The Windows servers that have been fueling DDoSes for months
arstechnica.com
arstechnica.com
The problem is that there is no protocol for rejecting traffic. That's why DDOS is so easy and successful. If you are a website you cannot send a message to uplink saying "I don't want traffic from this network". So small and large ISPs do nothing to help protect victims and make it easy for criminals to extort money.
It also creates a nice DoS vector: if I want to not take an exam today, I'll just do a little ping flood from the school network and get banned for a while. Similar to account locking on 3 invalid attempts, except now you can block everyone at once as soon as you're in the network or on the same ISP.
OTOH, we always had at least 4 webservers, so if just one got blackholed, no big deal, update DNS so most of the real users make it to the available servers, most of the abusers will keep hitting the blackholed server and not move on. If your abusers aren't run of the mill script kiddies using a rent-a-ddos service, it's more difficult.
[1] it's almost always the webservers, not the servers that do real work
For us though, getting one server blackholed every so often wasn't that big of a deal, so as long as everything was managed reasonably, and the ticketing was timely so we didn't spend a lot of time trying to figure out why server X wasn't working when it was just a blackhole from DDoS. A clever abuser could have caused a lot more trouble, but clever people tend to find more productive things to do.
[1] don't blackhole unless the traffic rate exceeds line rate (which topped out at 2x 10G), retest after 1 hour instead of 24 hours for the first retest, etc.
I totally understand what you're saying though.
BTW nice username
You have a nice username as well!
So basically ISP don't want to do anything to prevent misuse of their infrastructure because it is more profitable this way.
> It also creates a nice DoS vector: if I want to not take an exam today, I'll just do a little ping flood from the school network and get banned for a while.
The idea is that you can only block traffic going from school network to your site, but not any other traffic from that network.
So yes, we would still need that protocol.
Sure it's a good idea to allow requesting the blocks. But changing the reflection sources themselves so they can't be used for reflection anymore is also a good idea.
A new protocol only knocks off one head of the hydra, but does not solve the real problem.
"The problem is that the non-exisiting solution doesn't exist" - ok then
Microsoft has just recently made SMB safe for the Internet (Azure File Shares), but that's just one of many protocols on a Domain Controller...
> Microsoft has just recently made SMB safe for the Internet
cifs anyone?
Azure Active Directory has almost nothing in common with Active Directory, other than the name. Amongst other things, it uses HTTPS almost exclusively.
CIFS is an older protocol that Linux admins use incorrectly to refer to SMB, which is the file sharing protocol used by Windows.
Is Linux UNIX?
The enterprise world have a huge problem with it's addiction to legacy Microsoft technology that Microsoft is both aware of but also unable to fully address as their modern stuff just aren't all that competitive without the legacy compatibility. And the "domain controllers" it's at the very core of this problem.
In the unix ecosystem most of the old vulnerable legacy(which was never as bad as windowsNT) is actually dying out but for some reason most of the traditional wintel ecosystem seems to be partying like it's still 1999.
Really and truly the problem is executives not seeing the value in hiring for their actual IT problem space. Too many companies, especially ones that are more physical and have people who like to proudly claim computer ignorance, refuse to admit that with advances in technology that IT is an integral and vital part of the business.
Instead they don't even hire for positions they really need, or if they do, they hire for peanuts and get subpar gui-ninjas... and that's how you end up with a bunch of AD servers on the internet.
If you are talking about how the DC itself gets updates then it has outbound access normally via a proxy server or something like that.
You wouldn't put the DC on the internet that would be really insane.
if you cannot expose the AD server to the public internet, can you then actually use windows in remote first organization?
Those servers have been exposed to the internet because if they weren't the organizations using them would be forced to solve the chicken and egg problem of how to authenticate the users against an authentication server they cannot access without authentication.
I work in this exact type of environment. Your laptop is joined to the domain in office before being sent to you. You can of course logon to the laptop even though it cannot connect to the domain. You just have to connect to the VPN and domain periodically to get gp updates if there is some mandatory software it'll install when you connect. So you connect to the VPN after you logon locally.
You also have to connect to the domain to change your password.
