Light

Episode #836 Quiz

The Meris Botnet
Date: 2021-09-14 | Length: 2 hrs | Episode page at twit.tv

About this episode

Meris is a large botnet of compromised MikroTik routers, likely exploiting an unknown vulnerability or brute force, and using HTTP/1.1 pipelining, HTTPS, and open ports 2000 and 5678 to generate record 21.8 million requests-per-second Layer 7 DDoS attacks. Because requests are valid, blocking is difficult, requiring per-IP rate tracking.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific browser and domain-scoping limitation allowed Spook.js to bypass Chrome's Site Isolation protections?
Question 2: What change did Google make in response to the Spectre-based Spook.js research, and what was the immediate effect of that change?
Question 3: Which combination of characteristics did Qrator Labs identify as particularly significant in the Meris botnet's attack traffic?
Question 4: What did the episode say was the most likely device family underlying the Meris botnet, and what evidence supported that conclusion?
Question 5: What did the episode say was the scale and triggering method of the largest attack seen from the Meris botnet?
Cancel