ºÚȸ¹¥»÷£ºÉî¶È·ÖÎö²¢ËÝÔ´Dofloo½©Ê¬ÎïÁªÍø±³ºóµÄ¡°ºÚȸ¡±

Ðû²¼Ê±¼ä 2019-05-31


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2019Äê4Ô¿ªÊ¼ £¬¶«É­Æ½Ì¨ADLabÊӲ쵽ConfluenceÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2019-3396±»Dofloo½©Ê¬ÍøÂç¼Ò×åÓÃÓÚ¹¥Õ¼É豸×ÊÔ´ £¬Confluence ÊÇÒ»¸öרҵµÄÆóҵ֪ʶ¹ÜÀíÓëЭͬÈí¼þ £¬³£ÓÃÓÚ¹¹½¨ÆóÒµwiki¡£±¾´Î©¶´ÊÇÓÉÓÚConfluence Server ºÍConfluence DataÖеÄWidget Connector´æÔÚ·þÎñ¶ËÄ£°å×¢È멶´ £¬¹¥»÷Õ߽ṹÌض¨ÇëÇó¿ÉÔ¶³Ì±éÀú·þÎñÆ÷ÈÎÒâÎļþ £¬ÉõÖÁʵÏÖÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£ÓÐÒâ˼µÄÊÇDofloo½©Ê¬ÍøÂç¼Ò×å²»½ö¿ªÊ¼ÀûÓøßΣ©¶´½øÐй¥»÷ £¬¶øÇÒÆä±³ºóµÄºÚ¿Í»¹ÀûÓÃÒ»ÖÖ¸ü¾ßÓ°ÏìÁ¦µÄ¡°ºÚȸ¹¥»÷¡±À´ÈëÇÖ¹¤ÒµÁ´ £¬ÒÔÕÆ¿ØÔ½·¢Ç¿´óµÄÍøÂç¹¥»÷×ÊÔ´¡£¶øÔÚ´ËÇ° £¬ÎÒÃÇÒѾ­×öÁ˳¤Ê±¼äµÄÓëDofloo½©Ê¬¼Ò×åºÚ¿Í¹¤ÒµÁ´Ïà¹ØµÄÑо¿ £¬ÇÒÒѾ­È·¶¨ÁËÕâÖÖÆÕ±é´æÔÚÓÚDofloo¼Ò×åÖеġ°ºÚȸ¹¥»÷ÏÖÏó¡± £¬²¢¶ÔÆäÖеġ°ºÚȸ¡±½øÐÐÁ˺ã¾Ã×·×ÙÓë·ÖÎö¡£


´Ë´¦ £¬ÎÒÃÇËùÌá³ö¡°ºÚȸ¹¥»÷¡±²»½öÊÇÒ»ÖÖ¸ßЧµÄºÚ¿Í¹¥»÷ÊֶΠ£¬¶øÇÒ¸üÊÇÒ»ÖÖ¹¤ÒµÁ´¼¶´ËÍâ¹¥»÷ÒªÁì £¬Ò»°ãΪºÚÉ«¹¤ÒµÁ´ÉÏÓκڿÍËùΪ¡£ºÚȸ¹¥»÷Ó빩ӦÁ´¹¥»÷ÓÐÒìÇúͬ¹¤Ö®Ãî £¬Ö»Êǹ¥»÷µÄÄ¿±ê²»ÊÇͨÀýµÄ¹¤ÒµÁ´ £¬¶øÊǺڿ͹¤ÒµÁ´£»Êܹ¥»÷Á´µÄÄ©¶ËÒ²²»ÊÇÆÕͨÓû§ £¬¶øÊǼ«¾ßΣº¦ÐԵĺڿÍȺÌå¡£ÔÚÍøÂçÄþ¾²ÓëºÚ¿Í¹¤ÒµÁ´µÄºã¾Ã·´¿¹ £¬Ê¹µÃ¸Ã¹¤ÒµÁ´ÈÕ½¥³ÉÊìÇÒÅÓ´ó £¬²¢ÐγÉÁËÒ»¸öÅÓ´óµÄºÚ¿ÍÉú̬ϵͳ £¬¶øÔÚÀûÒæºÍÉú´æÐèÇóµÄÇýʹÏ £¬ºÚȸÏÖÏóËƺõÄð³ÉÁËÒ»¶¨ £¬ÉõÖÁÔÚʳÎïÁ´µÄÉ϶˽ø»¯³öÁ˺ÚȸÉú̬ £¬ÈçDeath½©Ê¬ÍøÂçµÄ¡°´óºÚȸ-ºÚȸ-ó«ò롱¡£


×Ô¶«É­Æ½Ì¨ADLabÓÚ2016Äê³õ·¢ÏÖºÚȸ¹¥»÷²¢ÓÚ2017Äê1ÔÂÐû²¼¡¶ºÚȸ¹¥»÷-½ÒÃØDeath½©Ê¬ÍøÂç±³ºóµÄÖÕ¼«¿ØÖÆÕß¡·Ö®ºó £¬»¹Ïà¼ÌÔÚ¶à¸ö¶ñÒâ´úÂë¼Ò×åÖз¢ÏÖÁ˺Úȸ¹¥»÷ £¬²¢Ðû²¼ÁËÉî¶È·ÖÎö³ÂËß¡¶½ÒÃØBillgates½©Ê¬ÍøÂçÖеĺÚȸÏÖÏ󡷺͡¶ºÚȸ¹¥»÷£º½ÒÃØTF½©Ê¬ÎïÁªÍøºÚ¿Í±³ºóµÄºÚ¿Í¡·¡£ÔÚ´ËÇ°µÄºÚȸ·ÖÎöºÍ×·×ÙÖÐ £¬ÎÒÃǽÒ¶ÁËDeath½©Ê¬ÍøÂç±³ºóµÄÄǸö¿ØÖÆ×ÅÉÏǧ½©Ê¬×ÓÍøÂçµÄ³¬¼¶ºÚ¿Í £¬ÒÔ¼°Éî²ØÔÚBillgates½©Ê¬ÍøÂçºÍÎïÁªÍø½©Ê¬DDoSTF¼Ò×å±³ºóµÄºÚȸ¡£´ËÍâÎÒÃÇ»¹ÏêϸÂÛÊöÁËÿ¸ö¼Ò×åÖС°ºÚȸ¹¥»÷¡±µÄºÚ¿ÍÌõÀí½á¹¹ £¬ÈçDeath½©Ê¬ÍøÂçµÄÈý¼¶ºÚ¿Í½á¹¹(´óºÚȸ-ºÚȸ-ó«òë) £¬BillgatesºÍTFµÄ¶þ¼¶ºÚ¿Í½á¹¹£¨ºÚȸ-ó«ò룩 £¬ÒÔ¼°¶ÔÏà¹ØµÄ´óºÚȸ¡¢ºÚȸºÍó«òë½øÐÐÁËÍøÂçÐÐΪ·ÖÎöºÍÉí·Ýʶ±ð £¬²¢×öÁ˾«×¼µÄºÚ¿Í»­Ïñ¡£


