Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: New Mirai Botnet Flaw That Could Cripple Cyber Attacks
Newsletter
Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: New Mirai Botnet Flaw That Could Cripple Cyber Attacks
Newsletter
Search
  • Latest Stories
  • Security & Tech
    • Security
    • Vulnerabilities
    • Dark Web
    • Technology
    • Privacy
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
© MRS Media Company. Hackerdose LLC. All Rights Reserved.

Vulnerabilities » New Mirai Botnet Flaw That Could Cripple Cyber Attacks

Vulnerabilities

New Mirai Botnet Flaw That Could Cripple Cyber Attacks

A new flaw in the infamous Mirai botnet could allow security researchers to disable these networks remotely, cutting off their ability to launch attacks.

Marco Rizal
Last updated: August 26, 2024 11:57 am
By Marco Rizal - Editor, Journalist 3 Min Read
Share
New Mirai Botnet Flaw That Could Cripple Cyber Attacks
SHARE

Cybersecurity researcher Jacob Masse has discovered a noteworthy vulnerability in the Mirai botnet, potentially giving law enforcement and security teams a new weapon in the fight against cybercrime.

The flaw discovered in Mirai's Command and Control (CNC) servers has the potential to cause a remote Denial of Service (DoS) attack on the botnet.

This attack would effectively disable the botnet, preventing it from executing any further operations.

Jacob Masse's investigation centered on the CNC server, which lies at the core of any botnet. This is the place where attackers have control over the zombies computers that have been infected and can be commanded to carry out attacks.

Masse discovered a flaw in the way Mirai's CNC servers handle incoming connections by analyzing the source code, reverse engineering, and conducting experiments.

This flaw occurs during the pre-authentication phase, which happens before the user completes the login process.

Basically, an attacker can crash the server by overloading its resources with multiple connection attempts after submitting a username.

The vulnerability in Mirai CNC’s architecture stems from poor management of multiple connection requests. In simple terms, the server struggles to handle multiple connections at the same time.

It is possible for a remote attacker to flood the server with authentication requests, such as repeatedly sending a username like “root”, without requiring any special access or authentication.

This tactic leads to the exhaustion of the server’s resources, eventually causing it to crash and go offline. This effectively disconnects the botnet from its command center, disrupting its operations and neutralizing its threat.

Masse successfully demonstrated this vulnerability using a small server with minimal resources, a 1-core CPU and 1GB of RAM.

image 19
Video demonstration by Masse. (Full video link)

He showed that his proof-of-concept (PoC) script could take a Mirai CNC server offline, proving that even a small-scale attacker could cripple a botnet using this flaw.

Masse successfully ran the script, resulting in the botnet CNC crashing. Once the exploit was no longer in use, the CNC server went offline, and his system returned to its usual performance levels.

This flaw has the potential to seriously affect botnet operations and cybersecurity defense. If this vulnerability is exploited, it has the potential to disable the command and control functions of Mirai botnets.

This would effectively halt their ability to launch attacks, thereby safeguarding numerous systems from Distributed Denial of Service (DDoS) attacks.

It also has the potential to greatly assist law enforcement agencies in their mission to dismantle botnets.

More Stories

BitcoinIRA Security Flaw Allows Hacker to Take Over User Accounts

40 Critical Vulnerabilities Found In Toshiba Printers

Hugging Face Chat Platform Vulnerabilities Exposed in New Security Research

Critical Docker Vulnerability Could Grant Hackers Full Access

Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newsletter

Receive the latest news and stories straight to your inbox.

Latest stories

Bitcoin Holds at $85K as Global Trade Tensions and Fed Speculation Unfold

April 15, 2025

Michael Saylor Doubles Down on Bitcoin (BTC) with $285M Investment Amid Global Uncertainty

April 14, 2025

Mantra Faces Crisis After OM Token Crashes 90% in a Day

April 14, 2025

Solana (SOL) on the Verge of a Breakout: Could $300 Be the Next Target?

April 14, 2025

You might also like

How a YouTube vulnerability can be used to steal files

How a YouTube Vulnerability Can Be Used to Steal Files

Backdoor in AI Models Waiting to Strike

Sleeping Backdoor in AI Models Waiting to Strike

Threat Actor Exposes Multiple Vulnerabilities in FBI Online Portal

Threat Actor Exposes Multiple Vulnerabilities in FBI Online Portal

Chrome Exploited by Hackers Using a Fake Crypto Game

Chrome Exploited by Hackers Using a Fake Crypto Game

Newsletter

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site

Quick Links

  • Contact Us
  • Search
  • Malware
  • Downloads

Company

  • About Us
  • Terms and Conditions
  • Cookies Policy
  • Privacy Policy
Advertise with us

Socials

Follow Us

© 2025 | HackerDose Media Company – All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?