ºÚȸ¹¥»÷£ºÉî¶È·ÖÎö²¢ËÝÔ´Dofloo½©Ê¬ÎïÁªÍø±³ºóµÄ¡°ºÚȸ¡±
°ä²¼¹¦·ò 2019-05-31
2019Äê4ÔÂÆðÍ·£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLab¹Û²ìµ½ConfluenceÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2019-3396±»Dofloo½©Ê¬ÍøÂç¼Ò×åÓÃÓÚ¹¥Õ¼É豸×ÊÔ´£¬£¬£¬£¬£¬Confluence ÊÇÒ»¸öרҵµÄÆóҵ֪ʶÖÎÀíÓëÐͬÈí¼þ£¬£¬£¬£¬£¬³£ÓÃÓÚ¹¹½¨ÆóÒµwiki¡£¡£¡£¡£¡£¡£¡£±¾´Î·ì϶ÊÇÓÉÓÚConfluence Server ºÍConfluence DataÖеÄWidget Connector´æÔÚ·þÎñ¶ËÄ£°å×¢Èë·ì϶£¬£¬£¬£¬£¬¹¥»÷Õß»ú¹ØÌض¨ÒªÇó¿ÉÔ¶³Ì±éÀú·þÎñÆ÷ËÁÒâÎļþ£¬£¬£¬£¬£¬ÉõÖÁʵÏÖÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£ÓÐÒâ˼µÄÊÇDofloo½©Ê¬ÍøÂç¼Ò×å²»½öÆðÍ·ÀûÓøßΣ·ì϶½øÐй¥»÷£¬£¬£¬£¬£¬²¢ÇÒÆä±³ºóµÄºÚ¿Í»¹ÀûÓÃÒ»ÖÖ¸ü¾ßÓ°ÏìÁ¦µÄ¡°ºÚȸ¹¥»÷¡±À´ÈëÇÖ²úÒµÁ´£¬£¬£¬£¬£¬ÒÔÕÆ¿ØÔ½·¢×³´óµÄÍøÂç¹¥»÷×ÊÔ´¡£¡£¡£¡£¡£¡£¡£¶øÔÚ´Ëǰ£¬£¬£¬£¬£¬ÎÒÃÇÒѾ×öÁ˳¤¹¦·òµÄÓëDofloo½©Ê¬¼Ò×åºÚ¿Í²úÒµÁ´ÓйصÄ×êÑУ¬£¬£¬£¬£¬ÇÒÒѾȷ¶¨ÁËÕâÖÔìձ鴿ÔÚÓÚDofloo¼Ò×åÖеġ°ºÚȸ¹¥»÷¾°Ïó¡±£¬£¬£¬£¬£¬²¢¶ÔÆäÖеġ°ºÚȸ¡±½øÐÐÁ˳־Ã×·×ÙÓë·ÖÎö¡£¡£¡£¡£¡£¡£¡£
´Ë´¦£¬£¬£¬£¬£¬ÎÒÃÇËùÌá³ö¡°ºÚȸ¹¥»÷¡±²»½öÊÇÒ»ÖÖ¸ßЧµÄºÚ¿Í¹¥»÷¼¿Á©£¬£¬£¬£¬£¬²¢ÇÒ¸üÊÇÒ»ÖÖ²úÒµÁ´¼¶´ËÍâ¹¥»÷²½Ö裬£¬£¬£¬£¬Í¨³£ÎªÐþÉ«²úÒµÁ´ÉÏÓκڿÍËùΪ¡£¡£¡£¡£¡£¡£¡£ºÚȸ¹¥»÷Ó빩¸øÁ´¹¥»÷ÓÐÒìÇúͬ¹¤Ö®Ã£¬£¬£¬£¬Ö»Êǹ¥»÷µÄÖ¸±ê²»ÊÇͨÀýµÄ²úÒµÁ´£¬£¬£¬£¬£¬¶øÊǺڿͲúÒµÁ´£»£»£»£»£»Êܹ¥»÷Á´µÄ½áβҲ²»ÊÇͨ³£Óû§£¬£¬£¬£¬£¬¶øÊǼ«¾ß·çÏÕÐԵĺڿÍȺÌå¡£¡£¡£¡£¡£¡£¡£ÔÚÍøÂ簲ȫÓëºÚ¿Í²úÒµÁ´µÄ³Ö¾ÃÆ¥µÐ£¬£¬£¬£¬£¬Ê¹µÃ¸Ã²úÒµÁ´ÈÕ½¥³ÉÊìÇÒ¸´ÔÓ£¬£¬£¬£¬£¬²¢ÐγÉÁËÒ»¸öÖØ´óµÄºÚ¿ÍÉú̬ϵͳ£¬£¬£¬£¬£¬¶øÔÚÀûÒæºÍÉú¼ÆÐèÒªµÄÇý²ßÏ£¬£¬£¬£¬£¬ºÚȸ¾°ÏóËÆºõÔì³ÉÁ˱ØÈ»£¬£¬£¬£¬£¬ÉõÖÁÔÚʳƷÁ´µÄÉ϶˽ø»¯³öÁ˺ÚȸÉú̬£¬£¬£¬£¬£¬ÈçDeath½©Ê¬ÍøÂçµÄ¡°´óºÚȸ-ºÚȸ-ó«ò롱¡£¡£¡£¡£¡£¡£¡£