¶ø±¾ÎĽ«»áÏêϸÂÛÊöºÚȸ¹¥»÷µÄ×îз¢ÏÖ¹ý³Ì £¬ÒÔ¼°Dofloo½©Ê¬ÍøÂç¼Ò×åÖÐËù´æÔڵġ°ºÚȸÏÖÏ󡱡£Í¨¹ý¶Ô¼Ò×å½øÐÐÈ«ÃæµÄ·ÖÎö»¹·¢ÏÖ £¬¸Ã½©Ê¬¼Ò×åµÄ×÷ÕßÔÚÖƽ©Ê¬¹ý³ÌÖоÍÁôÓкÚȸµÄ½Ó¿Ú £¬ËäÈ»ÉÙÁ¿¾«Ã÷µÄºÚ¿Í·¢ÏÖÁ˸ýӿڲ¢½øÐÐÁËÇå³ý £¬µ«ÊÇ´ó²¿ÃŵĺڿͳÉΪ±»¹¥»÷¹¤¾ß £¬±»Ö²ÈëÁ˺ÚȸºóÃÅ¡£±¾ÎÄÖÐÎÒÃÇ»¹»á¶ÔDofloo½©Ê¬ÍøÂç±³ºóµÄºÚȸ½øÐÐÉî¶ÈÍÚ¾òºÍ¶¨Î» £¬²¢·ÖÎö¸Ã¼Ò×åÓëÏàËƽ©Ê¬¼Ò×åMrBlack¡¢DnsAmp¡¢Flood.AÖ®¼äµÄͬԴÌØÐÔ¡£


1.Dofloo½©Ê¬¼Ò×å¼ò½é


Dofloo £¬ÓÖÃûSpikeºÍAES.DDoS £¬ÊÇÒ»¿îÖ§³ÖARM¡¢x86¡¢mipsdµÈ¶àCPU¼Ü¹¹µÄ½©Ê¬ÍøÂ編ʽ¡£Dofloo¼Ò×åÒò2014ÄêÕë¶Ô±±ÃÀÖÞºÍÑÇÖÞ¶à¸ö¹ú¼Ò½øÐиߴï215GbpsÁ÷Á¿µÄ¹¥»÷¶ø×ÅÃû £¬½ñºóºã¾ÃµÄ¹¥Õ¼ÎïÁªÍøÉ豸×ÊÔ´²¢Æµ·±µØ½øÐÐÍøÂç¹¥»÷»î¶¯¡£Æ¾¾ÝÈüÃÅÌú¿ËÔÚ2016ÄêÐû²¼µÄ¡¶Internet Security Thread Report¡· £¬Dofloo½©Ê¬ÍøÂç¶ñÒⷨʽλÁÐ2015Äê¶ÈIoTÁìÓò¶ñÒⷨʽÍþвÅÅÐаñµÚ¶þÃû¡£


´ËÍâ £¬Dofloo»¹ÔÚ2016Äê9ÔÂͬMirai½©Ê¬Ò»Æð¼ÓÈëÁËÔƼÆË㹫˾OVHµÄ¹¥»÷ £¬±¾´Î¹¥»÷µÄÁ÷Á¿Áè¼ÝÁË1Tbps £¬´´ÏÂÁËÂþÑÜʽ¾Ü¾ø·þÎñ¹¥»÷µÄÀúÊ·¼Ç¼ £¬¶øͬÄêµÄ10ÔÂÔٴμÓÈëÁËMiarai½©Ê¬Ö÷µ¼µÄ¶ÔÓòÃû·þÎñÉÌDynµÄ´ó¹æÄ£DDoS¹¥»÷ £¬ÖÂʹÕû¸öÃÀ¹ú¶«º£°¶µÄÍøÂç´¦ÓÚ¼«¶È̱»¾µÄ״̬¡£2019ÄêµÄ4¿ªÊ¼ÀûÓÃ×îÐÂÅû¶µÄÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2019-3396½øÐдóÃæ»ýÁ÷´« £¬¹¥Õ¼ÁËÏ൱ÊýÁ¿µÄÍøÂçÉ豸¡£ÏÂͼÊÇÎÒÃÇƾ¾ÝDofloo½©Ê¬ÍøÂçËùʵʩµÄ±ÈÁ¦ÖØÒªµÄ¹¥»÷ʼþËù»æÖƵĹ¥»÷Àúʷͼ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2.·¢ÏÖDofloo½©Ê¬ÖеĺÚȸ


ÔÚºã¾ÃµÄ¶Ô½©Ê¬ÍøÂçµÄÑо¿ÖÐ £¬DoflooÒ»Ö±ÊÇÎÒÃǼà¿ØµÄ¹¤¾ß¡£ÔÚ֮ǰµÄÑо¿ÖÐ £¬Í¨¹ý×Ô¶¯»¯·ÖÎö¸Ã¼Ò×åµÄ¹ØÁªÑù±¾ £¬·¢ÏָüÒ×åµÄ´ó²¿ÃÅÑù±¾¶¼ÊÐÆô¶¯Á½¸öÐµĹ¥»÷Ïß³Ì £¬²¢·¢ÏÖÕâÁ½¸öÏ̴߳æÔÚÒì³£ÐÐΪ¡£È磺²»½ö»áÉèÖÃÑÓ³ÙÆô¶¯Ïß³Ì £¬»¹»áʵÑé¸úÁíÒ»¸öC&C¿ØÖƶ˽øÐÐÁ¬½ÓͨÐÅ¡£Òò´Ë £¬ÎÒÃǶÔÕâЩÑù±¾½øÐÐÁ˽øÒ»²½µÄ·ÖÎö £¬×îÖÕÈ·¶¨¸Ã½©Ê¬Éú̬Öб»Ö²ÈëÁ˺Úȸ¡£


