2003年5月14日起,威斯康星大学麦迪逊分校的公共时间服务器遭到大规模流量泛洪。1数十万台网件品牌路由器因固件缺陷以异常高频率向该服务器发送SNTP时间查询请求。1受影响的IP地址128.105.39.11在24小时内接收了超过50万个来自不同网件设备的查询源。1
经调查发现,网件Platinum系列产品(包括RP614、MR814和DG814等型号)内嵌的SNTP客户端被硬编码为查询该校服务器地址,导致聚合流量超过150Mbps,最高峰值达426Mbps。1这些路由器的代码中还固定了UDP源端口23457,并以单秒间隔轮询该服务器。1共有707,147台受影响产品在泛洪中活跃。1网件公司承认了代码缺陷,并与威斯康星大学合作开发固件升级方案。1
类似的固件缺陷事件也曾发生在其他机构。澳大利亚CSIRO也遭到约85,000台SMC品牌路由器的攻击,产生约每秒2,800个数据包的流量。1针对此类问题,业界探讨了采用BGP任播部署或BGP抑制方案等解决方案,其中后者需要牺牲4,096个IPv4地址。1
Beginning on May 14, 2003, the University of Wisconsin-Madison's public time server faced an unprecedented flood of traffic originating from hundreds of thousands of Netgear routers affected by a critical firmware defect.1 The compromised devices, belonging to the Platinum product line including models RP614, MR814, and DG814, were hardcoded to query the university's server at IP address 128.105.39.11 at unusually frequent intervals.1 The assault generated between 250,000 and 700,000 data packets per second, with aggregate traffic exceeding 150 Mbps and peaking at 426 Mbps.1 Within a single day, over 500,000 unique Netgear source addresses were observed targeting the server.1
The root cause stemmed from a flawed SNTP client embedded in the routers' firmware that was configured to repeatedly poll the university's time service with a fixed UDP source port of 23,457 and single-second polling intervals.1 Netgear acknowledged the code defect and worked with the university to develop a firmware upgrade solution.1 Approximately 707,147 Netgear devices across the Platinum series were affected by this vulnerability.1
A similar incident occurred in Australia, where approximately 85,000 SMC brand routers launched a comparable attack against CSIRO, generating roughly 2,800 packets per second.1 Potential mitigation strategies under consideration included BGP anycast deployment or BGP suppression techniques, though the latter approach would require sacrificing 4,096 IPv4 addresses.1
评论
还没有评论,欢迎留下第一条。