ºÚȸ¹¥»÷£ºÉî¶ÈÆÊÎö²¢ËÝÔ´Dofloo½©Ê¬ÎïÁªÍø±³ºóµÄ¡°ºÚȸ¡±
Ðû²¼Ê±¼ä 2019-05-31
2019Äê4ÔÂ×îÏÈ£¬£¬£¬£¬£¬£¬¿Ðý¹ú¼ÊÓÎÏ·ADLabÊӲ쵽ConfluenceÔ¶³Ì´úÂëÖ´ÐÐÎó²îCVE-2019-3396±»Dofloo½©Ê¬ÍøÂç¼Ò×åÓÃÓÚ¹¥Õ¼×°±¸×ÊÔ´£¬£¬£¬£¬£¬£¬Confluence ÊÇÒ»¸öרҵµÄÆóҵ֪ʶÖÎÀíÓëÐͬÈí¼þ£¬£¬£¬£¬£¬£¬³£ÓÃÓÚ¹¹½¨ÆóÒµwiki¡£¡£¡£¡£¡£±¾´ÎÎó²îÊÇÓÉÓÚConfluence Server ºÍConfluence DataÖеÄWidget Connector±£´æÐ§ÀͶËÄ£°å×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß½á¹¹ÌØ¶¨ÇëÇó¿ÉÔ¶³Ì±éÀúЧÀÍÆ÷í§ÒâÎļþ£¬£¬£¬£¬£¬£¬ÉõÖÁʵÏÖÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£¡£ÓÐÒâ˼µÄÊÇDofloo½©Ê¬ÍøÂç¼Ò×å²»µ«×îÏÈʹÓøßΣÎó²î¾ÙÐй¥»÷£¬£¬£¬£¬£¬£¬²¢ÇÒÆä±³ºóµÄºÚ¿Í»¹Ê¹ÓÃÒ»ÖÖ¸ü¾ßÓ°ÏìÁ¦µÄ¡°ºÚȸ¹¥»÷¡±À´ÈëÇÖ¹¤ÒµÁ´£¬£¬£¬£¬£¬£¬ÒÔÕÆ¿ØÔ½·¢Ç¿Ê¢µÄÍøÂç¹¥»÷×ÊÔ´¡£¡£¡£¡£¡£¶øÔÚ´Ëǰ£¬£¬£¬£¬£¬£¬ÎÒÃÇÒѾ×öÁ˳¤Ê±¼äµÄÓëDofloo½©Ê¬¼Ò×åºÚ¿Í¹¤ÒµÁ´Ïà¹ØµÄÑо¿£¬£¬£¬£¬£¬£¬ÇÒÒѾȷ¶¨ÁËÕâÖ֯ձ鱣´æÓÚDofloo¼Ò×åÖеġ°ºÚȸ¹¥»÷Õ÷Ïó¡±£¬£¬£¬£¬£¬£¬²¢¶ÔÆäÖеġ°ºÚȸ¡±¾ÙÐÐÁ˺ã¾Ã×·×ÙÓëÆÊÎö¡£¡£¡£¡£¡£
´Ë´¦£¬£¬£¬£¬£¬£¬ÎÒÃÇËùÌá³ö¡°ºÚȸ¹¥»÷¡±²»µ«ÊÇÒ»ÖÖ¸ßЧµÄºÚ¿Í¹¥»÷ÊֶΣ¬£¬£¬£¬£¬£¬²¢ÇÒ¸üÊÇÒ»ÖÖ¹¤ÒµÁ´¼¶±ðµÄ¹¥»÷ÒªÁ죬£¬£¬£¬£¬£¬Ò»Ñùƽ³£ÎªÐþÉ«¹¤ÒµÁ´ÉÏÓκڿÍËùΪ¡£¡£¡£¡£¡£ºÚȸ¹¥»÷Ó빩ӦÁ´¹¥»÷ÓÐÒìÇúͬ¹¤Ö®Ã£¬£¬£¬£¬£¬Ö»Êǹ¥»÷µÄÄ¿µÄ²»ÊÇͨÀýµÄ¹¤ÒµÁ´£¬£¬£¬£¬£¬£¬¶øÊǺڿ͹¤ÒµÁ´£»£»£»£»£»£»Êܹ¥»÷Á´µÄ×îºóÒ²²»ÊÇͨË×Óû§£¬£¬£¬£¬£¬£¬¶øÊǼ«¾ßΣº¦ÐԵĺڿÍȺÌå¡£¡£¡£¡£¡£ÔÚÍøÂçÇå¾²ÓëºÚ¿Í¹¤ÒµÁ´µÄºã¾Ã¶Ô¿¹£¬£¬£¬£¬£¬£¬Ê¹µÃ¸Ã¹¤ÒµÁ´ÈÕ½¥³ÉÊìÇÒÖØ´ó£¬£¬£¬£¬£¬£¬²¢ÐγÉÁËÒ»¸öÖØ´óµÄºÚ¿ÍÉú̬ϵͳ£¬£¬£¬£¬£¬£¬¶øÔÚÀûÒæºÍÉúÑÄÐèÇóµÄÇýʹÏ£¬£¬£¬£¬£¬£¬ºÚȸÕ÷ÏóËÆºõÄð³ÉÁ˱ض¨£¬£¬£¬£¬£¬£¬ÉõÖÁÔÚʳÎïÁ´µÄÉ϶˽ø»¯³öÁ˺ÚȸÉú̬£¬£¬£¬£¬£¬£¬ÈçDeath½©Ê¬ÍøÂçµÄ¡°´óºÚȸ-ºÚȸ-ó«ò롱¡£¡£¡£¡£¡£