×Ô8827Ì«Ñô¼¯ÍÅADLabÓÚ2016ËêÊ×·¢ÏÖºÚȸ¹¥»÷²¢ÓÚ2017Äê1Ô°䲼¡¶ºÚȸ¹¥»÷-½ÒÃØDeath½©Ê¬ÍøÂç±³ºóµÄÖÕ¼«½ÚÔìÕß¡·Ö®ºó£¬£¬£¬£¬£¬»¹Ïà¼ÌÔÚ¶à¸ö¶ñÒâ´úÂë¼Ò×åÖз¢ÏÖÁ˺Úȸ¹¥»÷£¬£¬£¬£¬£¬²¢°ä²¼ÁËÉî¶È·ÖÎö»ã±¨¡¶½ÒÃØBillgates½©Ê¬ÍøÂçÖеĺÚȸ¾°Ï󡷺͡¶ºÚȸ¹¥»÷£º½ÒÃØTF½©Ê¬ÎïÁªÍøºÚ¿Í±³ºóµÄºÚ¿Í¡·¡£¡£¡£¡£¡£¡£¡£ÔÚ´ËǰµÄºÚȸ·ÖÎöºÍ×·×ÙÖУ¬£¬£¬£¬£¬ÎÒÃǸ淢ÁËDeath½©Ê¬ÍøÂç±³ºóµÄÄǸö½ÚÔì×ÅÉÏǧ½©Ê¬×ÓÍøÂçµÄ³¬µÈºÚ¿Í£¬£¬£¬£¬£¬ÒÔ¼°Éî²ØÔÚBillgates½©Ê¬ÍøÂçºÍÎïÁªÍø½©Ê¬DDoSTF¼Ò×å±³ºóµÄºÚȸ¡£¡£¡£¡£¡£¡£¡£´Ë±íÎÒÃÇ»¹¾ßÌåÂÛÊöÁËÿ¸ö¼Ò×åÖÓ×°ºÚȸ¹¥»÷¡±µÄºÚ¿Íµµ´Î½á¹¹£¬£¬£¬£¬£¬ÈçDeath½©Ê¬ÍøÂçµÄÈý¼¶ºÚ¿Í½á¹¹(´óºÚȸ-ºÚȸ-ó«òë)£¬£¬£¬£¬£¬BillgatesºÍTFµÄ¶þ¼¶ºÚ¿Í½á¹¹£¨ºÚȸ-ó«ò룩£¬£¬£¬£¬£¬ÒÔ¼°¶ÔÓйصĴóºÚȸ¡¢ºÚȸºÍó«òë½øÐÐÁËÍøÂçÐÐΪ·ÖÎöºÍÉí·Ý¼ø±ð£¬£¬£¬£¬£¬²¢×öÁ˾«×¼µÄºÚ¿Í»Ïñ¡£¡£¡£¡£¡£¡£¡£
1.Dofloo½©Ê¬¼Ò×å¼ò½é
Dofloo£¬£¬£¬£¬£¬±ðÃûSpikeºÍAES.DDoS£¬£¬£¬£¬£¬ÊÇÒ»¿îÖ§³ÖARM¡¢x86¡¢mipsdµÈ¶àCPU¼Ü¹¹µÄ½©Ê¬ÍøÂ編ʽ¡£¡£¡£¡£¡£¡£¡£Dofloo¼Ò×åÒò2014ÄêÕë¶Ô±±ÃÀÖÞºÍÑÇÖÞ¶à¸ö¹ú¶È½øÐиߴï215GbpsÁ÷Á¿µÄ¹¥»÷¶øÎÅÃû£¬£¬£¬£¬£¬¶ûºó³Ö¾ÃµÄ¹¥Õ¼ÎïÁªÍøÉ豸×ÊÔ´²¢ÆµÈԵؽøÐÐÍøÂç¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÈüÃÅÌú¿ËÔÚ2016Äê°ä²¼µÄ¡¶Internet Security Thread Report¡·£¬£¬£¬£¬£¬Dofloo½©Ê¬ÍøÂç¶ñÒⷨʽλÁÐ2015Äê¶ÈIoTÁìÓò¶ñÒⷨʽÍþвÅÅÐаñµÚ¶þÃû¡£¡£¡£¡£¡£¡£¡£
2.·¢ÏÖDofloo½©Ê¬ÖеĺÚȸ
Ôڳ־õĶԽ©Ê¬ÍøÂçµÄ×êÑÐÖУ¬£¬£¬£¬£¬DoflooÒ»ÏòÊÇÎÒÃÇ¼à¿ØµÄ¶ÔÏ󡣡£¡£¡£¡£¡£¡£ÔÚ֮ǰµÄ×êÑÐÖУ¬£¬£¬£¬£¬Í¨¹ý×Ô¶¯»¯·ÖÎö¸Ã¼Ò×åµÄ¹ØÁªÑù±¾£¬£¬£¬£¬£¬·¢ÏָüÒ×åµÄ´ó²¿ÃÅÑù±¾³ÇÊÐÆô¶¯Á½¸öÐµĹ¥»÷Ị̈߳¬£¬£¬£¬£¬²¢·¢ÏÖÕâÁ½¸öÏ̴߳æÔÚÒì³£ÐÐΪ¡£¡£¡£¡£¡£¡£¡£È磺²»½ö»áÉèÖÃÑÓ³¤Æô¶¯Ị̈߳¬£¬£¬£¬£¬»¹»á³¢ÊÔ¸úÁíÒ»¸öC&C½ÚÔì¶Ë½øÐÐÏνÓͨѶ¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬ÎÒÃǶÔÕâЩÑù±¾½øÐÐÁ˽øÒ»²½µÄ·ÖÎö£¬£¬£¬£¬£¬×îÖÕÈ·¶¨¸Ã½©Ê¬Éú̬Öб»Ö²ÈëÁ˺Úȸ¡£¡£¡£¡£¡£¡£¡£
