ºÚȸ¹¥»÷£ºÉî¶È·ÖÎö²¢ËÝÔ´Dofloo½©Ê¬ÎïÁªÍø±³ºóµÄ¡°ºÚȸ¡±
Ðû²¼Ê±¼ä 2019-05-31
2019Äê4Ô¿ªÊ¼£¬¶«Éƽ̨ADLabÊӲ쵽ConfluenceÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2019-3396±»Dofloo½©Ê¬ÍøÂç¼Ò×åÓÃÓÚ¹¥Õ¼É豸×ÊÔ´£¬Confluence ÊÇÒ»¸öרҵµÄÆóҵ֪ʶ¹ÜÀíÓëÐͬÈí¼þ£¬³£ÓÃÓÚ¹¹½¨ÆóÒµwiki¡£±¾´Î©¶´ÊÇÓÉÓÚConfluence Server ºÍConfluence DataÖеÄWidget Connector´æÔÚ·þÎñ¶ËÄ£°å×¢È멶´£¬¹¥»÷Õ߽ṹÌض¨ÇëÇó¿ÉÔ¶³Ì±éÀú·þÎñÆ÷ÈÎÒâÎļþ£¬ÉõÖÁʵÏÖÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£ÓÐÒâ˼µÄÊÇDofloo½©Ê¬ÍøÂç¼Ò×å²»½ö¿ªÊ¼ÀûÓøßΣ©¶´½øÐй¥»÷£¬¶øÇÒÆä±³ºóµÄºÚ¿Í»¹ÀûÓÃÒ»ÖÖ¸ü¾ßÓ°ÏìÁ¦µÄ¡°ºÚȸ¹¥»÷¡±À´ÈëÇÖ¹¤ÒµÁ´£¬ÒÔÕÆ¿ØÔ½·¢Ç¿´óµÄÍøÂç¹¥»÷×ÊÔ´¡£¶øÔÚ´ËÇ°£¬ÎÒÃÇÒѾ×öÁ˳¤Ê±¼äµÄÓëDofloo½©Ê¬¼Ò×åºÚ¿Í¹¤ÒµÁ´Ïà¹ØµÄÑо¿£¬ÇÒÒѾȷ¶¨ÁËÕâÖÖÆÕ±é´æÔÚÓÚDofloo¼Ò×åÖеġ°ºÚȸ¹¥»÷ÏÖÏó¡±£¬²¢¶ÔÆäÖеġ°ºÚȸ¡±½øÐÐÁ˺ã¾Ã×·×ÙÓë·ÖÎö¡£
´Ë´¦£¬ÎÒÃÇËùÌá³ö¡°ºÚȸ¹¥»÷¡±²»½öÊÇÒ»ÖÖ¸ßЧµÄºÚ¿Í¹¥»÷ÊֶΣ¬¶øÇÒ¸üÊÇÒ»ÖÖ¹¤ÒµÁ´¼¶´ËÍâ¹¥»÷ÒªÁ죬һ°ãΪºÚÉ«¹¤ÒµÁ´ÉÏÓκڿÍËùΪ¡£ºÚȸ¹¥»÷Ó빩ӦÁ´¹¥»÷ÓÐÒìÇúͬ¹¤Ö®ÃֻÊǹ¥»÷µÄÄ¿±ê²»ÊÇͨÀýµÄ¹¤ÒµÁ´£¬¶øÊǺڿ͹¤ÒµÁ´£»Êܹ¥»÷Á´µÄÄ©¶ËÒ²²»ÊÇÆÕͨÓû§£¬¶øÊǼ«¾ßΣº¦ÐԵĺڿÍȺÌå¡£ÔÚÍøÂçÄþ¾²ÓëºÚ¿Í¹¤ÒµÁ´µÄºã¾Ã·´¿¹£¬Ê¹µÃ¸Ã¹¤ÒµÁ´ÈÕ½¥³ÉÊìÇÒÅӴ󣬲¢ÐγÉÁËÒ»¸öÅÓ´óµÄºÚ¿ÍÉú̬ϵͳ£¬¶øÔÚÀûÒæºÍÉú´æÐèÇóµÄÇýʹÏ£¬ºÚȸÏÖÏóËƺõÄð³ÉÁËÒ»¶¨£¬ÉõÖÁÔÚʳÎïÁ´µÄÉ϶˽ø»¯³öÁ˺ÚȸÉú̬£¬ÈçDeath½©Ê¬ÍøÂçµÄ¡°´óºÚȸ-ºÚȸ-ó«ò롱¡£