×Ô¿Ðý¹ú¼ÊÓÎÏ·ADLabÓÚ2016ÄêÍ··¢Ã÷ºÚȸ¹¥»÷²¢ÓÚ2017Äê1ÔÂÐû²¼¡¶ºÚȸ¹¥»÷-½ÒÃØDeath½©Ê¬ÍøÂç±³ºóµÄ×îÖÕ¿ØÖÆÕß¡·Ö®ºó£¬£¬£¬£¬£¬£¬»¹Ïà¼ÌÔÚ¶à¸ö¶ñÒâ´úÂë¼Ò×åÖз¢Ã÷Á˺Úȸ¹¥»÷£¬£¬£¬£¬£¬£¬²¢Ðû²¼ÁËÉî¶ÈÆÊÎö±¨¸æ¡¶½ÒÃØBillgates½©Ê¬ÍøÂçÖеĺÚȸÕ÷Ï󡷺͡¶ºÚȸ¹¥»÷£º½ÒÃØTF½©Ê¬ÎïÁªÍøºÚ¿Í±³ºóµÄºÚ¿Í¡·¡£¡£¡£¡£¡£ÔÚ´ËǰµÄºÚȸÆÊÎöºÍ×·×ÙÖУ¬£¬£¬£¬£¬£¬ÎÒÃÇ½ÒÆÆÁËDeath½©Ê¬ÍøÂç±³ºóµÄËÈË¿ØÖÆ×ÅÉÏǧ½©Ê¬×ÓÍøÂçµÄ³¬µÈºÚ¿Í£¬£¬£¬£¬£¬£¬ÒÔ¼°Éî²ØÔÚBillgates½©Ê¬ÍøÂçºÍÎïÁªÍø½©Ê¬DDoSTF¼Ò×å±³ºóµÄºÚȸ¡£¡£¡£¡£¡£±ðµÄÎÒÃÇ»¹ÏêϸÐðÊöÁËÿ¸ö¼Ò×åÖС°ºÚȸ¹¥»÷¡±µÄºÚ¿ÍÌõÀí½á¹¹£¬£¬£¬£¬£¬£¬ÈçDeath½©Ê¬ÍøÂçµÄÈý¼¶ºÚ¿Í½á¹¹(´óºÚȸ-ºÚȸ-ó«òë)£¬£¬£¬£¬£¬£¬BillgatesºÍTFµÄ¶þ¼¶ºÚ¿Í½á¹¹£¨ºÚȸ-ó«ò룩£¬£¬£¬£¬£¬£¬ÒÔ¼°¶ÔÏà¹ØµÄ´óºÚȸ¡¢ºÚȸºÍó«òë¾ÙÐÐÁËÍøÂçÐÐΪÆÊÎöºÍÉí·Ýʶ±ð£¬£¬£¬£¬£¬£¬²¢×öÁ˾«×¼µÄºÚ¿Í»Ïñ¡£¡£¡£¡£¡£
1.Dofloo½©Ê¬¼Ò×å¼ò½é
Dofloo£¬£¬£¬£¬£¬£¬ÓÖÃûSpikeºÍAES.DDoS£¬£¬£¬£¬£¬£¬ÊÇÒ»¿îÖ§³ÖARM¡¢x86¡¢mipsdµÈ¶àCPU¼Ü¹¹µÄ½©Ê¬ÍøÂç³ÌÐò¡£¡£¡£¡£¡£Dofloo¼Ò×åÒò2014ÄêÕë¶Ô±±ÃÀÖÞºÍÑÇÖÞ¶à¸ö¹ú¼Ò¾ÙÐиߴï215GbpsÁ÷Á¿µÄ¹¥»÷¶ø×ÅÃû£¬£¬£¬£¬£¬£¬ÒÔºóºã¾ÃµÄ¹¥Õ¼ÎïÁªÍø×°±¸×ÊÔ´²¢ÆµÈԵؾÙÐÐÍøÂç¹¥»÷»î¶¯¡£¡£¡£¡£¡£Æ¾Ö¤ÈüÃÅÌú¿ËÔÚ2016ÄêÐû²¼µÄ¡¶Internet Security Thread Report¡·£¬£¬£¬£¬£¬£¬Dofloo½©Ê¬ÍøÂç¶ñÒâ³ÌÐòλÁÐ2015Äê¶ÈIoTÁìÓò¶ñÒâ³ÌÐòÍþвÅÅÐаñµÚ¶þÃû¡£¡£¡£¡£¡£

2.·¢Ã÷Dofloo½©Ê¬ÖеĺÚȸ
ÔÚºã¾ÃµÄ¶Ô½©Ê¬ÍøÂçµÄÑо¿ÖУ¬£¬£¬£¬£¬£¬DoflooÒ»Ö±ÊÇÎÒÃÇ¼à¿ØµÄ¹¤¾ß¡£¡£¡£¡£¡£ÔÚ֮ǰµÄÑо¿ÖУ¬£¬£¬£¬£¬£¬Í¨¹ý×Ô¶¯»¯ÆÊÎö¸Ã¼Ò×åµÄ¹ØÁªÑù±¾£¬£¬£¬£¬£¬£¬·¢Ã÷¸Ã¼Ò×åµÄ´ó²¿·ÖÑù±¾¶¼»áÆô¶¯Á½¸öÐµĹ¥»÷Ị̈߳¬£¬£¬£¬£¬£¬²¢·¢Ã÷ÕâÁ½¸öÏ̱߳£´æÒì³£ÐÐΪ¡£¡£¡£¡£¡£È磺²»µ«»áÉèÖÃÑÓ³ÙÆô¶¯Ị̈߳¬£¬£¬£¬£¬£¬»¹»áʵÑé¸úÁíÒ»¸öC&C¿ØÖƶ˾ÙÐÐÅþÁ¬Í¨Ñ¶¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬ÎÒÃǶÔÕâЩÑù±¾¾ÙÐÐÁ˽øÒ»²½µÄÆÊÎö£¬£¬£¬£¬£¬£¬×îÖÕÈ·¶¨¸Ã½©Ê¬Éú̬Öб»Ö²ÈëÁ˺Úȸ¡£¡£¡£¡£¡£
