
CVE-2026-30784: RustDesk hbbs Traffic Amplification PoC & PCAP Analysis
CVE-2026-30784: RustDesk hbbs Traffic Amplification PoC & PCAP Analysis
Key Finding: Enforcing key-based authentication (
-k _) does not prevent this amplification attack, because the amplification response is triggered during the unauthenticated initial handshake/ping phase.
The packet capture is stored at:
data/attack_only.pcap.gz
⚠️ Important Note on the Packet Capture: > To prevent server from being further utilized as an active amplifier in a distributed botnet attack, the
rustdesk-server(hbbs)+(hbbr) service was completely stopped before/during the packet capture.
Because the service was disabled to mitigate ongoing outbound amplification, the provided PCAP file (data/attack_only.pcap.gz) contains incoming traffic only. Even without the server's responses, the incoming vectors clearly demonstrate the malicious intent and structural footprint of the attack:
hbbs was down, there is no corresponding outbound amplified response traffic in this specific trace. This was a deliberate action to protect third-party victims.szpontnet...).