MH

M. Hájek

info

Please Note

1 records found

Observing scan and test, but not execute, on a public Memcached honeypot

Bachelor thesis (2026) - M. Hájek, Harm Griffioen, Mitchell Olsthoorn
The 2018 Memcached amplification attacks set the public DDoSrecord, after which UDP wasdisabled by default and port 11211 widely firewalled. Yet tens of thousands of misconfigured servers remain reachable, leaving open the question of whether, and how, attackers still exploit this residual surface. We address it with a custom, safety-bounded Memcached honeypot deployed on 16 public IPv4 addresses for 22 days. Over the window it recorded 4,261 packets from 465 sources. Traffic is dominated by stats reconnaissance bearing recognisable tooling fingerprints, and 23 sources swept the full address block: the scan and test phases of the established workflow are clearly present. The execute phase, however, never materialised: no source populated the cache, empirical amplification capped at ≈13×, and the only abuse-related traffic was neutralised. The honeypot egressed just 277 KiB in total. Memcached today behaves as a catalogued but dormant amplifier: continuously enumerated and re-measured, but rarely weaponised. ...