×Ô¶«Éƽ̨ADLabÓÚ2016Äê³õ·¢ÏÖºÚȸ¹¥»÷²¢ÓÚ2017Äê1ÔÂÐû²¼¡¶ºÚȸ¹¥»÷-½ÒÃØDeath½©Ê¬ÍøÂç±³ºóµÄÖÕ¼«¿ØÖÆÕß¡·Ö®ºó£¬»¹Ïà¼ÌÔÚ¶à¸ö¶ñÒâ´úÂë¼Ò×åÖз¢ÏÖÁ˺Úȸ¹¥»÷£¬²¢Ðû²¼ÁËÉî¶È·ÖÎö³ÂËß¡¶½ÒÃØBillgates½©Ê¬ÍøÂçÖеĺÚȸÏÖÏ󡷺͡¶ºÚȸ¹¥»÷£º½ÒÃØTF½©Ê¬ÎïÁªÍøºÚ¿Í±³ºóµÄºÚ¿Í¡·¡£ÔÚ´ËÇ°µÄºÚȸ·ÖÎöºÍ×·×ÙÖУ¬ÎÒÃǽÒ¶ÁËDeath½©Ê¬ÍøÂç±³ºóµÄÄǸö¿ØÖÆ×ÅÉÏǧ½©Ê¬×ÓÍøÂçµÄ³¬¼¶ºÚ¿Í£¬ÒÔ¼°Éî²ØÔÚBillgates½©Ê¬ÍøÂçºÍÎïÁªÍø½©Ê¬DDoSTF¼Ò×å±³ºóµÄºÚȸ¡£´ËÍâÎÒÃÇ»¹ÏêϸÂÛÊöÁËÿ¸ö¼Ò×åÖС°ºÚȸ¹¥»÷¡±µÄºÚ¿ÍÌõÀí½á¹¹£¬ÈçDeath½©Ê¬ÍøÂçµÄÈý¼¶ºÚ¿Í½á¹¹(´óºÚȸ-ºÚȸ-ó«òë)£¬BillgatesºÍTFµÄ¶þ¼¶ºÚ¿Í½á¹¹£¨ºÚȸ-ó«ò룩£¬ÒÔ¼°¶ÔÏà¹ØµÄ´óºÚȸ¡¢ºÚȸºÍó«òë½øÐÐÁËÍøÂçÐÐΪ·ÖÎöºÍÉí·Ýʶ±ð£¬²¢×öÁ˾«×¼µÄºÚ¿Í»Ïñ¡£
1.Dofloo½©Ê¬¼Ò×å¼ò½é
Dofloo£¬ÓÖÃûSpikeºÍAES.DDoS£¬ÊÇÒ»¿îÖ§³ÖARM¡¢x86¡¢mipsdµÈ¶àCPU¼Ü¹¹µÄ½©Ê¬ÍøÂ編ʽ¡£Dofloo¼Ò×åÒò2014ÄêÕë¶Ô±±ÃÀÖÞºÍÑÇÖÞ¶à¸ö¹ú¼Ò½øÐиߴï215GbpsÁ÷Á¿µÄ¹¥»÷¶ø×ÅÃû£¬½ñºóºã¾ÃµÄ¹¥Õ¼ÎïÁªÍøÉ豸×ÊÔ´²¢Æµ·±µØ½øÐÐÍøÂç¹¥»÷»î¶¯¡£Æ¾¾ÝÈüÃÅÌú¿ËÔÚ2016ÄêÐû²¼µÄ¡¶Internet Security Thread Report¡·£¬Dofloo½©Ê¬ÍøÂç¶ñÒⷨʽλÁÐ2015Äê¶ÈIoTÁìÓò¶ñÒⷨʽÍþвÅÅÐаñµÚ¶þÃû¡£

2.·¢ÏÖDofloo½©Ê¬ÖеĺÚȸ
ÔÚºã¾ÃµÄ¶Ô½©Ê¬ÍøÂçµÄÑо¿ÖУ¬DoflooÒ»Ö±ÊÇÎÒÃǼà¿ØµÄ¹¤¾ß¡£ÔÚ֮ǰµÄÑо¿ÖУ¬Í¨¹ý×Ô¶¯»¯·ÖÎö¸Ã¼Ò×åµÄ¹ØÁªÑù±¾£¬·¢ÏָüÒ×åµÄ´ó²¿ÃÅÑù±¾¶¼ÊÐÆô¶¯Á½¸öÐµĹ¥»÷Ị̈߳¬²¢·¢ÏÖÕâÁ½¸öÏ̴߳æÔÚÒì³£ÐÐΪ¡£È磺²»½ö»áÉèÖÃÑÓ³ÙÆô¶¯Ị̈߳¬»¹»áʵÑé¸úÁíÒ»¸öC&C¿ØÖƶ˽øÐÐÁ¬½ÓͨÐÅ¡£Òò´Ë£¬ÎÒÃǶÔÕâЩÑù±¾½øÐÐÁ˽øÒ»²½µÄ·ÖÎö£¬×îÖÕÈ·¶¨¸Ã½©Ê¬Éú̬Öб»Ö²ÈëÁ˺Úȸ¡£
