logo

Akamai Identifies Old Protocol in New DrDoS Attacks

ID: db892a47-1b9c-5ecf-9815-62fbcdc51f27

STIX ID: report--db892a47-1b9c-5ecf-9815-62fbcdc51f27

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2015-07-03

Date Updated: 2026-05-06

Author: Robert Vamosi

...
...

Akamai's PLXsert warned that legacy RIPv1 implementations on many SOHO routers are being abused for DrDoS amplification attacks: RIPv1 requests (UDP/520) can elicit large multi-packet responses, yielding an estimated amplification factor of ~131x and producing observed peaks of 12.8 GB/s. Akamai found ~53,693 RIPv1-responsive routers (not all suitable for amplification) and identified common affected models; mitigations include blocking UDP/520 at the edge, migrating to RIPv2, or replacing outdated routers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.