´ÓÉÏͼ¿ÉÒÔ¿´³ö£¬£¬£¬£¬£¬£¬ÓÐÈý¸öµØµãµÄÉÏÏ߯µ¶ÈÔ¶¸ßÓÚÆäËûµÄC&C¡£¡£¡£¡£¡£Á¬ÏµÑùÌìÖ°Îö·¢Ã÷£¬£¬£¬£¬£¬£¬ÉÏÏßµ½ÕâÈý¸öC&CµØµãµÄÑù±¾ÏÕЩ¶¼ÓÐÁ½¸ö×ÔÁ¦¿ØÖƵÄC&C£¬£¬£¬£¬£¬£¬²¢ÇÒ½©Ê¬»ØÁ¬ÕâÈý¸öC&CµØµã¶¼ÊÇͨ¹ý½¨Éè×ÓÏ̵߳ķ½·¨¾ÙÐУ¬£¬£¬£¬£¬£¬¶øÆä¹ØÁªµÄÑù±¾µÄÁíÍâÒ»¸öC&CÈ´ÊÇÔÚÖ÷Ïß³ÌÖоÙÐлØÁ¬¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬Í¨¹ý¸Ã½©Ê¬µÄÕ⼸¸öÌØÕ÷¿ÉÒԶ϶¨ÆäÖп϶¨±£´æºÚȸ¹¥»÷µÄÕ÷Ï󣬣¬£¬£¬£¬£¬¶øÕâÈý¸öC&CµØµã¼´ÊÇDofloo½©Ê¬Éú̬ÖеĺÚȸC&CµØµã£¬£¬£¬£¬£¬£¬ÓëºÚȸC&CµØµãÏà¹ØÁªµÄÆäËûC&CµØµã¼´ÊÇDofloo½©Ê¬Éú̬ÖÐó«òëºÚ¿ÍµÄC&CµØµã¡£¡£¡£¡£¡£
ÎÒÃǶÔÕâÈý¸öºÚȸC&CµØµãÏà¹ØÁªµÄó«òëC&C×öÁË·ÖÀàͳ¼Æ£¬£¬£¬£¬£¬£¬ÈçϱíËùʾ£º
C&CµØµã |
ó«òë½©Ê¬ÍøÂçÊýÄ¿ |
183.60.149.199 |
189 |
118.193.217.144 |
282 |
aaa.tfddos.net |
85 |
3.Dofloo½©Ê¬ºÚȸËÝÔ´Óë»Ïñ
ͨ¹ý¶ÔÑù±¾µÄÆÊÎö£¬£¬£¬£¬£¬£¬Á¬ÏµÑù±¾Öеĺ¯ÊýÃüÃûϰ¹ß¡¢¹¥»÷Á÷Á¿ÌØÕ÷¡¢±äÖÖÔ´Âë×¢ÊÍÒÔ¼°Ñù±¾±¬·¢Èö²¥Ê±ÓÃÀ´É¢²¥Ñù±¾µÄHFSÃæ°åÓïÑÔµÈÌØÕ÷£¬£¬£¬£¬£¬£¬ÎÒÃÇÅжϸüÒ×åÓɺ£Äڵĺڿͱàд¡£¡£¡£¡£¡£ÓÚÊÇÎÒÃÇËÝÔ´Ä¿µÄËø¶¨ÔÚº£ÄÚ£¬£¬£¬£¬£¬£¬Í¨¹ý¶ÔºÚȸÓòÃû¡°aaa.tfddos.net¡±ÖÐÒªº¦ÐÅÏ¢¡±tfddos¡±£¬£¬£¬£¬£¬£¬ÎÒÃǹØÁªµ½Ò»¿îÃûΪ¡°Ì¨·çDDoS¡±µÄ½©Ê¬Èí¼þ¡£¡£¡£¡£¡£²¢ÇÒͨ¹ý½øÒ»²½ÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬£¬¸Ã½©Ê¬Èí¼þµÄÄ£°åÑù±¾ÓëDofloo½©Ê¬¾ßÓм«ÎªÏàËÆµÄÐÐΪºÍÍøÂçÌØÕ÷¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¡°Ì¨·çDDoS¡±Ôںڿͼä»îÔ¾µÄʱ¼äͬDofloo±¬·¢Ê±¼ä¾ùÔÚ2014Äê¡£¡£¡£¡£¡£Æ¾Ö¤ÒÔÉÏһϵÁеÄÖ¤¾Ý֤ʵËûÃÇÖ®¼ä±£´æÒ»¶¨Í¬Ô´ÐÔ¡£¡£¡£¡£¡£ÎªÁ˽øÒ»²½È·ÈÏËûÃÇΪͳһ¿î½©Ê¬³ÌÐò£¬£¬£¬£¬£¬£¬ÎÒÃÇ»¹Ê¹ÓÃbindiff¶Ô¡°Ì¨·çDDoS¡±¿ØÖƶËÌìÉúµÄ½©Ê¬ÓëDoflooµÄÑù±¾¾ÙÐÐÁËÏàËÆ¶È±È¶Ô£¬£¬£¬£¬£¬£¬·¢Ã÷Á½Õß´úÂëÏàËÆ¶ÈΪ100%µÄ´úÂëÕ¼±ÈÁè¼Ý98%£¬£¬£¬£¬£¬£¬Òò´Ë¿ÉÒÔÈ·¶¨¡°Ì¨·çDDoS¡±¼´ÊÇDofloo¼Ò×åµÄÒ»¸öÖ÷¿Ø¡£¡£¡£¡£¡£±ÈÕÕͼÈçÏ£º