Õë¶ÔÎÒÃÇÊÕ¼¯µ½µÄ1200¸ö½©Ê¬Ñù±¾ £¬»æÖÆÑù±¾µÄÉÏÏßƵ¶ÈÕ¼ºÃ±ÈÏ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´ÓÉÏͼ¿ÉÒÔ¿´³ö £¬ÓÐÈý¸öµØÖ·µÄÉÏÏßƵ¶ÈÔ¶¸ßÓÚÆäËûµÄC&C¡£½áºÏÑùÌìÖ°Îö·¢ÏÖ £¬ÉÏÏßµ½ÕâÈý¸öC&CµØÖ·µÄÑù±¾¼¸ºõ¶¼ÓÐÁ½¸ö¶ÀÁ¢¿ØÖƵÄC&C £¬¶øÇÒ½©Ê¬»ØÁ¬ÕâÈý¸öC&CµØÖ·¶¼ÊÇͨ¹ý´´½¨×ÓÏ̵߳ķ½Ê½½øÐÐ £¬¶øÆä¹ØÁªµÄÑù±¾µÄÁíÍâÒ»¸öC&CÈ´ÊÇÔÚÖ÷Ïß³ÌÖнøÐлØÁ¬¡£Òò´Ë £¬Í¨¹ý¸Ã½©Ê¬µÄÕ⼸¸öÌØÐÔ¿ÉÒԶ϶¨ÆäÖп϶¨´æÔÚºÚȸ¹¥»÷µÄÏÖÏó £¬¶øÕâÈý¸öC&CµØÖ·±ãÊÇDofloo½©Ê¬Éú̬ÖеĺÚȸC&CµØÖ· £¬ÓëºÚȸC&CµØÖ·Ïà¹ØÁªµÄÆäËûC&CµØÖ·±ãÊÇDofloo½©Ê¬Éú̬ÖÐó«òëºÚ¿ÍµÄC&CµØÖ·¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÎÒÃǶÔÕâÈý¸öºÚȸC&CµØÖ·Ïà¹ØÁªµÄó«òëC&C×öÁË·ÖÀàͳ¼Æ £¬ÈçϱíËùʾ£º


C&CµØÖ·

ó«ò뽩ʬÍøÂçÊýÁ¿

183.60.149.199

189

118.193.217.144

282

aaa.tfddos.net

85


¿É¼û £¬ºÚȸC&C 118.193.217.144ÕÆ¿ØÁË×î¶àµÄó«ò뽩ʬÍøÂç £¬ÔÚ½ñºóµÄ·ÖÎöÖÐ £¬Í¨¹ýËÝÔ´È·¶¨ÁËÕâÈý¸öºÚȸC&CÊÜͬһ¸öºÚ¿Í¿ØÖÆ¡£


3.Dofloo½©Ê¬ºÚȸËÝÔ´Óë»­Ïñ


ͨ¹ý¶ÔÑù±¾µÄ·ÖÎö £¬½áºÏÑù±¾Öеĺ¯ÊýÃüÃûÏ°¹ß¡¢¹¥»÷Á÷Á¿ÌØÕ÷¡¢±äÖÖÔ´Âë×¢ÊÍÒÔ¼°Ñù±¾·¢×÷Á÷´«Ê±ÓÃÀ´É¢²¥Ñù±¾µÄHFSÃæ°åÓïÑÔµÈÌØÕ÷ £¬ÎÒÃÇÅж¨¸Ã¼Ò×åÓɹúÄڵĺڿͱàд¡£ÓÚÊÇÎÒÃÇËÝÔ´Ä¿±êËø¶¨ÔÚ¹úÄÚ £¬Í¨¹ý¶ÔºÚȸÓòÃû¡°aaa.tfddos.net¡±ÖÐÒªº¦ÐÅÏ¢¡±tfddos¡± £¬ÎÒÃǹØÁªµ½Ò»¿îÃûΪ¡°Ì¨·çDDoS¡±µÄ½©Ê¬Èí¼þ¡£¶øÇÒͨ¹ý½øÒ»²½·ÖÎö·¢ÏÖ £¬¸Ã½©Ê¬Èí¼þµÄÄ£°åÑù±¾ÓëDofloo½©Ê¬¾ßÓм«ÎªÏàËƵÄÐÐΪºÍÍøÂçÌØÐÔ¡£´ËÍâ £¬¡°Ì¨·çDDoS¡±Ôںڿͼä»îÔ¾µÄʱ¼äͬDofloo·¢×÷ʱ¼ä¾ùÔÚ2014Äꡣƾ¾ÝÒÔÉÏһϵÁеÄÖ¤¾ÝÖ¤Ã÷ËûÃÇÖ®¼ä´æÔÚÒ»¶¨Í¬Ô´ÐÔ¡£ÎªÁ˽øÒ»²½È·ÈÏËûÃÇΪͬһ¿î½©Ê¬·¨Ê½ £¬ÎÒÃÇ»¹ÀûÓÃbindiff¶Ô¡°Ì¨·çDDoS¡±¿ØÖƶËÉú³ÉµÄ½©Ê¬ÓëDoflooµÄÑù±¾½øÐÐÁËÏàËƶȱȶÔ £¬·¢ÏÖÁ½Õß´úÂëÏàËƶÈΪ100%µÄ´úÂëÕ¼±ÈÁè¼Ý98% £¬Òò´Ë¿ÉÒÔÈ·¶¨¡°Ì¨·çDDoS¡±±ãÊÇDofloo¼Ò×åµÄÒ»¸öÖ÷¿Ø¡£¶Ô±ÈͼÈçÏ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý¶ÔÔçÆڵġ°Ì¨·çDDoS¡±µÄ½©Ê¬Ä£°å·¨Ê½·ÖÎö·¢ÏÖÓëDoflooºÚȸC&CÏàͬµÄºóÃÅC&C£º183.60.149.199¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´ËÍâ £¬Í¨¹ý¶Ô¡°Ì¨·çDDoS¡±µÄËÝÔ´·¢ÏÖ £¬ÆäÔøÔÚÍøÕ¾tfddos.comÉÏ×÷Ϊ¹Ù·½Èí¼þ±»¹ûÈ»ÊÛÂô £¬¸ÃÍøÕ¾ËäÈ»½ÓÄÉÁËÓëDoflooºÚȸÓòÃû¡°aaa.tfddos.net¡±·×ÆçÑùµÄÓòÃû £¬µ«ËûÃǶ¼Ê¹ÓÃÁË¡°tfddos¡±×÷ΪÓòÃûµÄÒªº¦×Ö £¬Ò²¼´ÊÇ¡°tai£¨Ì¨£© feng£¨·ç£© ddos¡±¡£Òò¶øÎÒÃÇÈÏΪºóÃÅC&C£º183.60.149.199Óëaaa.tfddos.netΪͬһºÚ¿Í»òÕߺڿÍ×éÖ¯ËùΪ¡£