´ÓÉÏͼÄܹ»¿´³ö£¬£¬£¬£¬£¬ÓÐÈý¸öµØÖ·µÄÉÏÏ߯µ¶ÈÔ¶¸ßÓÚÆäËûµÄC&C¡£¡£¡£¡£¡£¡£¡£½áºÏÑù±¾·ÖÎö·¢ÏÖ£¬£¬£¬£¬£¬ÉÏÏßµ½ÕâÈý¸öC&CµØÖ·µÄÑù±¾ÏÕЩ¶¼ÓÐÁ½¸ö¶ÀÁ¢½ÚÔìµÄC&C£¬£¬£¬£¬£¬²¢ÇÒ½©Ê¬»ØÁ¬ÕâÈý¸öC&CµØÖ·¶¼ÊÇͨ¹ý´´½¨×ÓÏ̵߳ķ½Ê½½øÐУ¬£¬£¬£¬£¬¶øÆä¹ØÁªµÄÑù±¾µÄÁí±íÒ»¸öC&CÈ´ÊÇÔÚÖ÷Ïß³ÌÖнøÐлØÁ¬¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬Í¨¹ý¸Ã½©Ê¬µÄÕ⼸¸ö¸öÖ°Äܹ»Åж¨ÆäÖÐ×¢¶¨´æÔÚºÚȸ¹¥»÷µÄ¾°Ï󣬣¬£¬£¬£¬¶øÕâÈý¸öC&CµØÖ·¾ÍÊÇDofloo½©Ê¬Éú̬ÖеĺÚȸC&CµØÖ·£¬£¬£¬£¬£¬ÓëºÚȸC&CµØÖ·ÓйØÁªµÄÆäËûC&CµØÖ·¾ÍÊÇDofloo½©Ê¬Éú̬ÖÐó«òëºÚ¿ÍµÄC&CµØÖ·¡£¡£¡£¡£¡£¡£¡£
ÎÒÃǶÔÕâÈý¸öºÚȸC&CµØÖ·ÓйØÁªµÄó«òëC&C×öÁË·ÖÀàͳ¼Æ£¬£¬£¬£¬£¬ÈçϱíËùʾ£º
|
C&CµØÖ· |
ó«òë½©Ê¬ÍøÂçÊýÁ¿ |
|
183.60.149.199 |
189 |
|
118.193.217.144 |
282 |
|
aaa.tfddos.net |
85 |
3.Dofloo½©Ê¬ºÚȸËÝÔ´Óë»Ïñ
ͨ¹ý¶ÔÑù±¾µÄ·ÖÎö£¬£¬£¬£¬£¬½áºÏÑù±¾Öеĺ¯Êý¶¨Ãûϰ¹ß¡¢¹¥»÷Á÷Á¿Ìص㡢±äÖÖÔ´Âë×¢½âÒÔ¼°Ñù±¾·¢×÷´«²¼Ê±ÓÃÀ´É¢²¥Ñù±¾µÄHFSÃæ°å˵»°µÈÌØµã£¬£¬£¬£¬£¬ÎÒÃÇÅж¨¸Ã¼Ò×åÓɹúÄڵĺڿͱàд¡£¡£¡£¡£¡£¡£¡£Òò¶øÎÒÃÇËÝÔ´Ö¸±êËø¶¨ÔÚ¹úÄÚ£¬£¬£¬£¬£¬Í¨¹ý¶ÔºÚȸÓòÃû¡°aaa.tfddos.net¡±ÖйؼüÐÅÏ¢¡±tfddos¡±£¬£¬£¬£¬£¬ÎÒÃǹØÁªµ½Ò»¿îÃûΪ¡°Ì¨·çDDoS¡±µÄ½©Ê¬Èí¼þ¡£¡£¡£¡£¡£¡£¡£²¢ÇÒͨ¹ý½øÒ»²½·ÖÎö·¢ÏÖ£¬£¬£¬£¬£¬¸Ã½©Ê¬Èí¼þµÄÄ£°åÑù±¾ÓëDofloo½©Ê¬ÓµÓм«ÎªÀàËÆµÄÐÐΪºÍÍøÂç¸öÐÔ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬¡°Ì¨·çDDoS¡±Ôںڿͼä»îÔ¾µÄ¹¦·òͬDofloo·¢×÷¹¦·ò¾ùÔÚ2014Äê¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÒÔÉÏһϵÁеÄÖ¤¾ÝÖ¤Ã÷ËûÃÇÖ®¼ä´æÔڿ϶¨Í¬Ô´ÐÔ¡£¡£¡£¡£¡£¡£¡£ÎªÁ˽øÒ»²½È·ÈÏËûÃÇΪͳһ¿î½©Ê¬·¨Ê½£¬£¬£¬£¬£¬ÎÒÃÇ»¹ÀûÓÃbindiff¶Ô¡°Ì¨·çDDoS¡±½ÚÔì¶ËÌìÉúµÄ½©Ê¬ÓëDoflooµÄÑù±¾½øÐÐÁËÀàËÆ¶È±È¶Ô£¬£¬£¬£¬£¬·¢ÏÖÁ½Õß´úÂëÀàËÆ¶ÈΪ100%µÄ´úÂëÕ¼±È³¬¹ý98%£¬£¬£¬£¬£¬Òò¶øÄܹ»È·¶¨¡°Ì¨·çDDoS¡±¾ÍÊÇDofloo¼Ò×åµÄÒ»¸öÖ÷¿Ø¡£¡£¡£¡£¡£¡£¡£¶Ô±ÈͼÈçÏ£º
