Categories: All

BitTorrent Patches Flaw That Allowed Website Killing DRDoS Attacks


SPR’s: Today in its blog, BitTorrent announced that it has fixed a vulnerability that allowed the attackers to take down websites by carrying out distributed reflective denial of service attacks (DRDoS).

Recently Florian Adamsky gave a presentation at a USENIX Workshop tell the possibilities of exploiting UDP-based protocols for DRDoS attacks. uTorrent, BitTorrent, and BitTorrent Sync use the Micro Transport Protocol (µTP) implementation in libuTP as the preferred transport backend running on top of UDP. Due to this, the attacker with modest resources could exploit a BitTorrent user unknowingly and drive a large volume of traffic to the victim to make them offline.
However, Christian Averill, Vice President of Communications and Brand for BitTorrent, tells fossBytes that such an attack has not been observed in the wild. He states: “First, it’s important to understand that this is a theoretical scenario and that such an attack has not been observed in the wild. Florian Adamsky and his co-authors conducted an experiment in a controlled environment producing the results presented in the paper.”
In his recent blog post, he outlines the fact that the BitTorrent engineering team has mitigated any distant possibility of such an attack. In another post, Francisco De La Cruz, software engineer on the uTorrent/BitTorrent team, tells how such an attack works and further explains the steps taken by his team.
Christian tells fossBytes that Florian and the co-authors reported their findings to BitTorrent team responsibly few weeks back and they have issued a fix to the torrent client.
He also shares an interesting point about the vulnerability in Sync. “Even before the recent updates to Sync, the severity of the vulnerability was reduced by a few factors. First, the attacker would have to know the Sync user they are trying to exploit to get their “Secret” – or the Sync user would have to have exposed that “Secret” publicly in some way. In addition, Sync, by design, limits the amount of peers in a share making the attack surface much smaller. It would not serve as an effective source to mount large-scale attacks,” he explains.
Having something to add? Share your opinions through comments.
spatsariya

Recent Posts

Creality Falcon T1 Combines Five Laser Engravers Into One Machine

Laser engraving can be incredibly versatile. You can engrave designs on metal or wood and…

18 hours ago

Creality Falcon T1 Combines Five Laser Engravers Into One Machine

Laser engraving can be incredibly versatile. You can engrave designs on metal or wood and…

18 hours ago

How to Delete Your Search History From Google History?

Most people use Google services every day without thinking about how much activity gets recorded.…

21 hours ago

How to Delete Your Search History From Google History?

Most people use Google services every day without thinking about how much activity gets recorded.…

21 hours ago

The Real AI Bottleneck Is Memory — and Nvidia Just Locked It Up

$205.42· 0.00 (0.00%)Market Cap$4.97TDay Range$203.44 – $207.0752-week range$141.84 – $236.26Consensus target$298.93 · Buy (61 analysts)Forward…

1 day ago

Intel’s Foundry Finally Has Real Customers — Its Stock Is Priced for More

$124.57▲ +7.61 (+6.51%)Market Cap$626.1BDay Range$115.33 – $127.6052-week range$18.96 – $132.75Consensus target$93.12 · Hold (48 analysts)Forward…

1 day ago