ͨ¹ý¶ÔÔçÆÚµÄ¡°Ì¨·çDDoS¡±µÄ½©Ê¬Ä£°å³ÌÐòÆÊÎö·¢Ã÷ÓëDoflooºÚȸC&CÏàͬµÄºóÃÅC&C£º183.60.149.199¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬Í¨¹ý¶Ô¡°Ì¨·çDDoS¡±µÄËÝÔ´·¢Ã÷£¬£¬£¬£¬£¬£¬ÆäÔøÔÚÍøÕ¾tfddos.comÉÏ×÷Ϊ¹Ù·½Èí¼þ±»¹ûÕæÊÛÂô£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾ËäÈ»½ÓÄÉÁËÓëDoflooºÚȸÓòÃû¡°aaa.tfddos.net¡±·×ÆçÑùµÄÓòÃû£¬£¬£¬£¬£¬£¬µ«ËûÃǶ¼Ê¹ÓÃÁË¡°tfddos¡±×÷ΪÓòÃûµÄÒªº¦×Ö£¬£¬£¬£¬£¬£¬Ò²¼´ÊÇ¡°tai£¨Ì¨£© feng£¨·ç£© ddos¡±¡£¡£¡£¡£¡£Òò¶øÎÒÃÇÒÔΪºóÃÅC&C£º183.60.149.199Óëaaa.tfddos.netΪͳһºÚ¿Í»òÕߺڿÍ×éÖ¯ËùΪ¡£¡£¡£¡£¡£
¹ØÓÚºÚȸIP£º118.193.217.144µÄ·´²é·¢Ã÷£¬£¬£¬£¬£¬£¬ÔÚ2017Ä꣬£¬£¬£¬£¬£¬ÓòÃûwap.tfddos.netºÍaaa.tfddos.netÓë¸ÃIPµØµã¾ÙÐÐÁ˺ã¾ÃµÄ°ó¶¨¡£¡£¡£¡£¡£
ΪÁË×·×ÙDofloo½©Ê¬ÍøÂç±³ºóµÄºÚȸ£¬£¬£¬£¬£¬£¬ÎÒÃÇÏÈÍøÂçÁËC&CÏà¹ØµÄÐÅÏ¢²¢¾ÙÐÐÁËÆÊÎö¡£¡£¡£¡£¡£ÆäÖÐͨ¹ýIP£º183.60.149.199¹ØÁª³öÀ´µÄÏà¹ØÓòÃû´ó²¿·Ö±»×÷ΪɫÇéÍøÕ¾»ò²©²ÊÍøÕ¾Ê¹Ó㬣¬£¬£¬£¬£¬²¢ÎÞ¿ÉÓÃÏßË÷¡£¡£¡£¡£¡£¶øtfddos.comºÍtfddos.net¶¼½ÓÄÉÒþ˽±£»£»£»£»£»£»¤¼Æ»®£¬£¬£¬£¬£¬£¬ÎÞ·¨¾ÙÐнøÒ»²½µÄ×·ËÝ¡£¡£¡£¡£¡£
ͨ¹ýÒÔºóºã¾ÃµÄËÝÔ´ÆÊÎö£¬£¬£¬£¬£¬£¬ÎÒÃÇ»¹×·×Ùµ½Á˸úÚȸÔÚÏÖʵÌìÏÂÖеÄÉí·ÝÐÅÏ¢¡£¡£¡£¡£¡£´ËºÚȸÊǺÓÄÏÄÏÑôÁ½¼Ò¿Æ¼¼¹«Ë¾µÄ¼àÊ£¬£¬£¬£¬£¬£¬²¢ÇÒÒÔ80ÍòÔªÈϽÉ×ʽð³ÖÓÐÆäÖÐÒ»¼Ò¿Æ¼¼¹«Ë¾10%µÄ¹É·Ý£¬£¬£¬£¬£¬£¬±³µØÀï´Óʺڲú»î¶¯¡£¡£¡£¡£¡£

4.Dofloo½©Ê¬µä·¶ÑùÌìÖ°Îö
ÓÉÓÚDoflooÖ§³Ö¶àÖÖCPU¼Ü¹¹£¬£¬£¬£¬£¬£¬ÎÒÃÇÔÚ¶ÔÕâЩƽ̨µÄÑùÌìÖ°ÎöÖз¢Ã÷£¬£¬£¬£¬£¬£¬ËùÓÐDoflooÖ§³ÖµÄ¼Ü¹¹£¬£¬£¬£¬£¬£¬¶¼±£´æºÚȸÕ÷Ï󡣡£¡£¡£¡£¿ÉÊǽ©Ê¬×÷Õß¶Ô²î±ðµÄ¼Ü¹¹µÄºÚȸC&C´¦Öóͷ£ÂÔÓвî±ð£¬£¬£¬£¬£¬£¬Õâ¶Ô×Ô¶¯»¯ÆÊÎöÒ²Ôì³ÉÁËÒ»¶¨µÄÓ°Ïì¡£¡£¡£¡£¡£ÎÒÃǶԱ¾´ÎÍøÂçµÄ¹²¼Æ1200¸öÑù±¾µÄ¼Ü¹¹ËùÕ¼±ÈÀý¾ÙÐÐÁËͳ¼Æ£¬£¬£¬£¬£¬£¬»æÖƳÉͼÈçÏ£º