ͨ¹ý¶ÔÔçÆÚµÄ¡°Ì¨·çDDoS¡±µÄ½©Ê¬Ä£°å·¨Ê½·ÖÎö·¢ÏÖÓëDoflooºÚȸC&CÒ»ÑùµÄºóÃÅC&C£º183.60.149.199¡£¡£¡£¡£¡£¡£¡£
´Ë±í£¬£¬£¬£¬£¬Í¨¹ý¶Ô¡°Ì¨·çDDoS¡±µÄËÝÔ´·¢ÏÖ£¬£¬£¬£¬£¬ÆäÔøÔÚÍøÕ¾tfddos.comÉÏ×÷Ϊ¹Ù·½Èí¼þ±»¹«¿ªÊÛÂô£¬£¬£¬£¬£¬¸ÃÍøÕ¾¹ÌȻѡȡÁËÓëDoflooºÚȸÓòÃû¡°aaa.tfddos.net¡±²»Ò»ÑùµÄÓòÃû£¬£¬£¬£¬£¬µ«ËûÃǶ¼Ê¹ÓÃÁË¡°tfddos¡±×÷ΪÓòÃûµÄ¹Ø¼ü×Ö£¬£¬£¬£¬£¬Ò²¼´ÊÇ¡°tai£¨Ì¨£© feng£¨·ç£© ddos¡±¡£¡£¡£¡£¡£¡£¡£Òò¶øÎÒÃÇÒÔΪºóÃÅC&C£º183.60.149.199Óëaaa.tfddos.netΪͳһºÚ¿Í»òÕߺڿÍ×éÖ¯ËùΪ¡£¡£¡£¡£¡£¡£¡£
¶ÔÓÚºÚȸIP£º118.193.217.144µÄ·´²é·¢ÏÖ£¬£¬£¬£¬£¬ÔÚ2017Ä꣬£¬£¬£¬£¬ÓòÃûwap.tfddos.netºÍaaa.tfddos.netÓë¸ÃIPµØÖ·½øÐÐÁ˳־õİ󶨡£¡£¡£¡£¡£¡£¡£
ΪÁË×·×ÙDofloo½©Ê¬ÍøÂç±³ºóµÄºÚȸ£¬£¬£¬£¬£¬ÎÒÃÇÏÈÍøÂçÁËC&CÓйصÄÐÅÏ¢²¢½øÐÐÁË·ÖÎö¡£¡£¡£¡£¡£¡£¡£ÆäÖÐͨ¹ýIP£º183.60.149.199¹ØÁª³öÀ´µÄÓйØÓòÃû´ó²¿Ãű»×÷ΪɫÇéÍøÕ¾»ò²©²ÊÍøÕ¾Ê¹Ó㬣¬£¬£¬£¬²¢ÎÞ¿ÉÓÃÏßË÷¡£¡£¡£¡£¡£¡£¡£¶øtfddos.comºÍtfddos.net¶¼²ÉÈ¡ÒþÖÔ±£»£»£»£»£»¤¹æ»®£¬£¬£¬£¬£¬ÎÞ·¨½øÇ°½øÒ»²½µÄ×·Òä¡£¡£¡£¡£¡£¡£¡£
ͨ¹ý¶ûºó³Ö¾ÃµÄËÝÔ´·ÖÎö£¬£¬£¬£¬£¬ÎÒÃÇ»¹×·×Ùµ½Á˸úÚȸÔÚÏÖʵÊÀ½çÖеÄÉí·ÝÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£´ËºÚȸÊǺÓÄÏÄÏÑôÁ½¼Ò¿Æ¼¼¹«Ë¾µÄ¼àÊ£¬£¬£¬£¬£¬²¢ÇÒÒÔ80ÍòÔªÈϽÉ×ʽð³ÖÓÐÆäÖÐÒ»¼Ò¿Æ¼¼¹«Ë¾10%µÄ¹É·Ý£¬£¬£¬£¬£¬±³µØÀï´Óʺڲú»î¶¯¡£¡£¡£¡£¡£¡£¡£
4.Dofloo½©Ê¬µäÐÍÑù±¾·ÖÎö
ÓÉÓÚDoflooÖ§³Ö¶àÖÖCPU¼Ü¹¹£¬£¬£¬£¬£¬ÎÒÃÇÔÚ¶ÔÕâЩƽ̨µÄÑù±¾·ÖÎöÖз¢ÏÖ£¬£¬£¬£¬£¬ËùÓÐDoflooÖ§³ÖµÄ¼Ü¹¹£¬£¬£¬£¬£¬¶¼´æÔÚºÚȸ¾°Ï󡣡£¡£¡£¡£¡£¡£µ«Êǽ©Ê¬×÷Õß¶Ô·ÖÆçµÄ¼Ü¹¹µÄºÚȸC&C´¦ÖÃÂÔÓÐ·ÖÆç£¬£¬£¬£¬£¬Õâ¶Ô×Ô¶¯»¯·ÖÎöÒ²Ôì³ÉÁ˿϶¨µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£ÎÒÃǶԱ¾´ÎÍøÂçµÄ¹²¼Æ1200¸öÑù±¾µÄ¼Ü¹¹ËùÕ¼±ÈÀý½øÐÐÁËͳ¼Æ£¬£¬£¬£¬£¬»æÔì³ÉͼÈçÏ£º
