[nsp-sec] 9001: New UDP amplification port?

Borja Marcos borjamar at sarenet.es
Thu Jul 15 02:19:03 EDT 2021



> On 14 Jul 2021, at 17:02, JASON CHAMBERS <jchambers at ucla.edu> wrote:
> 
> ----------- nsp-security Confidential --------
> 
> 
> We saw some activity from 80.82.76.6 in June 2021, a 45 minute scan of 253k
> IPs.
> 
> July 2021 shows a flurry of activity, presumed to be community research.

Ruckus have confirmed that it is a flaw in their SmartZone controller, exploitable when it is
not behind a firewall.

They are testing the fixes and they will release them soon.

That would explain the limited number of ASs involved and I guess we will see very few of these,
if any. As far as I know they contacted the ISPs.


Thank you!




Borja.



More information about the nsp-security mailing list