´ÓÉÏͼ¿ÉÒÔ¿´³ö£¬ÓÐÈý¸öµØÖ·µÄÉÏÏßƵ¶ÈÔ¶¸ßÓÚÆäËûµÄC&C¡£½áºÏÑùÌìÖ°Îö·¢ÏÖ£¬ÉÏÏßµ½ÕâÈý¸öC&CµØÖ·µÄÑù±¾¼¸ºõ¶¼ÓÐÁ½¸ö¶ÀÁ¢¿ØÖƵÄC&C£¬¶øÇÒ½©Ê¬»ØÁ¬ÕâÈý¸öC&CµØÖ·¶¼ÊÇͨ¹ý´´½¨×ÓÏ̵߳ķ½Ê½½øÐУ¬¶øÆä¹ØÁªµÄÑù±¾µÄÁíÍâÒ»¸öC&CÈ´ÊÇÔÚÖ÷Ïß³ÌÖнøÐлØÁ¬¡£Òò´Ë£¬Í¨¹ý¸Ã½©Ê¬µÄÕ⼸¸öÌØÐÔ¿ÉÒԶ϶¨ÆäÖп϶¨´æÔÚºÚȸ¹¥»÷µÄÏÖÏ󣬶øÕâÈý¸öC&CµØÖ·±ãÊÇDofloo½©Ê¬Éú̬ÖеĺÚȸC&CµØÖ·£¬ÓëºÚȸC&CµØÖ·Ïà¹ØÁªµÄÆäËûC&CµØÖ·±ãÊÇDofloo½©Ê¬Éú̬ÖÐó«òëºÚ¿ÍµÄC&CµØÖ·¡£
ÎÒÃǶÔÕâÈý¸öºÚȸC&CµØÖ·Ïà¹ØÁªµÄó«òëC&C×öÁË·ÖÀàͳ¼Æ£¬ÈçϱíËùʾ£º
C&CµØÖ· |
ó«ò뽩ʬÍøÂçÊýÁ¿ |
183.60.149.199 |
189 |
118.193.217.144 |
282 |
aaa.tfddos.net |
85 |
3.Dofloo½©Ê¬ºÚȸËÝÔ´Óë»Ïñ
ͨ¹ý¶ÔÑù±¾µÄ·ÖÎö£¬½áºÏÑù±¾Öеĺ¯ÊýÃüÃûÏ°¹ß¡¢¹¥»÷Á÷Á¿ÌØÕ÷¡¢±äÖÖÔ´Âë×¢ÊÍÒÔ¼°Ñù±¾·¢×÷Á÷´«Ê±ÓÃÀ´É¢²¥Ñù±¾µÄHFSÃæ°åÓïÑÔµÈÌØÕ÷£¬ÎÒÃÇÅж¨¸Ã¼Ò×åÓɹúÄڵĺڿͱàд¡£ÓÚÊÇÎÒÃÇËÝÔ´Ä¿±êËø¶¨ÔÚ¹úÄÚ£¬Í¨¹ý¶ÔºÚȸÓòÃû¡°aaa.tfddos.net¡±ÖÐÒªº¦ÐÅÏ¢¡±tfddos¡±£¬ÎÒÃǹØÁªµ½Ò»¿îÃûΪ¡°Ì¨·çDDoS¡±µÄ½©Ê¬Èí¼þ¡£¶øÇÒͨ¹ý½øÒ»²½·ÖÎö·¢ÏÖ£¬¸Ã½©Ê¬Èí¼þµÄÄ£°åÑù±¾ÓëDofloo½©Ê¬¾ßÓм«ÎªÏàËƵÄÐÐΪºÍÍøÂçÌØÐÔ¡£´ËÍ⣬¡°Ì¨·çDDoS¡±Ôںڿͼä»îÔ¾µÄʱ¼äͬDofloo·¢×÷ʱ¼ä¾ùÔÚ2014Äꡣƾ¾ÝÒÔÉÏһϵÁеÄÖ¤¾ÝÖ¤Ã÷ËûÃÇÖ®¼ä´æÔÚÒ»¶¨Í¬Ô´ÐÔ¡£ÎªÁ˽øÒ»²½È·ÈÏËûÃÇΪͬһ¿î½©Ê¬·¨Ê½£¬ÎÒÃÇ»¹ÀûÓÃbindiff¶Ô¡°Ì¨·çDDoS¡±¿ØÖƶËÉú³ÉµÄ½©Ê¬ÓëDoflooµÄÑù±¾½øÐÐÁËÏàËƶȱȶԣ¬·¢ÏÖÁ½Õß´úÂëÏàËƶÈΪ100%µÄ´úÂëÕ¼±ÈÁè¼Ý98%£¬Òò´Ë¿ÉÒÔÈ·¶¨¡°Ì¨·çDDoS¡±±ãÊÇDofloo¼Ò×åµÄÒ»¸öÖ÷¿Ø¡£¶Ô±ÈͼÈçÏ£º
