[1] I wish I were joking, but this was verifiably the source of most of the volumetric DDoS I fought at my last job.
[1] I wish I were joking, but this was verifiably the source of most of the volumetric DDoS I fought at my last job.
https://en.wikipedia.org/wiki/Character_Generator_Protocol in case anyone else had never heard of this... um... unfortunate protocol. Works on TCP and UDP, basically "DDoS vector as a service" if I ever saw one (seriously, could you design a better protocol for DDoS?). Just... Who? How? Why!?
The big things these days are:
spoofers who generate a ton of syns to legit destinations which result in a lot of syn+ack to the victim. Bcp38 would help here.
Botnets generating a ton of UDP to destinations. Hosters, cloud providers (especially those with vulnerable/open EMR clusters) and broadband ISPs with easily compromised customers are the problem here. Kudos to those who take down the botnet command and controls.
Memached/ntp/cldap amplifiers. Still out there, still a problem. Thankfully a few of these services are policed at large peering interconnection points.
It's not needed for any application that I've ever heard of.
Why would anyone install this? On an Internet-facing server no less!?
Right behind this, I’ll put cloud providers who helpfully put default 0.0.0.0/0 rules in their firewalls.