CPU¼Ü¹¹µÄÂþÑÜͼ£¬£¬£¬£¬£¬£¬Ò»¶¨Ë®Æ½ÉÏҲ˵Ã÷Îú¸Ã¼Ò×åÈëÇÖ×°±¸ÀàÐ͵ÄÂþÑÜ£¬£¬£¬£¬£¬£¬¿ÉÒÔ¿´µ½ARM×°±¸µÄ±ÈÀýºÜÊǸߣ¬£¬£¬£¬£¬£¬ÕâҲ˵Ã÷ARMϵÄ×°±¸Êܵ½ºÚȸ¿ØÖƵıÈÀý½ÏÁ¿¸ß¡£¡£¡£¡£¡£
½ÓÏÂÀ´ÎÒÃǶÔDofloo¼Ò×åµÄµä·¶Ñù±¾¾ÙÐÐÁËÏêϸµÄÆÊÎö£¬£¬£¬£¬£¬£¬²¢ÇÒÆ¾Ö¤´ó×ÚÑù±¾ÌáÈ¡¹éÄɳöµä·¶µÄͨѶÁ÷Á¿ºÍ¹¥»÷Á÷Á¿ÌØÕ÷,²¢¶ÔDofloo¼Ò×å¾ÙÐÐÁËͬԴÐÔÆÊÎö¡£¡£¡£¡£¡£
4.1 ×°ÖûúÖÆ
Dofloo½©Ê¬³ÌÐòµÄ×°ÖûúÖÆÓУº½©Ê¬³ÌÐòÔÚËÞÖ÷»úµÄ³¤ÆÚ»¯ÉèÖá¢Àú³ÌΨһÐÔÅжϺÍÊØ»¤Àú³ÌÉèÖᣡ£¡£¡£¡£
½©Ê¬³ÌÐòͨ¹ýдÈ뿪»ú×ÔÆôÏÂÁîʵÏÖ³¤ÆÚ»¯¡£¡£¡£¡£¡£½©Ê¬³ÌÐòÔÚÆô¶¯ºó£¬£¬£¬£¬£¬£¬»áÊ×Ïȼì²éÆô¶¯µÄÏÂÁîÐвÎÊý, ÈôÊÇ·¢Ã÷ûÓвÎÊý£¬£¬£¬£¬£¬£¬ÄÇô¶ñÒâ³ÌÐò»áĬÈÏÊÇÔÚ¸Ã×°±¸µÄµÚÒ»´ÎÔËÐÐ,´Ëʱ»áŲÓá°autoboot¡±º¯Êý¡£¡£¡£¡£¡£Ôڸú¯ÊýÖУ¬£¬£¬£¬£¬£¬Å²Óá°system¡±º¯ÊýÖ´ÐÐϱíÖеÄÏÂÁ£¬£¬£¬£¬£¬ÒÔÈ·±£¶ñÒâ³ÌÐòÔÚ¸Ã×°±¸ÖØÆôºóÈÔÄܹ»Æô¶¯ÔËÐС£¡£¡£¡£¡£ÕâÒ²ÊÇDofloo¶ñÒâ³ÌÐòÔÚËÞÖ÷×°±¸ÊµÏÖ³¤ÆÚ»¯µÄΨһҪÁì¡£¡£¡£¡£¡£
sed -i -e '/^\r\n|\r|\n$/d' /etc/rc.local
sed -i -e '/%s/d' /etc/rc.local
sed -i -e '2 i%s/%s' /etc/rc.local
sed -i -e '2 i%s/%s start' /etc/rc.d/rc.local
sed -i -e '2 i%s/%s start' /etc/init.d/boot.local
4.2 ÉÏÏß»úÖÆ
4.3 ÐÄÌø»úÖÆ
½©Ê¬³ÌÐòÔÚSendInfoÏß³ÌʵÏÖÁË×ÔÉíµÄÐÄÌø»úÖÆ¡£¡£¡£¡£¡£Õâ¸öÏ̵߳ÄÖ÷Òª¹¦Ð§ÊÇÏòó«òë¿ØÖÆ¶ËºÍºÚȸ¿ØÖƶ˷¢ËÍÐÄÌø°ü£¬£¬£¬£¬£¬£¬ÐÄÌø°üÄÚÈݰüÀ¨Ä¿½ñCPUʹÓÃÂʺÍÍøÂçËÙÂÊÐÅÏ¢£¬£¬£¬£¬£¬£¬Í¨¹ýÒÔÏÂ2¸ö°ì·¨»ñÈ¡µ½ÕâЩÄÚÈÝ£º
£¨1£© ¼ì²é¡°eth0¡±µ½¡°eth9¡±¹æÄ£ÄÚÒÔÌ«Íø¿ÚµÄifconfigÐÅÏ¢¡£¡£¡£¡£¡£²¢Í¨¹ý¶ÁÈ¡/proc/net/dev Ŀ¼ÐÅÏ¢À´ÅÌËãÍøÂçËÙÂÊ¡£¡£¡£¡£¡£
£¨2£©Í¨¹ý¶ÁÈ¡/proc/statĿ¼ÏµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬»ñÈ¡cpuÊýÄ¿£¬£¬£¬£¬£¬£¬ÅÌËãÕ¼Óðٷֱȡ£¡£¡£¡£¡£