CPU¼Ü¹¹µÄÉ¢²¼Í¼£¬£¬£¬£¬£¬¿Ï¶¨Ë®Æ½ÉÏҲ˵ÁËÈ»¸Ã¼Ò×åÈëÇÖÉ豸ÀàÐ͵ÄÉ¢²¼£¬£¬£¬£¬£¬Äܹ»¿´µ½ARMÉ豸µÄ±ÈÀý¼«¶È¸ß£¬£¬£¬£¬£¬ÕâÒ²×¢Ã÷ARMϵÄÉ豸Êܵ½ºÚȸ½ÚÔìµÄ±ÈÀý±ÈÁ¦¸ß¡£¡£¡£¡£¡£¡£¡£
½ÓÏÂÀ´ÎÒÃǶÔDofloo¼Ò×åµÄµäÐÍÑù±¾½øÐÐÁ˾ßÌåµÄ·Ö½â£¬£¬£¬£¬£¬²¢ÇÒÆ¾¾Ý´óÁ¿Ñù±¾ÌáÈ¡×ۺϳöµäÐ͵ÄͨѶÁ÷Á¿ºÍ¹¥»÷Á÷Á¿Ìصã,²¢¶ÔDofloo¼Ò×å½øÐÐÁËͬԴÐÔ·ÖÎö¡£¡£¡£¡£¡£¡£¡£
4.1 ×°ÖûúÔì
Dofloo½©Ê¬·¨Ê½µÄ×°ÖûúÔìÓУº½©Ê¬·¨Ê½ÔÚËÞÖ÷»úµÄÓÆ¾Ã»¯ÉèÖᢹý³ÌΨһÐÔÅжϺÍÊØ»¤¹ý³ÌÉèÖᣡ£¡£¡£¡£¡£¡£
½©Ê¬·¨Ê½Í¨¹ýдÈ뿪»ú×ÔÆôºÅÁîʵÏÖÓÆ¾Ã»¯¡£¡£¡£¡£¡£¡£¡£½©Ê¬·¨Ê½ÔÚÆô¶¯ºó£¬£¬£¬£¬£¬»áÊ×ÏÈ²é³Æô¶¯µÄºÅÁîÐвÎÊý, ÈôÊÇ·¢ÏÖûÓвÎÊý£¬£¬£¬£¬£¬ÄÇô¶ñÒⷨʽ»áĬÈÏÊÇÔÚ¸ÃÉ豸µÄµÚÒ»´ÎÔËÐÐ,´Ëʱ»áŲÓá°autoboot¡±º¯Êý¡£¡£¡£¡£¡£¡£¡£Ôڸú¯ÊýÖУ¬£¬£¬£¬£¬Å²Óá°system¡±º¯ÊýÖ´ÐÐϱíÖеĺÅÁ£¬£¬£¬£¬ÒÔÈ·±£¶ñÒⷨʽÔÚ¸ÃÉ豸³ÁÆôºóÈÔ¿ÉÄÜÆô¶¯ÔËÐÓ×£¡£¡£¡£¡£¡£¡£ÕâÒ²ÊÇDofloo¶ñÒⷨʽÔÚËÞÖ÷É豸ʵÏÖÓÆ¾Ã»¯µÄΨһ²½Öè¡£¡£¡£¡£¡£¡£¡£
sed -i -e '/^\r\n|\r|\n$/d' /etc/rc.local
sed -i -e '/%s/d' /etc/rc.local
sed -i -e '2 i%s/%s' /etc/rc.local
sed -i -e '2 i%s/%s start' /etc/rc.d/rc.local
sed -i -e '2 i%s/%s start' /etc/init.d/boot.local
4.2 ÉÏÏß»úÔì
4.3 ÐÄÌø»úÔì
½©Ê¬·¨Ê½ÔÚSendInfoÏß³ÌʵÏÖÁË×ÔÉíµÄÐÄÌø»úÔì¡£¡£¡£¡£¡£¡£¡£Õâ¸öÏ̵߳ÄÖØÒªÖ°ÄÜÊÇÏòó«òë½ÚÔì¶ËºÍºÚȸ½ÚÔì¶Ë·¢ËÍÐÄÌø°ü£¬£¬£¬£¬£¬ÐÄÌø°üÄÚÈÝÔ̺¬µ±Ç°CPUʹÓÃÂʺÍÍøÂçËÙ¶ÈÐÅÏ¢£¬£¬£¬£¬£¬Í¨¹ýÒÔÏÂ2¸ö²½Öè»ñÈ¡µ½ÕâЩÄÚÈÝ£º
£¨1£© ²é³¡°eth0¡±µ½¡°eth9¡±ÁìÓòÄÚÒÔÌ«Íø¿ÚµÄifconfigÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£²¢Í¨¹ý¶ÁÈ¡/proc/net/dev Ŀ¼ÐÅÏ¢À´ÍÆËãÍøÂçËÙ¶È¡£¡£¡£¡£¡£¡£¡£
£¨2£©Í¨¹ý¶ÁÈ¡/proc/statĿ¼ÏµÄÐÅÏ¢£¬£¬£¬£¬£¬»ñÈ¡cpuÊýÁ¿£¬£¬£¬£¬£¬ÍÆËãÕ¼Óðٷֱȡ£¡£¡£¡£¡£¡£¡£
