Security News > 2024 > March > New ‘Loop DoS’ attack may impact up to 300,000 online systems

New ‘Loop DoS’ attack may impact up to 300,000 online systems
2024-03-20 19:40

A new denial-of-service attack dubbed 'Loop DoS' targeting application layer protocols can pair network services into an indefinite communication loop that creates large volumes of traffic.

The attack is possible due to a vulnerability, currently tracked as CVE-2024-2169, in the implementation of the UDP protocol, which is susceptible to IP spoofing and does not provide sufficient packet verification.

In total, it is estimated that 300,000 internet hosts are vulnerable to Loop DoS attacks.

Using firewall rules and access-control lists for UDP applications, turning off unnecessary UDP services, and implementing TCP or request validation are also measures that can mitigate the risk of an attack.

New acoustic attack determines keystrokes from typing patterns.

New acoustic attack steals data from keystrokes with 95% accuracy.


News URL

https://www.bleepingcomputer.com/news/security/new-loop-dos-attack-may-impact-up-to-300-000-online-systems/

Related Vulnerability