¶ÔÓÚºÚȸIP£º118.193.217.144µÄ·´²é·¢ÏÖ £¬ÔÚ2017Äê £¬ÓòÃûwap.tfddos.netºÍaaa.tfddos.netÓë¸ÃIPµØÖ·½øÐÐÁ˺ã¾ÃµÄ°ó¶¨¡£


´ÓÒÔÉÏ·ÖÎö¿ÉÒÔ¿´³öÈý¸öºÚȸC&C£¨183.60.149.199¡¢118.193.217.144¡¢aaa.tfddos.net£©ÊµÔòΪͬһ¸öºÚ¿Í»òÕߺڿÍ×éÖ¯Ëù¿ØÖÆ¡£ÎªÁ˸üÇåÎúµÄÃèÊöÕâЩIPºÍÓòÃûÖ®¼äµÄÁªÏµ £¬×ܽá³ö¹ØϵͼÈçÏ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ΪÁË×·×ÙDofloo½©Ê¬ÍøÂç±³ºóµÄºÚȸ £¬ÎÒÃÇÏÈÊÕ¼¯ÁËC&CÏà¹ØµÄÐÅÏ¢²¢½øÐÐÁË·ÖÎö¡£ÆäÖÐͨ¹ýIP£º183.60.149.199¹ØÁª³öÀ´µÄÏà¹ØÓòÃû´ó²¿Ãű»×÷ΪɫÇéÍøÕ¾»ò²©²ÊÍøվʹÓà £¬²¢ÎÞ¿ÉÓÃÏßË÷¡£¶øtfddos.comºÍtfddos.net¶¼½ÓÄÉÒþ˽±£»¤·½°¸ £¬ÎÞ·¨½øÐнøÒ»²½µÄ×·ËÝ¡£


ÐÒÔ˵ÄÊÇÎÒÃÇÔÚ¡°Ì¨·çDDoS¡±µÄÊÛÂôÀúÊ·¼Ç¼Öз¢ÏÖÒ»ÆðÆÛթʼþ £¬Ê¼þÖÐһλ¹ºÖÃÕßÅû¶ÁË··ÂôÈËÔ±µÄQQºÅÂëºÍÖ§¸¶±¦Õ˺Å¡£Í¨¹ý½øÒ»²½·ÖÎö £¬ÎÒÃÇ×îºóÈ·ÈÏÁ˸÷·ÂôÈËÔ±µÄQQ±ãÊÇ¡°Ì¨·çDDoS¡±¿ª·¢ÕßµÄÊÂʵ¡£´ËÍâÎÒÃÇ»¹Í¨¹ý¸ÃQQµÄ¹ØÁªÐÅÏ¢ÊÕ¼¯µ½¸ÃÈËÔ±ÓжàÄêºÚ²ú´ÓÒµÀúÊ·£ºÈçÆä´Ó2011Ä꿪ʼ±àдDDoSÈí¼þ £¬²¢´´½¨¡°Ì¨·çÊÂÇéÊÒ¡±£»Í¬Ê±Æ仹´ÓÊÂÓëDDoSÏà¹ØµÄºÚ¹¤ÒµÎñ £¬²¢Í¨¹ý··Âô¶ñÒâ¹¥»÷Èí¼þºÍ·¢¶¯DDoS¹¥»÷À´Ä±È¡·Ç·¨ÊÕÒæ¡£¶ø´ËºÚ¿Í±ãÊÇÎÒÒªËÝÔ´µÄDofloo½©Ê¬ÍøÂç±³ºóµÄºÚȸ,Æä³ýÁË¿ª·¢ÓС°Ì¨·çDDoS¡±½©Ê¬Èí¼þÍâ £¬»¹¿ª·¢¶à¿îDDoS¹¥»÷¹¤¾ßÈ磺ѪÐÈDDoS¡¢²Ð±©DDoSºÍ±©ÓêDDoSµÈ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý½ñºóºã¾ÃµÄËÝÔ´·ÖÎö £¬ÎÒÃÇ»¹×·×Ùµ½Á˸úÚȸÔÚÏÖʵÊÀ½çÖеÄÉí·ÝÐÅÏ¢¡£´ËºÚȸÊǺÓÄÏÄÏÑôÁ½¼Ò¿Æ¼¼¹«Ë¾µÄ¼àÊ £¬¶øÇÒÒÔ80ÍòÔªÈϽÉ×ʽð³ÖÓÐÆäÖÐÒ»¼Ò¿Æ¼¼¹«Ë¾10%µÄ¹É·Ý £¬±³µØÀï´Óʺڲú»î¶¯¡£


ÒÀ¾ÝÎÒÃǶÔÑùÌìÖ°ÎöºÍËÝÔ´»ñÈ¡µ½µÄÐÅÏ¢ £¬ÕûÀíºÍ¹éÄɺó £¬×ܽᲢ»æÖƳöºÚȸµÄ»­ÏñÈçÏ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4.Dofloo½©Ê¬µäÐÍÑùÌìÖ°Îö


ÓÉÓÚDoflooÖ§³Ö¶àÖÖCPU¼Ü¹¹ £¬ÎÒÃÇÔÚ¶ÔÕâЩƽ̨µÄÑùÌìÖ°ÎöÖз¢ÏÖ £¬ËùÓÐDoflooÖ§³ÖµÄ¼Ü¹¹ £¬¶¼´æÔÚºÚȸÏÖÏó¡£µ«Êǽ©Ê¬×÷Õ߶ԲîÒìµÄ¼Ü¹¹µÄºÚȸC&C´¦ÖÃÂÔÓвîÒì £¬Õâ¶Ô×Ô¶¯»¯·ÖÎöÒ²Ôì³ÉÁËÒ»¶¨µÄÓ°Ïì¡£ÎÒÃǶԱ¾´ÎÊÕ¼¯µÄ¹²¼Æ1200¸öÑù±¾µÄ¼Ü¹¹ËùÕ¼±ÈÀý½øÐÐÁËͳ¼Æ £¬»æÖƳÉͼÈçÏ£º
 
¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

CPU¼Ü¹¹µÄÂþÑÜͼ £¬Ò»¶¨Ë®Æ½ÉÏҲ˵Ã÷Á˸üÒ×åÈëÇÖÉ豸ÀàÐ͵ÄÂþÑÜ £¬¿ÉÒÔ¿´µ½ARMÉ豸µÄ±ÈÀý·Ç³£¸ß £¬ÕâҲ˵Ã÷ARMϵÄÉ豸Êܵ½ºÚȸ¿ØÖƵıÈÀý±ÈÁ¦¸ß¡£


