Call of Duty botnet launches 10Gbps DDoS

By
Follow google news

Unpatched servers used in attack.

A botnet of servers used for the popular gaming title Call of Duty have been hijacked and used in a 10 gigabit distributed denial of service (DDoS) attack.

Call of Duty botnet launches 10Gbps DDoS

The attack bombarded a small unnamed business with a UDP flood by exploiting a flaw that is still present in thousands of game servers.

The flaw meant that servers did not require a valid player session in order to process replies.

This allowed attackers to write code to send UDP packets to the victim by spoofing the IP address.

European anti-DDoS vendor VistNet, which moved to block the attack, said thousands of vulnerable sites could be found with a “quick Google search”.

Administrators could apply a patch to fix the flaw, which rate limited reply packets to a given IP address.

The fix logged an attackers’ IP address when query packets were sent, and ignored further queries for a set time. 

Administrators of hacked Call of Duty 4: Modern Warfare servers had initially thought VistNet was behind the attacks. Few understood how their servers were compromised, the company said.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Komatsu Australia to move 4000 users to zero trust cloud security

Komatsu Australia to move 4000 users to zero trust cloud security

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Foreign control of AI vendors a board-level risk, ASD says

Foreign control of AI vendors a board-level risk, ASD says

Hackers targeted US private equity, other firms including Blackstone, CME

Hackers targeted US private equity, other firms including Blackstone, CME

Log In

  |  Forgot your password?