> Those servers have been exposed to the internet because if they weren't the organizations using them would be forced to solve the chicken and egg problem of how to authenticate the users against an authentication server they cannot access without authentication.
No you can logon to a computer with your domain credentials even when it's not connected to the domain.
The internet facing deployment means you have to set up ADFS Web Application Proxy in DMZ that is NOT domain joined and can communicate with domain-joined ADFS service.
ADFS allows plenty of stuff, including 2FA, for example for trusted devices only, which has been registered with ADFS and uses certificate based auth. It allows SSO with online services like Azure, Google Workspace and more.
Edit: Ahh, sorry, the story is about not logging into web apps, but domain joined computer. Credentials are cached on user laptop, so you can login without network (you can prevent credential caching if you will. You should for domain admin accounts). Or you setup always on VPN (DirectAccess or wireguard) so that you always have the connectivity.
I have not done network administration in a very long time, so my suspicion is that many of these domain controllers were set up by not very experienced people with not very intelligent bosses thinking that "it was done once, therefore it is done forever".
They don't. MOre so - they don't even know what they are doing.
NB there are people on the other side of the spectrum - I've met enough Linux fanboys who insisted what they don't need a firewall running on their public machines, because... Linux is safe.
Obviously in a more involved (enterprise) setup a firewall will make sense for several reasons, but on a small server you rent for yourself to run an httpd and let's say an ircd plus ssh, what exactly do you think a firewall does for you?
> but on a small server you rent for yourself
Bwahaha!
But what if I WANT to install software that opens it? Like MongoDB for example? What could be wrong if I just install some MongoDB to run $softwarename, right? Nothing wrong could happen, yes?
Read my comment at [0], I don't want to repeat it here.
Why would it need a firewall running?
Today you setup you shiny new host and you know exactly what is running on it and what ports are open. Some months/years later?
Yes, a single purpose mail server can get by with tcp/22 and tcp/25 for all it's useful life but something more complex?
Or when you don't even know for sure what are defaults are and you 'move fast and break things'? Should I remind you about MongoDB fiasco? [0] Are you sure all your 'internal' services (DBs and whatever) are bound to localhost and not to 0.0.0.0?
Running a firewall in the default drop/whitelist mode (at least for the inbound traffic) protects you against your own mistakes.
Add to this what while you can be an exceptional localhost admin, as soon as you have more than 5 hosts and/or work with other people you can never be sure what every host is properly configured, secured, don't have anything unnecessary running.
[0] https://krebsonsecurity.com/2017/01/extortionists-wipe-thous...
>> If installed on a server with the default settings, for example, MongoDB allows anyone to browse the databases, download them, or even write over them and delete them.
Edit: with a 'deemed safe enough by Gordonjcp@HN' column of course.
Your argument is "software might have unsafe defaults, so you should rely on a piece of software that might have unsafe defaults".
My argument is having an additional layer of protection just in case. Do you wear a helmet only on the days you fall off from your bicycle?
> you should rely on a piece of software that might have unsafe defaults
Well, if you just took the helmet with you but never bothered to wear it...
If you cannot install a server without ensuring you're running what you expect to be running, you've no business running it at all.
It's a skill that everyone should know, if they want to run servers. It's a skill you can acquire by reading some very simple instructions.
Imagine if bridges were designed and built by the fuckwits that created (or indeed use) MongoDB.
The other way in which the analogy is flawed is that I might very well consider myself a perfect cyclist, but that still doesn't protect me from that drunk driver in a SUV shooting out a side alley where I have no chance to react.
A firewall does nothing useful if there's nothing to firewall.
Probably something like "hey, my nephew is a computer nerd, why not hire him instead of $EXPENSIVE_CONSULTING_COMPANY?"
Followed a couple months by: "Why is our internet so slow?" and "why aren't out customers getting our emails?"
Actual article that Ars writes about: https://blog.lumen.com/cldap-reflectors-on-the-rise-despite-...
Actual news (less vague title than Ars'): the number of vulnerable systems has increased ("from the 7K range to over 12K" "over the last 12 months"). Only 15% stays online longer than a year, though, so it seems that most admins catch on after a while. "[T]he Connectionless Lightweight Directory Access Protocol (CLDAP) [has a] Bandwidth Amplification Factor (BAF) of 56 to 70x".