½ÓÏÂÀ´ÎÒÃǶÔDofloo¼Ò×åµÄµäÐÍÑù±¾½øÐÐÁËÏêϸµÄÆÊÎö £¬¶øÇÒƾ¾Ý´óÁ¿Ñù±¾ÌáÈ¡¹éÄɳöµäÐ͵ÄͨѶÁ÷Á¿ºÍ¹¥»÷Á÷Á¿ÌØÕ÷,²¢¶ÔDofloo¼Ò×å½øÐÐÁËͬԴÐÔ·ÖÎö¡£


4.1 °²×°»úÖÆ


Dofloo½©Ê¬·¨Ê½µÄ°²×°»úÖÆÓУº½©Ê¬·¨Ê½ÔÚËÞÖ÷»úµÄ³Ö¾Ã»¯ÉèÖᢽø³ÌΨһÐÔÅжϺÍÊØ»¤½ø³ÌÉèÖá£


½©Ê¬·¨Ê½Í¨¹ýдÈ뿪»ú×ÔÆôÃüÁîʵÏֳ־û¯¡£½©Ê¬·¨Ê½ÔÚÆô¶¯ºó £¬»áÊ×Ïȼì²éÆô¶¯µÄÃüÁîÐвÎÊý, Èç¹û·¢ÏÖûÓвÎÊý £¬ÄÇô¶ñÒⷨʽ»áĬÈÏÊÇÔÚ¸ÃÉ豸µÄµÚÒ»´ÎÔËÐÐ,´Ëʱ»áµ÷Óá°autoboot¡±º¯Êý¡£Ôڸú¯ÊýÖÐ £¬µ÷Óá°system¡±º¯ÊýÖ´ÐÐϱíÖеÄÃüÁî £¬ÒÔÈ·±£¶ñÒⷨʽÔÚ¸ÃÉ豸ÖØÆôºóÈÔÄܹ»Æô¶¯ÔËÐС£ÕâÒ²ÊÇDofloo¶ñÒⷨʽÔÚËÞÖ÷É豸ʵÏֳ־û¯µÄΨһҪÁì¡£


sed -i -e '/exit/d'  /etc/rc.local
sed -i -e '/^\r\n|\r|\n$/d' /etc/rc.local
sed -i -e '/%s/d' /etc/rc.local
sed -i -e '2 i%s/%s' /etc/rc.local
sed -i -e '2 i%s/%s start'  /etc/rc.d/rc.local

sed -i -e '2 i%s/%s start'  /etc/init.d/boot.local


½©Ê¬·¨Ê½Í¨¹ý¶Ô±ÈϵͳÖÐÔËÐеĽø³ÌÃûÀ´È·±£ÔËÐнø³ÌµÄΨһÐÔ £¬²¢µ÷ÓÃforkº¯Êý´´½¨ÊØ»¤½ø³Ì¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4.2 ÉÏÏß»úÖÆ


ÔÚ°²×°»úÖÆÉèÖÃÍê±Ïºó £¬½©Ê¬·¨Ê½Óë¿ØÖƶËC&C½øÐÐÁ¬½Ó¡£´Ëʱ¶ñÒⷨʽ»áÊÕ¼¯±»ÈëÇÖÉ豸µÄϵͳÐÅÏ¢ £¬²¢°ÑÕâЩÐÅÏ¢×÷ΪÉÏÏß°üµÄÄÚÈÝ·¢Ë͵½¿ØÖƶ˴¦¡£Õâ¸öÉÏÏß°üµÄÄÚÈÝ°üÂÞÄں˰汾¡¢CPUƵÂÊ¡¢×ÜÄÚ´æ¾Þϸ¡¢Íø¿Ú´ø¿íÒÔ¼°Ò»Ð©Ó²±àÂë×Ö·û´® £¬ºÃ±È¡°VERSONEX¡±ºÍ´óÁ¿Ñù±¾ÖзºÆðµÄ¡°Hacker¡±¡£ÔÚºÚȸµÄÏß³ÌÖÐ £¬ÆäÉÏÏß»úÖƵÄÖ÷Ì幦ЧÓëó«òëÏ̴߳¦µÄ¹¦Ð§ÏàËƶȼ«¸ß¡£²îÒìµÄÊÇ £¬ºÚȸÏ̻߳áÑÓ³Ù15СʱºÍ40·ÖÖÓÉÏÏß £¬ÕâÍùÍù»áÃÔ»ó·ÖÎöÈËÔ±²¢¿ÉÄÜÌÓ±Ü×Ô¶¯»¯É³ÏäµÄ¼ì²â £¬Ê¹µÃºÚȸC&CÒþÄäÔÚ´óÁ¿µÄÇëÇóÖÐ £¬¼õÉÙ±»·¢ÏֵĿÉÄÜ¡£Í¨¹ý¶Ô´óÁ¿Ñù±¾µÄ·ÖÎö £¬ÎÒÃÇ·¢ÏÖÉÏÏß°üµÄÀι̾ÞϸΪ0x400×Ö½Ú £¬²¢¶ÔÉÏÏß°ü¸ñʽ½âÎö¡¢ÌáÈ¡ºó¹éÄÉÕûÀí³öÕæʵµÄÊý¾Ý½á¹¹ £¬ÆäÔÚÄÚ´æÖеÄÂþÑÜÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4.3 ÐÄÌø»úÖÆ


½©Ê¬·¨Ê½ÔÚSendInfoÏß³ÌʵÏÖÁË×ÔÉíµÄÐÄÌø»úÖÆ¡£Õâ¸öÏ̵߳ÄÖ÷Òª¹¦Ð§ÊÇÏòó«òë¿ØÖƶ˺ͺÚȸ¿ØÖƶ˷¢ËÍÐÄÌø°ü £¬ÐÄÌø°üÄÚÈÝ°üÂÞµ±Ç°CPUʹÓÃÂʺÍÍøÂçËÙ¶ÈÐÅÏ¢ £¬Í¨¹ýÒÔÏÂ2¸ö²½Öè»ñÈ¡µ½ÕâЩÄÚÈÝ£º


£¨1£© ¼ì²é¡°eth0¡±µ½¡°eth9¡±·¶Î§ÄÚÒÔÌ«Íø¿ÚµÄifconfigÐÅÏ¢¡£²¢Í¨¹ý¶ÁÈ¡/proc/net/dev Ŀ¼ÐÅÏ¢À´¼ÆËãÍøÂçËÙÂÊ¡£