ͨ¹ý¶ÔÔçÆڵġ°Ì¨·çDDoS¡±µÄ½©Ê¬Ä£°å·¨Ê½·ÖÎö·¢ÏÖÓëDoflooºÚȸC&CÏàͬµÄºóÃÅC&C£º183.60.149.199¡£
´ËÍ⣬ͨ¹ý¶Ô¡°Ì¨·çDDoS¡±µÄËÝÔ´·¢ÏÖ£¬ÆäÔøÔÚÍøÕ¾tfddos.comÉÏ×÷Ϊ¹Ù·½Èí¼þ±»¹ûÈ»ÊÛÂô£¬¸ÃÍøÕ¾ËäÈ»½ÓÄÉÁËÓëDoflooºÚȸÓòÃû¡°aaa.tfddos.net¡±·×ÆçÑùµÄÓòÃû£¬µ«ËûÃǶ¼Ê¹ÓÃÁË¡°tfddos¡±×÷ΪÓòÃûµÄÒªº¦×Ö£¬Ò²¼´ÊÇ¡°tai£¨Ì¨£© feng£¨·ç£© ddos¡±¡£Òò¶øÎÒÃÇÈÏΪºóÃÅC&C£º183.60.149.199Óëaaa.tfddos.netΪͬһºÚ¿Í»òÕߺڿÍ×éÖ¯ËùΪ¡£
¶ÔÓÚºÚȸIP£º118.193.217.144µÄ·´²é·¢ÏÖ£¬ÔÚ2017Ä꣬ÓòÃûwap.tfddos.netºÍaaa.tfddos.netÓë¸ÃIPµØÖ·½øÐÐÁ˺ã¾ÃµÄ°ó¶¨¡£
ΪÁË×·×ÙDofloo½©Ê¬ÍøÂç±³ºóµÄºÚȸ£¬ÎÒÃÇÏÈÊÕ¼¯ÁËC&CÏà¹ØµÄÐÅÏ¢²¢½øÐÐÁË·ÖÎö¡£ÆäÖÐͨ¹ýIP£º183.60.149.199¹ØÁª³öÀ´µÄÏà¹ØÓòÃû´ó²¿Ãű»×÷ΪɫÇéÍøÕ¾»ò²©²ÊÍøվʹÓ㬲¢ÎÞ¿ÉÓÃÏßË÷¡£¶øtfddos.comºÍtfddos.net¶¼½ÓÄÉÒþ˽±£»¤·½°¸£¬ÎÞ·¨½øÐнøÒ»²½µÄ×·ËÝ¡£
ͨ¹ý½ñºóºã¾ÃµÄËÝÔ´·ÖÎö£¬ÎÒÃÇ»¹×·×Ùµ½Á˸úÚȸÔÚÏÖʵÊÀ½çÖеÄÉí·ÝÐÅÏ¢¡£´ËºÚȸÊǺÓÄÏÄÏÑôÁ½¼Ò¿Æ¼¼¹«Ë¾µÄ¼àÊ£¬¶øÇÒÒÔ80ÍòÔªÈϽÉ×ʽð³ÖÓÐÆäÖÐÒ»¼Ò¿Æ¼¼¹«Ë¾10%µÄ¹É·Ý£¬±³µØÀï´Óʺڲú»î¶¯¡£

4.Dofloo½©Ê¬µäÐÍÑùÌìÖ°Îö
ÓÉÓÚDoflooÖ§³Ö¶àÖÖCPU¼Ü¹¹£¬ÎÒÃÇÔÚ¶ÔÕâЩƽ̨µÄÑùÌìÖ°ÎöÖз¢ÏÖ£¬ËùÓÐDoflooÖ§³ÖµÄ¼Ü¹¹£¬¶¼´æÔÚºÚȸÏÖÏó¡£µ«Êǽ©Ê¬×÷Õ߶ԲîÒìµÄ¼Ü¹¹µÄºÚȸC&C´¦ÖÃÂÔÓвîÒ죬Õâ¶Ô×Ô¶¯»¯·ÖÎöÒ²Ôì³ÉÁËÒ»¶¨µÄÓ°Ïì¡£ÎÒÃǶԱ¾´ÎÊÕ¼¯µÄ¹²¼Æ1200¸öÑù±¾µÄ¼Ü¹¹ËùÕ¼±ÈÀý½øÐÐÁËͳ¼Æ£¬»æÖƳÉͼÈçÏ£º