±ÈÁ¦ÓÐȤµÄÊÇ£¬£¬£¬£¬£¬ÏÂÓεĺڿÍÔÚ·¢ÆðDDoS¹¥»÷µÄʱ³½£¬£¬£¬£¬£¬¿ÉÄܵ××Ó²»»áÏëµ½£¬£¬£¬£¬£¬Ö÷¿ØÖÐÏÔʾµÄ¶ñÒⷨʽµÄ¹¥»÷Á÷Á¿ËÙ¶ÈÏÕЩ¶¼ÊÇαÔìµÄ¡£¡£¡£¡£¡£¡£¡£ÎÒÃÇÔÚSendInfoÏß³ÌÖз¢ÏÖ£¬£¬£¬£¬£¬µ±¶ñÒⷨʽִÐÐDDoS¹¥»÷ʱ£¬£¬£¬£¬£¬»áŲÓá°fake_net_speed¡±º¯Êý£¬£¬£¬£¬£¬¸Ãº¯Êý»áƾ¾Ý·ÖÆçµÄDDoS¹¥»÷µÄģʽ£¬£¬£¬£¬£¬ÔÚÒ»¸ö¹Ì¶¨µÄÁìÓòÄÚαÔì¹¥»÷Á÷Á¿ËÙ¶È¡£¡£¡£¡£¡£¡£¡£ÏÂͼΪ¶Ô²¿ÃÅÍÆËãËæ»úÁ÷Á¿µÄ½ØÍ¼£º
½©Ê¬·¨Ê½Î±ÔìµÄ¹¥»÷Á÷Á¿Êý¾ÝÁìÓòÈçϱíËùʾ£º
4.4 ½ÚÔìÖ¸Áî½âÎöÓëDDoS¹¥»÷
·¢ËÍÍêÉÏÏß°üÖ®ºó£¬£¬£¬£¬£¬´Ëʱ½©Ê¬·¨Ê½»áÆÚ´ý½Ó¹Ü½ÚÔì¶ËµÄ½ÚÔìÖ¸Áî¡£¡£¡£¡£¡£¡£¡£Dofloo»áÊ×ÏȰѽÚÔìÖ¸Áî°üµÄǰËĸö×Ö½Ú×÷ΪģʽָÁîÂë½øÐнâÎö£¬£¬£¬£¬£¬ÓÉ´ËÀ´ÅжϽÓÏÂÀ´Òª½øÐеIJÙ×÷£¬£¬£¬£¬£¬ÖØÒªÖ§³ÖµÄ²Ù×÷ÓÐÈýÖÖ:
£¨2£©Ö¸ÁîÂëΪ0x6ʱ£¬£¬£¬£¬£¬½øÈëDealwithDDoSº¯Êý£¬£¬£¬£¬£¬´Ëº¯ÊýΪDDoS¹¥»÷º¯Êý£¬£¬£¬£¬£¬ËùÓÐÖ´Ðй¥»÷µÄÅжϺÍÂß¼¶¼Ôڴ˺¯ÊýÖÓ×£¡£¡£¡£¡£¡£¡£
£¨3£©Ö¸ÁîÂëΪ0x7ʱ³½£¬£¬£¬£¬£¬Å²ÓÃkillº¯Êý£¬£¬£¬£¬£¬ÖÕÖ¹¹ý³Ì¡£¡£¡£¡£¡£¡£¡£
ͬʱDofloo¼Ò×å¶Ô½ÚÔìÖ¸Áî½øÐÐÁË128λµÄAES¼ÓÃÜ£¬£¬£¬£¬£¬Õâ¸ö¸öÐÔ´ó´óÔö³¤ÁË¶ÔÆä½ÚÔìÖ¸ÁîÁ÷Á¿¼à¿ØºÍʶ´ËÍâÄѶȡ£¡£¡£¡£¡£¡£¡£ÎÒÃǶÔÍøÂçµ½µÄÑù±¾½øÐзÖÎöºó·¢ÏÖ£¬£¬£¬£¬£¬ËùÓмܹ¹Ï½©Ê¬·¨Ê½ÓÃÀ´½âÃܵÄKEY¶¼ÊÇÒ»ÑùµÄ£¬£¬£¬£¬£¬ÕâÒ²×¢Ã÷»¥ÁªÍøÖÐDofloo½©Ê¬¼Ò×åµÄÑù±¾¶¼À´×Ôͳһ¸öÄ£°æ¡£¡£¡£¡£¡£¡£¡£KEYÈçÏÂËùʾ£º
unsignedcharaes_key[] = { 0x2b, 0x7e, 0x15, 0x16, 0x28, 0xae, 0xd2, 0xa6, 0xab, 0xf7, 0x15, 0x88, 0x9, 0xcf, 0x4f, 0x3c };
ÎÒÃÇÄ£ÄâÁËδ¼ÓÃܵĽÚÔìÖ¸Á³ýȥǰ4¸ö×÷ΪģʽָÁîÂëµÄ×Ö½Ú£©ÔÚÄÚ´æÖеIJ¼¾Ö,Æä½ÚÔìÖ¸ÁîµÄ¸÷¸ö×ֶεÄÔ¢ÒâÈçÏÂͼËùʾ£º
µ±½øÈëµ½DealwithDDoSº¯Êýʱ£¬£¬£¬£¬£¬½©Ê¬·¨Ê½Æ¾¾ÝÖ¸Á£¬£¬£¬£¬Æô¶¯·ÖÆçµÄ¹¥»÷Ï̡߳£¡£¡£¡£¡£¡£¡£Dofloo¼Ò×å²»½öÓµÓÐSYN¡¢HTTPµÈ´«Í³µÄ¹¥»÷²½Ö裬£¬£¬£¬£¬»¹ÓµÓÐÀûÓÃUDPºÍ̸µÄ·´Éä·Å´óµÄ¹¥»÷·½Ê½£¬£¬£¬£¬£¬ºÃ±ÈDNS·Å´ó¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÏÂͼΪDofloo¿ÉÌáÒéµÄµäÐ͵ÄDDoS¹¥»÷µÄ²½Ö裺
