Skip to content

Davey Winder

delivering award-winning technology journalism since 1991

  • home
  • about me
  • follow me on mastodon
  • privacy policy
  • Toggle search form
Photo of a group of toy soldiers

Misconfigured memcached server DDoS threat is too powerful to be ignored

Posted on March 2, 2018March 2, 2018 By Davey Winder

DDoS threat actors have started to exploit a known problem with unsecured Memcache servers to launch some hugely powerful attacks

Multiple DDoS mitigation vendors have this week warned of spikes in reflection attacks by threat actors exploiting insecure, Internet-facing, memcached servers. The size of these attacks has been described as huge, massive and in one case insanely large. The high-bandwidth attacks have regularly exceeded 100Gbps in size, and have peaked nearer 500Gbps.  Vulnerable memcached servers are internet-facing; the default configuration exposes the UDP port (11211) to external connections. A search of the Shodan engine, which looks for Internet-connected devices, shows there are around 90,000 such memcached servers currently exposed to the potential of attack.
Ashley Stephenson, CEO at Corero Network Security, told SC Media that “memcached is vulnerable to UDP exploits due to an unnecessarily permissive wide-open default access policy allowing it to serve all requesters without prejudice.”

Click here to read complete article

Analysis, Threatscape Tags:DDoS

Post navigation

Previous Post: Enter boardroom, set hair on fire. How not to tackle incident response
Next Post: Five worrying cyberthreats to connected tech

Related Articles

Forget Passwords, This New Tech Is Nearly Hacker-Proof, 1Password Says Analysis
Photo of front end collision, crash test of cars This Surprisingly Simple Hack Can Crash iPhones—Update To iOS 17.2 Now Hacking
Gmail Hackers Leave Vital Clues Behind—Check These 3 Things Now Analysis
No, 1Password Has Not Just Been Hacked—Your Passwords Are Safe Analysis
New Critical Security Warning For iPhone, iPad, Watch, Mac—Attacks Underway Analysis
New Emergency Chrome Security Update After Critical iOS 16.6.1 Release Analysis

Categories

Post Archive

Tags

0day Analysis Android Apple Apps breach bug bounty Business Chrome crime Cybercrime Data Protection Encryption Enterprise Google Government Hackers Hacking Health healthcare industry iOS IoT iPhone Malware Microsoft News NHS Opinion passwords Phishing Privacy ransomware Research Russia Samsung threat intelligence Twitter Update Vulnerabilites vulnerabilities Vulnerability Windows Windows 10 zero-day

Copyright © 2025 Davey Winder .

×
Cookies
We serve cookies. If you think that's ok, just click "Accept all". You can also choose what kind of cookies you want by clicking "Settings". Read our cookie policy
Settings Refuse all Accept all
Cookies
Choose what kind of cookies to accept. Your choice will be saved for one year. Read our cookie policy
  • Necessary
    These cookies are not optional. They are needed for the website to function.
  • Statistics
    In order for us to improve the website's functionality and structure, based on how the website is used.
  • Experience
    In order for our website to perform as well as possible during your visit. If you refuse these cookies, some functionality will disappear from the website.
  • Marketing
    By sharing your interests and behavior as you visit our site, you increase the chance of seeing personalized content and offers.
Save Refuse all Accept all
GDPR Cookie Policy