Monday, August 17, 2015

Exploiting Torrent to launch DDoS attacks.


                Torrent sites and the torrent downloader such as utorrent and vuze has been used by many users across globe and there has been many countries that blocks torrent. Recently it has been noted that this torrent protocol can be used to launch a DDoS attack.

                 Torrent protocol is the simple file sharing protocol in which the users shares the files among peers and so there will be a connectivity between the peers or the computers across the globe and this may be exploited to launch the attack.

                  DDoS (Distributed Denial of Service) attack is the distributed version of DoS attack where the user will make the services unavailable for the users and this can be accomplished normaly by the bots across the globe.

                   Now as an advancement a security researcher has published a paper stating that the Reflective DDoS attack can be launched using the Peer to Peer or P2P protocol.

                   The traffic is amplified to a higher bandwidth and then the attack is launched on larger scale. Past year there has been a massive hit upto 300Gbps Dos attack recorded. Now it can be achieved upto 400 Gbps using this technique.

                    utorrent has been notified about the attack and the patch has been made but still it is vulnerable to Distributed Hash Table (DHT) attack and vuze is also notified and yet to release the patch.

                     The work has been published as a paper and it can be viewed here.

P.S : The post is to create awareness and not to be misused.

No comments:

Post a Comment