²¢ÇÒÎÒÃǶÔDoflooµÄ¹¥»÷²½Öè½øÐÐÁË·ÖÎö×ܽᣬ£¬£¬£¬£¬²¢¶Ô²¿ÃŹ¥»÷²½ÖèµÄÁ÷Á¿ÌØµã½øÐÐÁËÌáÈ¡£¬£¬£¬£¬£¬Ôì×÷Á÷Á¿Ìصã±íÈçÏ£º
ÎÒÃÇÔÚ·ÖÎö¹¥»÷Ï̵߳Äʱ³½£¬£¬£¬£¬£¬·¢ÏÖARM¼Ü¹¹µÄ¶ñÒâÑù±¾Ã¿´Î¹¥»÷´´½¨µÄ¹¥»÷Ï̼߳«¶È¶à£¬£¬£¬£¬£¬µ¥´Î¹¥»÷Ö¸Áî¿É´´½¨¼¸ÖÖÉõÖÁÊ®¼¸ÖÖ·ÖÆçÀàÐ͵Ĺ¥»÷Ï̡߳£¡£¡£¡£¡£¡£¡£½áºÏÑù±¾CPUµÄÉ¢²¼£¬£¬£¬£¬£¬ÎÒÃÇÄܹ»µÃÖªARMÉ豸ϵÄDofloo¶ñÒⷨʽÊǸý©Ê¬¼Ò×åµÄÖ÷Á¦£¬£¬£¬£¬£¬ÔÚDDoS¹¥»÷ÖÐÌṩÁËÖØÒªµÄÁ÷Á¿Ö§³Ö¡£¡£¡£¡£¡£¡£¡£
ͬʱƾ¾Ý¼à¿Øµ½Dofloo¹¥»÷º¹Ç࣬£¬£¬£¬£¬·¢ÏָüÒ×åÖØÒªµÄ¹¥»÷·½Ê½ÒÔUDP Flood ΪÖ÷£¬£¬£¬£¬£¬½üÄêÀ´ºÚ¿ÍÒ²Ô½À´Ô½Ï²»¶DNSºÍNTPµÈ·´Éä·Å´ó¹¥»÷¼¿Á©À´¶Ô·þÎñÆ÷½øÇ°½ø¹¥ £¬£¬£¬£¬£¬DoflooµÄ¹¥»÷·½Ê½Õ¼±ÈÒ²Ó¡Ö¤ÁËÕâÒ»µã¡£¡£¡£¡£¡£¡£¡£Í¬Ê±ÎÒÃÇÒ²Äܹ»¿´µ½Layer7²ãµÄCC_FloodºÍLayer4²ãµÄTCP_Flood¡¢SYN Flood×÷Ϊ´«Í³µÄDDoSµÄ¹¥»÷·½Ê½£¬£¬£¬£¬£¬ÆäÕ¼±ÈÒ²Ò»Ïò½ÏΪ²»±ä¡£¡£¡£¡£¡£¡£¡£²¢ÇÒÎÒÃÇÆ¾¾ÝÓйصĵý±¨Êý¾ÝµÃÖª£¬£¬£¬£¬£¬DoflooµÄ¹¥»÷Á¿Ïà¶ÔÓÚÆäËûµÄ¼Ò×å½ÏÉÙ£¬£¬£¬£¬£¬ÎÒÃÇ·ÖÎö´§Ä¦Doflooÿ´Î·¢Æð¹¥»÷ʱ¿ªÆôÁË´óÁ¿µÄ¹¥»÷Ị̈߳¬£¬£¬£¬£¬ÕâÑùÄܼӴ󷢰üÁ¿£¬£¬£¬£¬£¬¼±¾çµ¼ÖÂÖ¸±ê·þÎñÆ÷å´»ú¡£¡£¡£¡£¡£¡£¡£
4.5 ͬԴÐÔ·ÖÎö
ÎÒÃǹ۲쵽ºÃ¶àɱ¶¾Èí¼þ¶ÔDofloo¼Ò×巨ʽÓÐ·ÖÆçµÄ¶¨Ãû·½Ê½£¬£¬£¬£¬£¬ÉõÖÁ¼ø±ðΪÆäËû¼Ò×åµÄ·¨Ê½£¬£¬£¬£¬£¬Òò¶øÎªÁËÈ·¶¨Dofloo¼Ò×åµÄÔ´Âë×é³É£¬£¬£¬£¬£¬ÎÒÃÇ¶ÔÆä½øÐÐÁËͬԴÐÔ·ÖÎö¡£¡£¡£¡£¡£¡£¡£
²¢ÇÒ»¹Äܹ»¿´µ½Mr.BlackͬÑùÓÐͬÃûµÄ£¬£¬£¬£¬£¬ÌáÒéDDoS¹¥»÷µÄº¯ÊýDealWithDDoS£¬£¬£¬£¬£¬ÆäÌáÒé¹¥»÷µÄ½ÚÔìÖ¸Áî±àÂëÒ²Ò»Ñù¡£¡£¡£¡£¡£¡£¡£
Ö»²»ÍâMr.BlackÖнöÓÐ5ÖÖDDoS¹¥»÷·½Ê½¡£¡£¡£¡£¡£¡£¡£Í¨¹ý²éÔÄMr.BlackµÄÔ´Â룬£¬£¬£¬£¬·¢ÏÖMr.BlackÔ´ÂëÖв¢Ã»ÓкÚȸºóÃÅÏ̺߳ÍAES¼ÓÃÜ£¬£¬£¬£¬£¬Ã»ÓÐÔ¶¿Ø²¿ÃÅ£¬£¬£¬£¬£¬½öÄÜÌáÒéDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£Òò¶ø´§Ä¦DoflooΪ²Î¿¼Mr.Black´úÂë¸ü¸ÄºóµÄ±äÖÖ¡£¡£¡£¡£¡£¡£¡£