CPU¼Ü¹¹µÄÂþÑÜͼ£¬Ò»¶¨Ë®Æ½ÉÏҲ˵Ã÷Á˸üÒ×åÈëÇÖÉ豸ÀàÐ͵ÄÂþÑÜ£¬¿ÉÒÔ¿´µ½ARMÉ豸µÄ±ÈÀý·Ç³£¸ß£¬ÕâҲ˵Ã÷ARMϵÄÉ豸Êܵ½ºÚȸ¿ØÖƵıÈÀý±ÈÁ¦¸ß¡£
½ÓÏÂÀ´ÎÒÃǶÔDofloo¼Ò×åµÄµäÐÍÑù±¾½øÐÐÁËÏêϸµÄÆÊÎö£¬¶øÇÒƾ¾Ý´óÁ¿Ñù±¾ÌáÈ¡¹éÄɳöµäÐ͵ÄͨѶÁ÷Á¿ºÍ¹¥»÷Á÷Á¿ÌØÕ÷,²¢¶ÔDofloo¼Ò×å½øÐÐÁËͬԴÐÔ·ÖÎö¡£
4.1 °²×°»úÖÆ
Dofloo½©Ê¬·¨Ê½µÄ°²×°»úÖÆÓУº½©Ê¬·¨Ê½ÔÚËÞÖ÷»úµÄ³Ö¾Ã»¯ÉèÖᢽø³ÌΨһÐÔÅжϺÍÊØ»¤½ø³ÌÉèÖá£
½©Ê¬·¨Ê½Í¨¹ýдÈ뿪»ú×ÔÆôÃüÁîʵÏֳ־û¯¡£½©Ê¬·¨Ê½ÔÚÆô¶¯ºó£¬»áÊ×Ïȼì²éÆô¶¯µÄÃüÁîÐвÎÊý, Èç¹û·¢ÏÖûÓвÎÊý£¬ÄÇô¶ñÒⷨʽ»áĬÈÏÊÇÔÚ¸ÃÉ豸µÄµÚÒ»´ÎÔËÐÐ,´Ëʱ»áµ÷Óá°autoboot¡±º¯Êý¡£Ôڸú¯ÊýÖУ¬µ÷Óá°system¡±º¯ÊýÖ´ÐÐϱíÖеÄÃüÁÒÔÈ·±£¶ñÒⷨʽÔÚ¸ÃÉ豸ÖØÆôºóÈÔÄܹ»Æô¶¯ÔËÐС£ÕâÒ²ÊÇDofloo¶ñÒⷨʽÔÚËÞÖ÷É豸ʵÏֳ־û¯µÄΨһҪÁì¡£
sed -i -e '/^\r\n|\r|\n$/d' /etc/rc.local
sed -i -e '/%s/d' /etc/rc.local
sed -i -e '2 i%s/%s' /etc/rc.local
sed -i -e '2 i%s/%s start' /etc/rc.d/rc.local
sed -i -e '2 i%s/%s start' /etc/init.d/boot.local
4.2 ÉÏÏß»úÖÆ
4.3 ÐÄÌø»úÖÆ
½©Ê¬·¨Ê½ÔÚSendInfoÏß³ÌʵÏÖÁË×ÔÉíµÄÐÄÌø»úÖÆ¡£Õâ¸öÏ̵߳ÄÖ÷Òª¹¦Ð§ÊÇÏòó«òë¿ØÖƶ˺ͺÚȸ¿ØÖƶ˷¢ËÍÐÄÌø°ü£¬ÐÄÌø°üÄÚÈÝ°üÂÞµ±Ç°CPUʹÓÃÂʺÍÍøÂçËÙ¶ÈÐÅÏ¢£¬Í¨¹ýÒÔÏÂ2¸ö²½Öè»ñÈ¡µ½ÕâЩÄÚÈÝ£º
£¨1£© ¼ì²é¡°eth0¡±µ½¡°eth9¡±·¶Î§ÄÚÒÔÌ«Íø¿ÚµÄifconfigÐÅÏ¢¡£²¢Í¨¹ý¶ÁÈ¡/proc/net/dev Ŀ¼ÐÅÏ¢À´¼ÆËãÍøÂçËÙÂÊ¡£
£¨2£©Í¨¹ý¶ÁÈ¡/proc/statĿ¼ÏµÄÐÅÏ¢£¬»ñÈ¡cpuÊýÁ¿£¬¼ÆËãÕ¼Óðٷֱȡ£