Actionable advice for Windows Server owners is provided at the bottom of both articles.
---
> [heading] A never-ending arms race
Are there still protocols newly put into production that do not take reflection attacks into account? In my experience, it's all legacy. And don't more and more ISPs enforce BCP38 (http://bcp38.info)?
Not sure this headline of Ars' is true.
On a server it's just crazy. Microsoft has thoroughly proven that they have no clue how to make a mail server, remote desktop server or network services that can be safely connected to a public network.
On a PC it's also a privacy nightmare.
Very few businesses think they can do without those. IT history of these 30 last years have kind of segregated sysadmin/architects types. The one focused on internal IT / desktop services solutions are typically more knowledgeable in Microsoft technologies while unix/linux sysadmins usually focus on the non desktop/office related stuff. Despite decent solutions existing without Microsoft, very few people know enough about them to recommend them.
Most emails clients support ldap for contacts with additional carddav server to sync personnal contacts accross devices, Sogo groupware works well for that , add a fairly decent webmail interface and has an outlook connector for easy configuration of microsoft desktops but if you need office 365 functionnalities, Nextcloud would be the way to go imho. It is available as a service too and is cheaper than Microsoft 365. I am not sure how an on premise Nextcloud would scale to huge companies (but enteprise offering say it scales to hundreds of millions of users) but for small businesses it is easy to set up.
I would really like some comparison from administration effort:
1. How easy it is to tie those things together? Like installing that Linux AD server components
2. How easy from deployment POV it is to join computers to network and start using a networked user account?
3. How easy it is to use print server connected to domain?
4. How easy it is for member servers within domain to start accepting SSO connections from those clients/servers?
5. How easy it is to have centralized configuration for linux host and target them? I mean using Linux tools as I suppose linux env won't have gpmc.msc. Let's say you would like all your client hosts, all software to talk TLS1.2+ only.
6. How easy would it be to establish internal certification authority with certificate auto renewal?
I'm aware of paid solutions, but just from marketing material, so no clue how it behaves in real life and how far it goes.
Please don't assume I'm starting flamewars. I just see a great value within Windows AD environment that is easy to set up but as we see from article, takes effort to configure and maintain secure and consistent environment.
My experience with Linux is limited in domain area, and I haven't been familiar with centralized configuration options - I just want to see if it takes 1x/2x/10x effort to do the same in Linux env.
Connecting individual servers / applications to OpenLDAP and Keycloack varies widely though, not all apps has OIDC support but you can put them behind an authenticating proxy like oauth2-proxy.
Can't comment on how easy it would be to join desktops and print servers though as I never did it myself.
There are things that are super easy. For example samba is a real dropin replacement for an AD, you can join windows computer to it very easily. Similarly, the bigger distros all have easy setup to enable joining a linux desktop to an Active Directory for auth.
I have used centralized configuration management tool such as puppet, cfengine, saltstack and ansible for years. I did the exercise of managing desktops with them and it was fairly easy. Hey I even deployed windows servers with foreman and puppet.
But for you it might be a nightmare to have to learn a new domain specific language.
Not particularly for me :) Just seeing value proposition for Windows AD - in Linux world, you have to glue together different and competing things for good or worse IDK, but windows just bring that integrated experience OOTB. But good that there exist options in Linux world. It is probably twice++ the effort to manage Lin along Win desktops, so I see why corps don't bother... because you still have to have those windows boxes. And that translates into MS AD for easy management and vast, better or worse, talent pool. I see Windows corps, where appropriate, deploy Linux Servers within infra, for example webservers as that translates into saving $.
Samba, yeah, it just really works and good that we have it. But it is only a part in corporate management toolbox. Even MS Active Directory is a part in corporate management toolbox as you still need something like InTune to manage endpoint installs, still some parts must be scripted, monitored, etc.
It's still sad that incompetent people get to choose rotten technology - often burning tax payers money (or even religious donations).
In fact, this is considered ancient history nowadays.