½ÏÁ¿ÓÐȤµÄÊÇ£¬£¬£¬£¬£¬£¬ÏÂÓεĺڿÍÔÚ·¢¶¯DDoS¹¥»÷µÄʱ¼ä£¬£¬£¬£¬£¬£¬¿ÉÄÜ»ù´¡²»»áÏëµ½£¬£¬£¬£¬£¬£¬Ö÷¿ØÖÐÏÔʾµÄ¶ñÒâ³ÌÐòµÄ¹¥»÷Á÷Á¿ËÙÂÊÏÕЩ¶¼ÊÇαÔìµÄ¡£¡£¡£¡£¡£ÎÒÃÇÔÚSendInfoÏß³ÌÖз¢Ã÷£¬£¬£¬£¬£¬£¬µ±¶ñÒâ³ÌÐòÖ´ÐÐDDoS¹¥»÷ʱ£¬£¬£¬£¬£¬£¬»áŲÓá°fake_net_speed¡±º¯Êý£¬£¬£¬£¬£¬£¬¸Ãº¯Êý»áƾ֤²î±ðµÄDDoS¹¥»÷µÄģʽ£¬£¬£¬£¬£¬£¬ÔÚÒ»¸öÀο¿µÄ¹æÄ£ÄÚαÔì¹¥»÷Á÷Á¿ËÙÂÊ¡£¡£¡£¡£¡£ÏÂͼΪ¶Ô²¿·ÖÅÌËãËæ»úÁ÷Á¿µÄ½ØÍ¼£º
½©Ê¬³ÌÐòαÔìµÄ¹¥»÷Á÷Á¿Êý¾Ý¹æÄ£ÈçϱíËùʾ£º
4.4 ¿ØÖÆÖ¸ÁîÆÊÎöÓëDDoS¹¥»÷
·¢ËÍÍêÉÏÏß°üÖ®ºó£¬£¬£¬£¬£¬£¬´Ëʱ½©Ê¬³ÌÐò»áÆÚ´ýÎüÊÕ¿ØÖƶ˵ĿØÖÆÖ¸Áî¡£¡£¡£¡£¡£Dofloo»áÊ×ÏȰѿØÖÆÖ¸Áî°üµÄǰËĸö×Ö½Ú×÷ΪģʽָÁîÂë¾ÙÐÐÆÊÎö£¬£¬£¬£¬£¬£¬ÓÉ´ËÀ´ÅжϽÓÏÂÀ´Òª¾ÙÐеIJÙ×÷£¬£¬£¬£¬£¬£¬Ö÷ÒªÖ§³ÖµÄ²Ù×÷ÓÐÈýÖÖ:
£¨2£©Ö¸ÁîÂëΪ0x6ʱ£¬£¬£¬£¬£¬£¬½øÈëDealwithDDoSº¯Êý£¬£¬£¬£¬£¬£¬´Ëº¯ÊýΪDDoS¹¥»÷º¯Êý£¬£¬£¬£¬£¬£¬ËùÓÐÖ´Ðй¥»÷µÄÅжϺÍÂß¼¶¼Ôڴ˺¯ÊýÖС£¡£¡£¡£¡£
£¨3£©Ö¸ÁîÂëΪ0x7ʱ¼ä£¬£¬£¬£¬£¬£¬Å²ÓÃkillº¯Êý£¬£¬£¬£¬£¬£¬ÖÕÖ¹Àú³Ì¡£¡£¡£¡£¡£
ͬʱDofloo¼Ò×å¶Ô¿ØÖÆÖ¸Áî¾ÙÐÐÁË128λµÄAES¼ÓÃÜ£¬£¬£¬£¬£¬£¬Õâ¸öÌØÕ÷´ó´óÔöÌíÁË¶ÔÆä¿ØÖÆÖ¸ÁîÁ÷Á¿¼à¿ØºÍʶ±ðµÄÄѶȡ£¡£¡£¡£¡£ÎÒÃǶÔÍøÂçµ½µÄÑù±¾¾ÙÐÐÆÊÎöºó·¢Ã÷£¬£¬£¬£¬£¬£¬ËùÓмܹ¹Ï½©Ê¬³ÌÐòÓÃÀ´½âÃܵÄKEY¶¼ÊÇÏàͬµÄ£¬£¬£¬£¬£¬£¬ÕâҲ˵Ã÷»¥ÁªÍøÖÐDofloo½©Ê¬¼Ò×åµÄÑù±¾¶¼À´×Ôͳһ¸öÄ£°æ¡£¡£¡£¡£¡£KEYÈçÏÂËùʾ£º
unsignedcharaes_key[] = { 0x2b, 0x7e, 0x15, 0x16, 0x28, 0xae, 0xd2, 0xa6, 0xab, 0xf7, 0x15, 0x88, 0x9, 0xcf, 0x4f, 0x3c };
ÎÒÃÇÄ£ÄâÁËδ¼ÓÃܵĿØÖÆÖ¸Á³ýȥǰ4¸ö×÷ΪģʽָÁîÂëµÄ×Ö½Ú£©ÔÚÄÚ´æÖеĽṹ,Æä¿ØÖÆÖ¸ÁîµÄ¸÷¸ö×ֶεļÄÒåÈçÏÂͼËùʾ£º
µ±½øÈëµ½DealwithDDoSº¯Êýʱ£¬£¬£¬£¬£¬£¬½©Ê¬³ÌÐòƾָ֤Á£¬£¬£¬£¬£¬Æô¶¯²î±ðµÄ¹¥»÷Ï̡߳£¡£¡£¡£¡£Dofloo¼Ò×å²»µ«¾ßÓÐSYN¡¢HTTPµÈ¹Å°åµÄ¹¥»÷ÒªÁ죬£¬£¬£¬£¬£¬»¹¾ßÓÐʹÓÃUDPÐÒéµÄ·´Éä·Å´óµÄ¹¥»÷·½·¨£¬£¬£¬£¬£¬£¬ºÃ±ÈDNS·Å´ó¹¥»÷¡£¡£¡£¡£¡£ÏÂͼΪDofloo¿ÉÌᳫµÄµä·¶µÄDDoS¹¥»÷µÄÒªÁ죺