±ÈÁ¦ÓÐȤµÄÊÇ£¬ÏÂÓεĺڿÍÔÚ·¢¶¯DDoS¹¥»÷µÄʱºò£¬¿ÉÄÜ»ù´¡²»»áÏëµ½£¬Ö÷¿ØÖÐÏÔʾµÄ¶ñÒⷨʽµÄ¹¥»÷Á÷Á¿ËÙÂʼ¸ºõ¶¼ÊÇαÔìµÄ¡£ÎÒÃÇÔÚSendInfoÏß³ÌÖз¢ÏÖ£¬µ±¶ñÒⷨʽִÐÐDDoS¹¥»÷ʱ£¬»áµ÷Óá°fake_net_speed¡±º¯Êý£¬¸Ãº¯Êý»áƾ¾Ý²îÒìµÄDDoS¹¥»÷µÄģʽ£¬ÔÚÒ»¸öÀι̵ķ¶Î§ÄÚαÔì¹¥»÷Á÷Á¿ËÙÂÊ¡£ÏÂͼΪ¶Ô²¿ÃżÆËãËæ»úÁ÷Á¿µÄ½Øͼ£º
½©Ê¬·¨Ê½Î±ÔìµÄ¹¥»÷Á÷Á¿Êý¾Ý·¶Î§ÈçϱíËùʾ£º
4.4 ¿ØÖÆÖ¸Áî½âÎöÓëDDoS¹¥»÷
·¢ËÍÍêÉÏÏß°üÖ®ºó£¬´Ëʱ½©Ê¬·¨Ê½»áÆÚ´ý½ÓÊÕ¿ØÖƶ˵ĿØÖÆÖ¸Áî¡£Dofloo»áÊ×ÏÈ°Ñ¿ØÖÆÖ¸Áî°üµÄÇ°Ëĸö×Ö½Ú×÷ΪģʽָÁîÂë½øÐнâÎö£¬ÓÉ´ËÀ´ÅжϽÓÏÂÀ´Òª½øÐеIJÙ×÷£¬Ö÷ÒªÖ§³ÖµÄ²Ù×÷ÓÐÈýÖÖ:
£¨2£©Ö¸ÁîÂëΪ0x6ʱ£¬½øÈëDealwithDDoSº¯Êý£¬´Ëº¯ÊýΪDDoS¹¥»÷º¯Êý£¬ËùÓÐÖ´Ðй¥»÷µÄÅжϺÍÂß¼¶¼Ôڴ˺¯ÊýÖС£
£¨3£©Ö¸ÁîÂëΪ0x7ʱºò£¬µ÷ÓÃkillº¯Êý£¬ÖÕÖ¹½ø³Ì¡£
ͬʱDofloo¼Ò×å¶Ô¿ØÖÆÖ¸Áî½øÐÐÁË128λµÄAES¼ÓÃÜ£¬Õâ¸öÌØÐÔ´ó´óÔö¼ÓÁ˶ÔÆä¿ØÖÆÖ¸ÁîÁ÷Á¿¼à¿ØºÍʶ´ËÍâÄѶȡ£ÎÒÃǶÔÊÕ¼¯µ½µÄÑù±¾½øÐзÖÎöºó·¢ÏÖ£¬ËùÓмܹ¹Ï½©Ê¬·¨Ê½ÓÃÀ´½âÃܵÄKEY¶¼ÊÇÏàͬµÄ£¬ÕâҲ˵Ã÷»¥ÁªÍøÖÐDofloo½©Ê¬¼Ò×åµÄÑù±¾¶¼À´×Ôͬһ¸öÄ£°æ¡£KEYÈçÏÂËùʾ£º
unsignedcharaes_key[] = { 0x2b, 0x7e, 0x15, 0x16, 0x28, 0xae, 0xd2, 0xa6, 0xab, 0xf7, 0x15, 0x88, 0x9, 0xcf, 0x4f, 0x3c };
ÎÒÃÇÄ£ÄâÁËδ¼ÓÃܵĿØÖÆÖ¸Á³ýȥǰ4¸ö×÷ΪģʽָÁîÂëµÄ×Ö½Ú£©ÔÚÄÚ´æÖеĽṹ,Æä¿ØÖÆÖ¸ÁîµÄ¸÷¸ö×ֶεĺ¬ÒåÈçÏÂͼËùʾ£º
