⚠️CVE-2024-45163: Remote DoS in Mirai Botnet (The Mirai Botnet Kill Switch)
I discovered a vulnerability in Mirai (and several variants) that makes it easy to take down the botnet’s command and control server. When the CNC receives any incoming TCP data, even random bytes or a known username like “root,” it keeps the session open while waiting for a password that never arrives.
If someone opens many of these connections at once, the server slowly burns through its resources and stops responding.
There’s no authentication required and it can be done remotely, which makes it a simple but effective way to disrupt the botnet’s operations.