Thousands of public domain controllers (DCs) worldwide might be enlisted using a new attack method to build a malicious botnet and utilize it to launch potent distributed denial-of-service (DDoS) attacks.
Researchers Or Yair and Shahak Morag of SafeBreach have dubbed the strategy Win-DDoS. They presented their findings at today’s DEF CON 33 security conference.
In a post shared with The Hacker News, Yair and Morag stated, As we investigated the complexities of the Windows LDAP client code, we found a significant flaw that allowed us to manipulate the URL referral process to point DCs at a victim server to overwhelm it.
Consequently, we developed Win-DDoS, a method that would allow an attacker to use the strength of tens of thousands of public DCs worldwide to build a malicious botnet with enormous upload rates and resources read more about New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAP.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
