meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, February 28th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 28 February 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. memcached reflective DDoS; Formbook Info Stealer News; Critical SAML Vulnerability

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, February 28th, 2018 edition of the Sansonet Storm Center's

0:07.5

Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.4

Lots of talk the last few days about massive denial of service attack that use the MAMCash server as a reflector.

0:24.3

Problem here is MAMCash is a very simple memory based as the name implies no SQL database.

0:32.1

So simple key value storage and well because it's simple there's really no access control plus it is accessible

0:39.9

via udp. Now udp based protocols are always somewhat susceptible to spoofing and that's exactly

0:48.2

what's happening here. An attacker is spoofing a victim's source IP address and then sending a stats, short for status command, to the Memcash server.

1:02.0

In response, you will get, well, a status report of the Memcash server, which is at least around a kilobyte in size, but maybe several hundred

1:14.2

kilobytes in size.

1:16.4

So there is a massive amplification factor here.

1:20.5

If you are at the bad end, at the receiving end of denial of service attack like this, you

1:26.2

should see a lot of inbound UDP packets coming

1:29.7

from port 11,211.

1:34.4

Now typically these denial of service attacks are large enough where a simple firewall filter

1:40.7

probably won't save the day.

1:43.8

Maybe you're lucky but you're probably better off

1:47.1

with going upstream to an anti-denial of service provider that will help you to filter this

1:56.5

traffic far away from your own network. On the other hand, the administrators who keep

2:03.4

Memcash exposed, really not much you can do to help them. It is actually, well, not hard,

2:10.5

but not that easy to expose Memcash like this. By default, it only listens on the loopback interface. And if you actually look

2:20.7

at the configuration file, it has a specific warning that, well, you should not expose it to the

2:27.0

internet. But we all know people like to put stuff like this in the cloud and then they need to

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.