£¨2£©Í¨¹ý¶ÁÈ¡/proc/statĿ¼ÏµÄÐÅÏ¢ £¬»ñÈ¡cpuÊýÁ¿ £¬¼ÆËãÕ¼ÓðٷֱÈ¡£


¾­¹ýÖ¸¶¨¸ñʽƴ½Óºó £¬»áÑ­»·²»Í£µÄ·¢ËÍÐÅÏ¢µ½C&C¶Ë¡£ÏÂͼΪ·¢Ë͵ÄÐÄÌø°üÐÅÏ¢£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±ÈÁ¦ÓÐȤµÄÊÇ £¬ÏÂÓεĺڿÍÔÚ·¢¶¯DDoS¹¥»÷µÄʱºò £¬¿ÉÄÜ»ù´¡²»»áÏëµ½ £¬Ö÷¿ØÖÐÏÔʾµÄ¶ñÒⷨʽµÄ¹¥»÷Á÷Á¿ËÙÂʼ¸ºõ¶¼ÊÇαÔìµÄ¡£ÎÒÃÇÔÚSendInfoÏß³ÌÖз¢ÏÖ £¬µ±¶ñÒⷨʽִÐÐDDoS¹¥»÷ʱ £¬»áµ÷Óá°fake_net_speed¡±º¯Êý £¬¸Ãº¯Êý»áƾ¾Ý²îÒìµÄDDoS¹¥»÷µÄģʽ £¬ÔÚÒ»¸öÀι̵ķ¶Î§ÄÚαÔì¹¥»÷Á÷Á¿ËÙÂÊ¡£ÏÂͼΪ¶Ô²¿ÃżÆËãËæ»úÁ÷Á¿µÄ½Øͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½©Ê¬·¨Ê½Î±ÔìµÄ¹¥»÷Á÷Á¿Êý¾Ý·¶Î§ÈçϱíËùʾ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4.4 ¿ØÖÆÖ¸Áî½âÎöÓëDDoS¹¥»÷


·¢ËÍÍêÉÏÏß°üÖ®ºó £¬´Ëʱ½©Ê¬·¨Ê½»áÆÚ´ý½ÓÊÕ¿ØÖƶ˵ĿØÖÆÖ¸Áî¡£Dofloo»áÊ×ÏÈ°Ñ¿ØÖÆÖ¸Áî°üµÄÇ°Ëĸö×Ö½Ú×÷ΪģʽָÁîÂë½øÐнâÎö £¬ÓÉ´ËÀ´ÅжϽÓÏÂÀ´Òª½øÐеIJÙ×÷ £¬Ö÷ÒªÖ§³ÖµÄ²Ù×÷ÓÐÈýÖÖ:


£¨1£©Ö¸ÁîÂëΪ0x5ʱ £¬½øÈëCmdShellº¯Êý £¬¸Ãº¯ÊýÄÚ²¿µ÷ÓÃÁËsystemº¯Êý £¬¿É×÷ΪԶ¿ØÀ´ÏÂÔØ»òÖ´ÐÐÆäËûÖ¸¶¨ÊýÁî¡£
£¨2£©Ö¸ÁîÂëΪ0x6ʱ £¬½øÈëDealwithDDoSº¯Êý £¬´Ëº¯ÊýΪDDoS¹¥»÷º¯Êý £¬ËùÓÐÖ´Ðй¥»÷µÄÅжϺÍÂß¼­¶¼Ôڴ˺¯ÊýÖС£

£¨3£©Ö¸ÁîÂëΪ0x7ʱºò £¬µ÷ÓÃkillº¯Êý £¬ÖÕÖ¹½ø³Ì¡£


ͬʱDofloo¼Ò×å¶Ô¿ØÖÆÖ¸Áî½øÐÐÁË128λµÄAES¼ÓÃÜ £¬Õâ¸öÌØÐÔ´ó´óÔö¼ÓÁ˶ÔÆä¿ØÖÆÖ¸ÁîÁ÷Á¿¼à¿ØºÍʶ´ËÍâÄѶÈ¡£ÎÒÃǶÔÊÕ¼¯µ½µÄÑù±¾½øÐзÖÎöºó·¢ÏÖ £¬ËùÓмܹ¹Ï½©Ê¬·¨Ê½ÓÃÀ´½âÃܵÄKEY¶¼ÊÇÏàͬµÄ £¬ÕâҲ˵Ã÷»¥ÁªÍøÖÐDofloo½©Ê¬¼Ò×åµÄÑù±¾¶¼À´×Ôͬһ¸öÄ£°æ¡£KEYÈçÏÂËùʾ£º


unsignedcharaes_key[] = { 0x2b, 0x7e, 0x15, 0x16, 0x28,  0xae, 0xd2, 0xa6, 0xab, 0xf7, 0x15, 0x88, 0x9, 0xcf, 0x4f, 0x3c };


ÎÒÃÇÄ£ÄâÁËδ¼ÓÃܵĿØÖÆÖ¸Á³ýȥǰ4¸ö×÷ΪģʽָÁîÂëµÄ×Ö½Ú£©ÔÚÄÚ´æÖеĽṹ,Æä¿ØÖÆÖ¸ÁîµÄ¸÷¸ö×ֶεĺ¬ÒåÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µ±½øÈëµ½DealwithDDoSº¯Êýʱ £¬½©Ê¬·¨Ê½Æ¾¾ÝÖ¸Áî £¬Æô¶¯²îÒìµÄ¹¥»÷Ï̡߳£Dofloo¼Ò×å²»½ö¾ßÓÐSYN¡¢HTTPµÈ´«Í³µÄ¹¥»÷ÒªÁì £¬»¹¾ßÓÐÀûÓÃUDPЭÒéµÄ·´Éä·Å´óµÄ¹¥»÷·½Ê½ £¬ºÃ±ÈDNS·Å´ó¹¥»÷¡£ÏÂͼΪDofloo¿ÉÌᳫµÄµäÐ͵ÄDDoS¹¥»÷µÄÒªÁ죺