ÔÚDnsAmpÓëDofloo¼Ò×åµÄ¶Ô±ÈÖУ¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÔìä´úÂë²î¾à½Ï´ó£¬£¬£¬£¬£¬µ«ÊÇÖØÒª¹¥»÷´úÂëÒÔ¼°·¨Ê½ÕûÌåÉè¼ÆË¼Â·±ÈÁ¦ÀàËÆ¡£¡£¡£¡£¡£¡£¡£ÔÚDnsAmp¼Ò×åÖУ¬£¬£¬£¬£¬Óƾû¯ÒÀÈ»ÊÇͨ¹ýÉèÖá°/etc/rc.d/rc.local¡±À´Î¬³Ö¿ª»ú×ÔÆô£¬£¬£¬£¬£¬²¢ÇÒÔÚÆô¶¯ºóͬDoflooÒ»Ñù£¬£¬£¬£¬£¬»áÊ×ÏÈÈ·¶¨¹ý³ÌµÄΨһÐÔ¡£¡£¡£¡£¡£¡£¡£¶øËüµÄ¹¥»÷Ï̡߳°AttackWorker¡±ÖУ¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖͬDoflooÒ»ÑùÓµÓÐͬÃûµÄ¹¥»÷º¯Êý¡°DealwithDDoS¡±£¬£¬£¬£¬£¬Ö»²»Íâ½öÓÐ4ÖÖ¹¥»÷·½Ê½£¬£¬£¬£¬£¬±ðÀëΪudp£¬£¬£¬£¬£¬icmp£¬£¬£¬£¬£¬dnsAmp,syn¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»DnsAmpÓëDoflooÕûÌå´úÂëÀàËÆ¶È²»ÊÇÌ«¸ß£¬£¬£¬£¬£¬µ«ÊÇÆ¾¾ÝÆäÖØÒª¹¥»÷´úÂëºÍ·¨Ê½ÕûÌåµÄÉè¼ÆË¼Â·£¬£¬£¬£¬£¬ÎÒÃÇ´§Ä¦¶þÕßÓµÓйØÁªÐÔ£¬£¬£¬£¬£¬ÖÁÉÙDnsAmpΪ²Î¿¼Dofloo´úÂë¶ø²úÉúµÄÀàËÆ±äÖÖ¡£¡£¡£¡£¡£¡£¡£²¿ÃŶԱÈͼÈçÏ£º
5.×Ü ½á
±¾Æª»ã±¨³Áµã¶ÔDofloo½©Ê¬ÍøÂç¼Ò×åÖдæÔڵĺÚȸ¾°Ïó½øÐÐÁË·ÖÎöÅû¶£¬£¬£¬£¬£¬²¢ËÝÔ´×·×ÙºÚȸ£¬£¬£¬£¬£¬²ú³öºÚȸ»Ïñ¡£¡£¡£¡£¡£¡£¡£Í¬Ê±¶ÔµäÐ͵Ľ©Ê¬Ñù±¾½øÐÐÁË·ÖÎö£¬£¬£¬£¬£¬ÌáÈ¡×ۺϳöÉÏÏß¡¢ÐÄÌø¡¢½ÚÔìÖ¸ÁîºÍÌáÒé¹¥»÷µÄÁ÷Á¿Ìåʽ¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Îļþ£º
1¡¢DDoS-Capable IoT Malwares: Comparative Analysis and Mirai Investigation
https://www.hindawi.com/journals/scn/2018/7178164/
http://www.antiy.net/p/2017-global-botnet-ddos-attack-threat-report
https://www.insight.com/content/dam/insight-web/en_US/article-images/whitepapers/partner-whitepapers/Internet%20Security%20Threat%20Report.pdf
http://blog.malwaremustdie.org/2014/09/tango-down-report-of-op-china-elf-ddoser.html


¾©¹«Íø°²±¸11010802024551ºÅ