µ±½øÈëµ½DealwithDDoSº¯Êýʱ£¬½©Ê¬·¨Ê½Æ¾¾ÝÖ¸ÁÆô¶¯²îÒìµÄ¹¥»÷Ï̡߳£Dofloo¼Ò×å²»½ö¾ßÓÐSYN¡¢HTTPµÈ´«Í³µÄ¹¥»÷ÒªÁ죬»¹¾ßÓÐÀûÓÃUDPÐÒéµÄ·´Éä·Å´óµÄ¹¥»÷·½Ê½£¬ºÃ±ÈDNS·Å´ó¹¥»÷¡£ÏÂͼΪDofloo¿ÉÌᳫµÄµäÐ͵ÄDDoS¹¥»÷µÄÒªÁ죺
¶øÇÒÎÒÃǶÔDoflooµÄ¹¥»÷ÒªÁì½øÐÐÁË·ÖÎö×ܽᣬ²¢¶Ô²¿ÃŹ¥»÷ÒªÁìµÄÁ÷Á¿ÌØÕ÷½øÐÐÁËÌáÈ¡£¬ÖÆ×÷Á÷Á¿ÌØÕ÷±íÈçÏ£º
ÎÒÃÇÔÚ·ÖÎö¹¥»÷Ï̵߳Äʱºò£¬·¢ÏÖARM¼Ü¹¹µÄ¶ñÒâÑù±¾Ã¿´Î¹¥»÷´´½¨µÄ¹¥»÷Ï̷߳dz£¶à£¬µ¥´Î¹¥»÷Ö¸Áî¿É´´½¨¼¸ÖÖÉõÖÁÊ®¼¸ÖÖ²îÒìÀàÐ͵Ĺ¥»÷Ï̡߳£½áºÏÑù±¾CPUµÄÂþÑÜ£¬ÎÒÃÇ¿ÉÒÔµÃÖªARMÉ豸ϵÄDofloo¶ñÒⷨʽÊǸý©Ê¬¼Ò×åµÄÖ÷Á¦£¬ÔÚDDoS¹¥»÷ÖÐÌṩÁËÖ÷ÒªµÄÁ÷Á¿Ö§³Ö¡£
ͬʱƾ¾Ý¼à¿Øµ½Dofloo¹¥»÷ÀúÊ·£¬·¢ÏָüÒ×åÖ÷ÒªµÄ¹¥»÷·½Ê½ÒÔUDP Flood ΪÖ÷£¬½üÄêÀ´ºÚ¿ÍÒ²Ô½À´Ô½Ï²»¶DNSºÍNTPµÈ·´Éä·Å´ó¹¥»÷ÊÖ¶ÎÀ´¶Ô·þÎñÆ÷½øÐй¥»÷ £¬DoflooµÄ¹¥»÷·½Ê½Õ¼±ÈÒ²Ó¡Ö¤ÁËÕâÒ»µã¡£Í¬Ê±ÎÒÃÇÒ²¿ÉÒÔ¿´µ½Layer7²ãµÄCC_FloodºÍLayer4²ãµÄTCP_Flood¡¢SYN Flood×÷Ϊ´«Í³µÄDDoSµÄ¹¥»÷·½Ê½£¬ÆäÕ¼±ÈÒ²Ò»Ö±½ÏΪÎȶ¨¡£¶øÇÒÎÒÃÇƾ¾ÝÏà¹ØµÄÇ鱨Êý¾ÝµÃÖª£¬DoflooµÄ¹¥»÷Á¿Ïà¶ÔÓÚÆäËûµÄ¼Ò×å½ÏÉÙ£¬ÎÒÃÇ·ÖÎöÍƲâDoflooÿ´Î·¢¶¯¹¥»÷ʱ¿ªÆôÁË´óÁ¿µÄ¹¥»÷Ị̈߳¬ÕâÑùÄܼӴ󷢰üÁ¿£¬¿ìËÙµ¼ÖÂÄ¿±ê·þÎñÆ÷å´»ú¡£
4.5 ͬԴÐÔ·ÖÎö
ÎÒÃÇÊӲ쵽ºÜ¶àɱ¶¾Èí¼þ¶ÔDofloo¼Ò×巨ʽÓвîÒìµÄÃüÃû·½Ê½£¬ÉõÖÁʶ±ðΪÆäËû¼Ò×åµÄ·¨Ê½£¬Òò´ËΪÁËÈ·¶¨Dofloo¼Ò×åµÄÔ´Âë×é³É£¬ÎÒÃǶÔÆä½øÐÐÁËͬԴÐÔ·ÖÎö¡£
¶øÇÒ»¹¿ÉÒÔ¿´µ½Mr.BlackͬÑùÓÐͬÃûµÄ£¬ÌᳫDDoS¹¥»÷µÄº¯ÊýDealWithDDoS£¬ÆäÌᳫ¹¥»÷µÄ¿ØÖÆÖ¸Áî±àÂëÒ²Ïàͬ¡£
Ö»²»ÍâMr.BlackÖнöÓÐ5ÖÖDDoS¹¥»÷·½Ê½¡£Í¨¹ý²éÔÄMr.BlackµÄÔ´Â룬·¢ÏÖMr.BlackÔ´ÂëÖв¢Ã»ÓкÚȸºóÃÅÏ̺߳ÍAES¼ÓÃÜ£¬Ã»ÓÐÔ¶¿Ø²¿ÃÅ£¬½öÄÜÌᳫDDoS¹¥»÷¡£Òò´ËÍƲâDoflooΪ²Î¿¼Mr.Black´úÂë¸ü¸ÄºóµÄ±äÖÖ¡£