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶øÇÒÎÒÃǶÔDoflooµÄ¹¥»÷ÒªÁì½øÐÐÁË·ÖÎö×ܽá £¬²¢¶Ô²¿ÃŹ¥»÷ÒªÁìµÄÁ÷Á¿ÌØÕ÷½øÐÐÁËÌáÈ¡ £¬ÖÆ×÷Á÷Á¿ÌØÕ÷±íÈçÏ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÎÒÃÇÔÚ·ÖÎö¹¥»÷Ï̵߳Äʱºò £¬·¢ÏÖARM¼Ü¹¹µÄ¶ñÒâÑù±¾Ã¿´Î¹¥»÷´´½¨µÄ¹¥»÷Ï̷߳dz£¶à £¬µ¥´Î¹¥»÷Ö¸Áî¿É´´½¨¼¸ÖÖÉõÖÁÊ®¼¸ÖÖ²îÒìÀàÐ͵Ĺ¥»÷Ï̡߳£½áºÏÑù±¾CPUµÄÂþÑÜ £¬ÎÒÃÇ¿ÉÒÔµÃÖªARMÉ豸ϵÄDofloo¶ñÒⷨʽÊǸý©Ê¬¼Ò×åµÄÖ÷Á¦ £¬ÔÚDDoS¹¥»÷ÖÐÌṩÁËÖ÷ÒªµÄÁ÷Á¿Ö§³Ö¡£


ͬʱƾ¾Ý¼à¿Øµ½Dofloo¹¥»÷ÀúÊ· £¬·¢ÏָüÒ×åÖ÷ÒªµÄ¹¥»÷·½Ê½ÒÔUDP Flood ΪÖ÷ £¬½üÄêÀ´ºÚ¿ÍÒ²Ô½À´Ô½Ï²»¶DNSºÍNTPµÈ·´Éä·Å´ó¹¥»÷ÊÖ¶ÎÀ´¶Ô·þÎñÆ÷½øÐй¥»÷  £¬DoflooµÄ¹¥»÷·½Ê½Õ¼±ÈÒ²Ó¡Ö¤ÁËÕâÒ»µã¡£Í¬Ê±ÎÒÃÇÒ²¿ÉÒÔ¿´µ½Layer7²ãµÄCC_FloodºÍLayer4²ãµÄTCP_Flood¡¢SYN Flood×÷Ϊ´«Í³µÄDDoSµÄ¹¥»÷·½Ê½ £¬ÆäÕ¼±ÈÒ²Ò»Ö±½ÏΪÎȶ¨¡£¶øÇÒÎÒÃÇƾ¾ÝÏà¹ØµÄÇ鱨Êý¾ÝµÃÖª £¬DoflooµÄ¹¥»÷Á¿Ïà¶ÔÓÚÆäËûµÄ¼Ò×å½ÏÉÙ £¬ÎÒÃÇ·ÖÎöÍƲâDoflooÿ´Î·¢¶¯¹¥»÷ʱ¿ªÆôÁË´óÁ¿µÄ¹¥»÷Ïß³Ì £¬ÕâÑùÄܼӴ󷢰üÁ¿ £¬¿ìËÙµ¼ÖÂÄ¿±ê·þÎñÆ÷å´»ú¡£


ÏÂͼΪDofloo½©Ê¬¼Ò×å¹¥»÷·½Ê½Õ¼±Èͼ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4.5 ͬԴÐÔ·ÖÎö


ÎÒÃÇÊӲ쵽ºÜ¶àɱ¶¾Èí¼þ¶ÔDofloo¼Ò×巨ʽÓвîÒìµÄÃüÃû·½Ê½ £¬ÉõÖÁʶ±ðΪÆäËû¼Ò×åµÄ·¨Ê½ £¬Òò´ËΪÁËÈ·¶¨Dofloo¼Ò×åµÄÔ´Âë×é³É £¬ÎÒÃǶÔÆä½øÐÐÁËͬԴÐÔ·ÖÎö¡£


ͨ¹ý¶ÔDofloo½©Ê¬ÍøÂç½øÐÐͬԴÐÔ·ÖÎö £¬·¢ÏÖDofloo½©Ê¬ÍøÂç¼Ò×åͬMr.Black½©Ê¬ÍøÂç¼Ò×å¡¢Flood.AÒÔ¼°DnsAmp½©Ê¬¼Ò×åÓкܸߵÄÏàËƶÈ¡£Ê×ÏÈ £¬ÎÒÃǶÔMr.Black¼Ò×åÖеĵäÐÍÑù±¾ºÍDofloo¼Ò×åµÄµäÐÍÑù±¾½øÐÐÁ˶ԱÈ £¬·¢ÏÖÕâÁ½¸ö¼Ò×åµÄÕûÌåÁ÷³ÌºÍ²¿ÃÅ´úÂë¸ß¶ÈÏàËÆ £¬ºÃ±ÈÏÂͼÖеÄÉÏÏß»úÖƲ¿ÃÅ £¬Í¨¹ý¶Ô±È¿ÉÒÔ¿´µ½ £¬ÉÏÏß°üµÄÄÚÈݺ͸ñʽҲ¼«ÎªÏàËÆ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶øÇÒ»¹¿ÉÒÔ¿´µ½Mr.BlackͬÑùÓÐͬÃûµÄ £¬ÌᳫDDoS¹¥»÷µÄº¯ÊýDealWithDDoS £¬ÆäÌᳫ¹¥»÷µÄ¿ØÖÆÖ¸Áî±àÂëÒ²Ïàͬ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ö»²»ÍâMr.BlackÖнöÓÐ5ÖÖDDoS¹¥»÷·½Ê½¡£Í¨¹ý²éÔÄMr.BlackµÄÔ´Âë £¬·¢ÏÖMr.BlackÔ´ÂëÖв¢Ã»ÓкÚȸºóÃÅÏ̺߳ÍAES¼ÓÃÜ £¬Ã»ÓÐÔ¶¿Ø²¿ÃÅ £¬½öÄÜÌᳫDDoS¹¥»÷¡£Òò´ËÍƲâDoflooΪ²Î¿¼Mr.Black´úÂë¸ü¸ÄºóµÄ±äÖÖ¡£