²¢ÇÒÎÒÃǶÔDoflooµÄ¹¥»÷ÒªÁì¾ÙÐÐÁËÆÊÎö×ܽᣬ£¬£¬£¬£¬£¬²¢¶Ô²¿·Ö¹¥»÷ÒªÁìµÄÁ÷Á¿ÌØÕ÷¾ÙÐÐÁËÌáÈ¡£¬£¬£¬£¬£¬£¬ÖÆ×÷Á÷Á¿ÌØÕ÷±íÈçÏ£º
ÎÒÃÇÔÚÆÊÎö¹¥»÷Ï̵߳Äʱ¼ä£¬£¬£¬£¬£¬£¬·¢Ã÷ARM¼Ü¹¹µÄ¶ñÒâÑù±¾Ã¿´Î¹¥»÷½¨ÉèµÄ¹¥»÷Ï̺߳ÜÊǶ࣬£¬£¬£¬£¬£¬µ¥´Î¹¥»÷Ö¸Áî¿É½¨É輸ÖÖÉõÖÁÊ®¼¸ÖÖ²î±ðÀàÐ͵Ĺ¥»÷Ï̡߳£¡£¡£¡£¡£Á¬ÏµÑù±¾CPUµÄÂþÑÜ£¬£¬£¬£¬£¬£¬ÎÒÃÇ¿ÉÒÔµÃÖªARM×°±¸ÏµÄDofloo¶ñÒâ³ÌÐòÊǸý©Ê¬¼Ò×åµÄÖ÷Á¦£¬£¬£¬£¬£¬£¬ÔÚDDoS¹¥»÷ÖÐÌṩÁËÖ÷ÒªµÄÁ÷Á¿Ö§³Ö¡£¡£¡£¡£¡£
ͬʱƾ֤¼à¿Øµ½Dofloo¹¥»÷ÀúÊ·£¬£¬£¬£¬£¬£¬·¢Ã÷¸Ã¼Ò×åÖ÷ÒªµÄ¹¥»÷·½·¨ÒÔUDP Flood ΪÖ÷£¬£¬£¬£¬£¬£¬½üÄêÀ´ºÚ¿ÍÒ²Ô½À´Ô½Ï²»¶DNSºÍNTPµÈ·´Éä·Å´ó¹¥»÷ÊÖ¶ÎÀ´¶ÔЧÀÍÆ÷¾ÙÐй¥»÷ £¬£¬£¬£¬£¬£¬DoflooµÄ¹¥»÷·½·¨Õ¼±ÈÒ²Ó¡Ö¤ÁËÕâÒ»µã¡£¡£¡£¡£¡£Í¬Ê±ÎÒÃÇÒ²¿ÉÒÔ¿´µ½Layer7²ãµÄCC_FloodºÍLayer4²ãµÄTCP_Flood¡¢SYN Flood×÷Ϊ¹Å°åµÄDDoSµÄ¹¥»÷·½·¨£¬£¬£¬£¬£¬£¬ÆäÕ¼±ÈÒ²Ò»Ö±½ÏΪÎȹ̡£¡£¡£¡£¡£²¢ÇÒÎÒÃÇÆ¾Ö¤Ïà¹ØµÄÇ鱨Êý¾ÝµÃÖª£¬£¬£¬£¬£¬£¬DoflooµÄ¹¥»÷Á¿Ïà¹ØÓÚÆäËûµÄ¼Ò×å½ÏÉÙ£¬£¬£¬£¬£¬£¬ÎÒÃÇÆÊÎöÍÆ²âDoflooÿ´Î·¢¶¯¹¥»÷ʱ¿ªÆôÁË´ó×ڵĹ¥»÷Ị̈߳¬£¬£¬£¬£¬£¬ÕâÑùÄܼӴ󷢰üÁ¿£¬£¬£¬£¬£¬£¬¿ìËÙµ¼ÖÂÄ¿µÄЧÀÍÆ÷å´»ú¡£¡£¡£¡£¡£
4.5 ͬԴÐÔÆÊÎö
ÎÒÃÇÊӲ쵽Ðí¶àɱ¶¾Èí¼þ¶ÔDofloo¼Ò×å³ÌÐòÓвî±ðµÄÃüÃû·½·¨£¬£¬£¬£¬£¬£¬ÉõÖÁʶ±ðΪÆäËû¼Ò×åµÄ³ÌÐò£¬£¬£¬£¬£¬£¬Òò´ËΪÁËÈ·¶¨Dofloo¼Ò×åµÄÔ´Âë×é³É£¬£¬£¬£¬£¬£¬ÎÒÃÇ¶ÔÆä¾ÙÐÐÁËͬԴÐÔÆÊÎö¡£¡£¡£¡£¡£
²¢ÇÒ»¹¿ÉÒÔ¿´µ½Mr.BlackͬÑùÓÐͬÃûµÄ£¬£¬£¬£¬£¬£¬ÌᳫDDoS¹¥»÷µÄº¯ÊýDealWithDDoS£¬£¬£¬£¬£¬£¬ÆäÌᳫ¹¥»÷µÄ¿ØÖÆÖ¸Áî±àÂëÒ²Ïàͬ¡£¡£¡£¡£¡£
Ö»²»¹ýMr.BlackÖнöÓÐ5ÖÖDDoS¹¥»÷·½·¨¡£¡£¡£¡£¡£Í¨¹ý²éÔÄMr.BlackµÄÔ´Â룬£¬£¬£¬£¬£¬·¢Ã÷Mr.BlackÔ´ÂëÖв¢Ã»ÓкÚȸºóÃÅÏ̺߳ÍAES¼ÓÃÜ£¬£¬£¬£¬£¬£¬Ã»ÓÐÔ¶¿Ø²¿·Ö£¬£¬£¬£¬£¬£¬½öÄÜÌᳫDDoS¹¥»÷¡£¡£¡£¡£¡£Òò´ËÍÆ²âDoflooΪ²Î¿¼Mr.Black´úÂë¸ü¸ÄºóµÄ±äÖÖ¡£¡£¡£¡£¡£
