actually, now that I think about it, I wonder if this "Black Nurse" is partly the result of the ASA's insufficient buffers and not just an actual firmware issue.
All in all, this feels very amateurish to me and I'm surprised people are buying into it - I guess doom and gloom sells pageviews. I mean, if their conclusion is the below, I don't see how this is making so much noise:
"We believe,that what we see when our customers get hit by the BlackNurse attack is that the firewall admins have just followed recommendations or misconfigured firewalls. Mitigation on firewalls could be to change default config or to patch any code that can lead to a DoS state."
There's generic name for these attacks: Resource consumption attack.
> Even a single computer can take down big servers using BlackNurse Attack (...) Researchers at TDC Security Operations Center have discovered a new attack technique that lone attackers with limited resources (in this case, a laptop and at least 15Mbps of bandwidth) can use to knock large servers offline. (...)
> By sending a Type 3 ICMP packets with a code of 3, a hacker can cause a Denial of Service (DoS) state by overloading the CPUs of certain types of server firewalls, regardless of the quality of internet connection. The BlackNurse traffic volume is very small, ranging from 15 Mbps to 18 Mbps (or about 40,000 to 50,000 packets per second), which is laughable compared to record-breaking 1.1 Tbps DDoS attack recorded against French Internet service provider OVH in September.
[1]: http://thehackernews.com/2016/11/dos-attack-server-firewall....
All routing would stop, the internet would simply grind to a halt. Am I missing something?
Control plane security overview: http://www.cisco.com/c/en/us/products/collateral/security/io...
Control plane best practices: http://www.cisco.com/c/en/us/about/security-center/copp-best...
Protecting the Router Control Plane: https://tools.ietf.org/html/rfc6192
You'll probably also want to read the Network Security Baseline: http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Se...
More resource exhaustion DoS: TTL expiry attack http://www.cisco.com/c/en/us/about/security-center/ttl-expir...
Troubleshooting high CPU use (on 7500's) http://www.cisco.com/c/en/us/support/docs/routers/7500-serie...
Blocking type 3/3 can also make some other denial of service attacks easier because it takes longer for the server to figure out that the device at that IP doesn't want the packets the server is sending when the request is from a spoofed IP address.
But what about TCP only? AFAIK, TCP RST is usually used when a packet is received with no connection. The only place I'm aware of that uses ICMP 3/3 is the REJECT iptables target when the defaults are used.
Damnit, I'm protected by the glory of FreeBSD-based firewalls.
I still tried anyway, but nothing happened :(
The recommendation is to accept ALL ICMP traffic, from everywhere, to everywhere, whatever it is.
I've wasted too much time debugging tricky network issues because a dude thought that blocking ICMP was a great idea.
ICMP types 3 and 4 should always be allowed.
At your discretion, you may allow other types as well.
Inbound, I allow types 0, 3, 4, 8, and 11, but I'm a network engineer. A paranoid security guy may prefer to block some of those.
hping3 -1 -C 3 -K 3 -i u20 <target ip>
ofc that assumes you have access to hping/hping3. I plan to check my own server as soon as I can.
We recommend that you grant permission for the ICMP unreachable message type (type 3). Denying ICMP unreachable messages disables ICMP Path MTU discovery, which can halt IPsec and PPTP traffic. See RFC 1195 and RFC 1435 for details about Path MTU Discovery