È»ºóͨ¹ýFlood.AͬMr.BlackºÍDofloo¼Ò×å½øÐжԱÈ £¬·¢ÏÖFlood.A¼Ò×å½ÏMr.Black¼Ò×åÐÂÔö¡°SynFLood_Message¡±ºÚȸºóÃÅÏß³Ì £¬¡°DealwithDDoS¡±º¯ÊýÖÐÔö¼ÓLayer7²ãµÄHTTPºéË®¹¥»÷ £¬Ã»ÓÐAES¼ÓÃܺÍÔ¶¿Ø¹¦Ð§ £¬ÓëMr.Black¼Ò×å½ÏΪÏàËÆ,²¿ÃŶԱÈͼÈçÏ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚDnsAmpÓëDofloo¼Ò×åµÄ¶Ô±ÈÖÐ £¬ÎÒÃÇ·¢ÏÖÆä´úÂë²îÒì½Ï´ó £¬µ«ÊÇÖ÷Òª¹¥»÷´úÂëÒÔ¼°·¨Ê½ÕûÌåÉè¼Æ˼·±ÈÁ¦ÏàËÆ¡£ÔÚDnsAmp¼Ò×åÖÐ £¬³Ö¾Ã»¯ÈÔÈ»ÊÇͨ¹ýÉèÖá°/etc/rc.d/rc.local¡±À´±£³Ö¿ª»ú×ÔÆô £¬¶øÇÒÔÚÆô¶¯ºóͬDoflooÒ»Ñù £¬»áÊ×ÏÈÈ·¶¨½ø³ÌµÄΨһÐÔ¡£¶øËüµÄ¹¥»÷Ï̡߳°AttackWorker¡±ÖÐ £¬ÎÒÃÇ·¢ÏÖͬDoflooÒ»Ñù¾ßÓÐͬÃûµÄ¹¥»÷º¯Êý¡°DealwithDDoS¡± £¬Ö»²»Íâ½öÓÐ4ÖÖ¹¥»÷·½Ê½ £¬·Ö±ðΪudp £¬icmp £¬dnsAmp,syn¹¥»÷¡£ËäÈ»DnsAmpÓëDoflooÕûÌå´úÂëÏàËƶȲ»ÊÇÌ«¸ß £¬µ«ÊÇƾ¾ÝÆäÖ÷Òª¹¥»÷´úÂëºÍ·¨Ê½ÕûÌåµÄÉè¼Æ˼· £¬ÎÒÃÇÍƲâ¶þÕß¾ßÓйØÁªÐÔ £¬ÖÁÉÙDnsAmpΪ²Î¿¼Dofloo´úÂë¶ø·¢ÉúµÄÏàËƱäÖÖ¡£²¿ÃŶԱÈͼÈçÏ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Òò´Ë £¬ÎÒÃÇ´óÖ¿ÉÒÔÍƲâ³öÈçϵĹØϵ£ºMrBlack¿ÉÄÜΪԭʼ¶ñÒⷨʽ £¬Flood.AΪÆä±äÖÖ £¬Ö÷ÒªÔö¼ÓµÄ¹¦Ð§ÓкóÃźÚȸÏ̺߳ÍHTTPºéË®¹¥»÷£»Dofloo¿ÉÄÜΪMr.Black»òFlood.AµÄ±äÖÖ £¬Ö÷ÒªÐÂÔöµÄÌØÐÔÓз¨Ê½³Ö¾Ã»¯ÉèÖà £¬¿ØÖÆÖ¸ÁîAES¼ÓÃÜ £¬ÒÔ¼°Ìí¼Ó¶àÖÖDDoS¹¥»÷ÒªÁ죻ÍƲâDnsAmpΪDoflooµÄ±äÖÖ £¬Ëü²Î¿¼ÁËDoflooµÄ²¿ÃÅ´úÂëºÍÉè¼Æ˼·¡£ÎÒÃÇ×ܽáÆäËÄÕߵĹØϵͼÈçÏ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


5.×Ü ½á


±¾Æª³ÂËßÖصã¶ÔDofloo½©Ê¬ÍøÂç¼Ò×åÖдæÔڵĺÚȸÏÖÏó½øÐÐÁË·ÖÎöÅû¶ £¬²¢ËÝÔ´×·×ÙºÚȸ £¬²ú³öºÚȸ»­Ïñ¡£Í¬Ê±¶ÔµäÐ͵Ľ©Ê¬Ñù±¾½øÐÐÁË·ÖÎö £¬ÌáÈ¡¹éÄɳöÉÏÏß¡¢ÐÄÌø¡¢¿ØÖÆÖ¸ÁîºÍÌᳫ¹¥»÷µÄÁ÷Á¿¸ñʽ¡£


ͬʱ £¬Í¨¹ý¶ÔºÚȸºÍó«òëµÄ·ÖÎö £¬Ö¤ÊµÁ˺Úȸ¹¥»÷Ëù´æÔÚµÄDZÔÚ¾Þ´óΣº¦¡£¾¡¹Ü²¿ÃźڿÍʵÑéÈ¥µôÆäºÚȸÏ̲߳¢ÖØÐÂÁ÷´« £¬µ«¾ø´ó¶àÊýµÄDofloo½©Ê¬Ñù±¾ÈÔÈ»ÁôÓдËÀàºóÃÅ £¬Ò²ÓкڿÍÔÚÈ·ÈϺÚȸIP»òÓòÃûʧЧºó½µµÍÁ˾¯ÌèÐÔ £¬µ«ÊÇÎÒÃÇ·¢ÏÖÓв¿ÃźÚȸÓòÃûÔÚDZ·üÒ»¶Îʱ¼äºó £¬ÈԻῶû½âÎöÉÏÏß £¬¶Ôó«òë½øÐÐÒ»²¨ÊոËùÒÔ £¬×ÛºÏÅжϸúÚȸ½©Ê¬×ÊÔ´¸»ºñ¡¢ÊµÁ¦Ç¿º·¡£´ËÍâ £¬Í¨¹ý¹ã·ºµÄ·ÖÎö·¢ÏÖ £¬ÕâÖÖ¹¥»÷·½Ê½»¹´óÁ¿´æÔÚÓÚÆäËû½©Ê¬·¨Ê½¡¢WEB Sehll¹¥»÷¹¤¾ß¼°Èä³æľÂí¹¥»÷¹¤¾ß £¬Õâ»òÐíÐèÒª¹ã´óÄþ¾²Ñо¿ÈËÔ±ºÍÄþ¾²»ú¹¹ÅäºÏÁôÒâ´ËÀ๥»÷µÄÄ»ºóºÚȸ £¬ÖØÊÓ¸ÃÀàÍþв¿ÉÄÜÔì³ÉµÄ¾Þ´óΣº¦ £¬¼°Ê±·¢ÏÖ²¢Çå³ýÒþÄäÓÚÍøÂçÖеÄÒ»´óÍþв¡£


²Î¿¼ÎÄÏ×£º


1¡¢DDoS-Capable IoT Malwares: Comparative Analysis and Mirai Investigation

https://www.hindawi.com/journals/scn/2018/7178164/


2¡¢2017 Global botnet DDoS attack threat report

http://www.antiy.net/p/2017-global-botnet-ddos-attack-threat-report


3¡¢Internet Security Threat Report

https://www.insight.com/content/dam/insight-web/en_US/article-images/whitepapers/partner-whitepapers/Internet%20Security%20Threat%20Report.pdf


4¡¢Tango down report of OP China ELF DDoS'er
http://blog.malwaremustdie.org/2014/09/tango-down-report-of-op-china-elf-ddoser.html