ÔÚDnsAmpÓëDofloo¼Ò×åµÄ±ÈÕÕÖУ¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷Æä´úÂë²î±ð½Ï´ó£¬£¬£¬£¬£¬£¬¿ÉÊÇÖ÷Òª¹¥»÷´úÂëÒÔ¼°³ÌÐòÕûÌåÉè¼ÆË¼Ð÷½ÏÁ¿ÏàËÆ¡£¡£¡£¡£¡£ÔÚDnsAmp¼Ò×åÖУ¬£¬£¬£¬£¬£¬³¤ÆÚ»¯ÈÔÈ»ÊÇͨ¹ýÉèÖá°/etc/rc.d/rc.local¡±À´¼á³Ö¿ª»ú×ÔÆô£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚÆô¶¯ºóͬDoflooÒ»Ñù£¬£¬£¬£¬£¬£¬»áÊ×ÏÈÈ·¶¨Àú³ÌµÄΨһÐÔ¡£¡£¡£¡£¡£¶øËüµÄ¹¥»÷Ï̡߳°AttackWorker¡±ÖУ¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ͬDoflooÒ»Ñù¾ßÓÐͬÃûµÄ¹¥»÷º¯Êý¡°DealwithDDoS¡±£¬£¬£¬£¬£¬£¬Ö»²»¹ý½öÓÐ4ÖÖ¹¥»÷·½·¨£¬£¬£¬£¬£¬£¬»®·ÖΪudp£¬£¬£¬£¬£¬£¬icmp£¬£¬£¬£¬£¬£¬dnsAmp,syn¹¥»÷¡£¡£¡£¡£¡£ËäÈ»DnsAmpÓëDoflooÕûÌå´úÂëÏàËÆ¶È²»ÊÇÌ«¸ß£¬£¬£¬£¬£¬£¬¿ÉÊÇÆ¾Ö¤ÆäÖ÷Òª¹¥»÷´úÂëºÍ³ÌÐòÕûÌåµÄÉè¼ÆË¼Ð÷£¬£¬£¬£¬£¬£¬ÎÒÃÇÍÆ²â¶þÕß¾ßÓйØÁªÐÔ£¬£¬£¬£¬£¬£¬ÖÁÉÙDnsAmpΪ²Î¿¼Dofloo´úÂë¶ø±¬·¢µÄÏàËÆ±äÖÖ¡£¡£¡£¡£¡£²¿·Ö±ÈÕÕͼÈçÏ£º

5.×Ü ½á
±¾Æª±¨¸æÖصã¶ÔDofloo½©Ê¬ÍøÂç¼Ò×åÖб£´æµÄºÚȸÕ÷Ïó¾ÙÐÐÁËÆÊÎöÅû¶£¬£¬£¬£¬£¬£¬²¢ËÝÔ´×·×ÙºÚȸ£¬£¬£¬£¬£¬£¬²ú³öºÚȸ»Ïñ¡£¡£¡£¡£¡£Í¬Ê±¶Ôµä·¶µÄ½©Ê¬Ñù±¾¾ÙÐÐÁËÆÊÎö£¬£¬£¬£¬£¬£¬ÌáÈ¡¹éÄɳöÉÏÏß¡¢ÐÄÌø¡¢¿ØÖÆÖ¸ÁîºÍÌᳫ¹¥»÷µÄÁ÷Á¿ÃûÌᣡ£¡£¡£¡£
²Î¿¼ÎÄÏ×£º
1¡¢DDoS-Capable IoT Malwares: Comparative Analysis and Mirai Investigation
https://www.hindawi.com/journals/scn/2018/7178164/
http://www.antiy.net/p/2017-global-botnet-ddos-attack-threat-report
https://www.insight.com/content/dam/insight-web/en_US/article-images/whitepapers/partner-whitepapers/Internet%20Security%20Threat%20Report.pdf
http://blog.malwaremustdie.org/2014/09/tango-down-report-of-op-china-elf-ddoser.html