ÔÚDnsAmpÓëDofloo¼Ò×åµÄ¶Ô±ÈÖУ¬ÎÒÃÇ·¢ÏÖÆä´úÂë²îÒì½Ï´ó£¬µ«ÊÇÖ÷Òª¹¥»÷´úÂëÒÔ¼°·¨Ê½ÕûÌåÉè¼Æ˼·±ÈÁ¦ÏàËÆ¡£ÔÚDnsAmp¼Ò×åÖУ¬³Ö¾Ã»¯ÈÔÈ»ÊÇͨ¹ýÉèÖá°/etc/rc.d/rc.local¡±À´±£³Ö¿ª»ú×ÔÆô£¬¶øÇÒÔÚÆô¶¯ºóͬDoflooÒ»Ñù£¬»áÊ×ÏÈÈ·¶¨½ø³ÌµÄΨһÐÔ¡£¶øËüµÄ¹¥»÷Ï̡߳°AttackWorker¡±ÖУ¬ÎÒÃÇ·¢ÏÖͬDoflooÒ»Ñù¾ßÓÐͬÃûµÄ¹¥»÷º¯Êý¡°DealwithDDoS¡±£¬Ö»²»Íâ½öÓÐ4ÖÖ¹¥»÷·½Ê½£¬·Ö±ðΪudp£¬icmp£¬dnsAmp,syn¹¥»÷¡£ËäÈ»DnsAmpÓëDoflooÕûÌå´úÂëÏàËƶȲ»ÊÇÌ«¸ß£¬µ«ÊÇƾ¾ÝÆäÖ÷Òª¹¥»÷´úÂëºÍ·¨Ê½ÕûÌåµÄÉè¼Æ˼·£¬ÎÒÃÇÍƲâ¶þÕß¾ßÓйØÁªÐÔ£¬ÖÁÉÙDnsAmpΪ²Î¿¼Dofloo´úÂë¶ø·¢ÉúµÄÏàËƱäÖÖ¡£²¿ÃŶԱÈͼÈçÏ£º

5.×Ü ½á
±¾Æª³ÂËßÖصã¶ÔDofloo½©Ê¬ÍøÂç¼Ò×åÖдæÔڵĺÚȸÏÖÏó½øÐÐÁË·ÖÎöÅû¶£¬²¢ËÝÔ´×·×ÙºÚȸ£¬²ú³öºÚȸ»Ïñ¡£Í¬Ê±¶ÔµäÐ͵Ľ©Ê¬Ñù±¾½øÐÐÁË·ÖÎö£¬ÌáÈ¡¹éÄɳöÉÏÏß¡¢ÐÄÌø¡¢¿ØÖÆÖ¸ÁîºÍÌᳫ¹¥»÷µÄÁ÷Á¿¸ñʽ¡£
²Î¿¼ÎÄÏ×£º
1¡¢DDoS-Capable IoT Malwares: Comparative Analysis and Mirai Investigation
https://www.hindawi.com/journals/scn/2018/7178164/
http://www.antiy.net/p/2017-global-botnet-ddos-attack-threat-report
https://www.insight.com/content/dam/insight-web/en_US/article-images/whitepapers/partner-whitepapers/Internet%20Security%20Threat%20Report.pdf
http://blog.malwaremustdie.org/2014/09/tango-down-report-of-op-china-elf-ddoser.html