Proof-of-Concept Code for Memcached DDoS Attacks Published Online

Faybert

Level 24
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Jan 8, 2017
1,321
8,958
2,279
Brazil
Proof-of-concept code to run massive DDoS attacks using unsecured Memcached servers has been published online this week, along with a ready-made list of over 17,000 IP addresses belonging to vulnerable Memcached servers.

Two, and not one, of such proof-of-concept (PoC) utilities, have been released, both uniques in their own way.

PoC #1
The first is a Python script named Memcacrashed.py that scans Shodan for IPs of vulnerable Memcached servers and allows a user to launch a DDoS attack against a desired target within seconds of running the tool.

The creator of this tool is —surprisingly— the infosec researcher behind the Spuz.me blog.
...
...
...