Showing posts with label DDoS/DoS Attacks. Show all posts
Showing posts with label DDoS/DoS Attacks. Show all posts

Friday, May 5, 2017

Cisco Patches Critical Flaw in Small Business Router

From SecurityWeek:

Cisco Patches Critical Flaw in Small Business Router

"Cisco has released a firmware update for one of its small business routers to address a critical vulnerability that can be exploited for denial-of-service (DoS) attacks and arbitrary code execution.

The vulnerability, discovered by researchers from GeekPwn, a China-based IoT-focused hacking competition, affects CVR100W Wireless-N VPN routers. The company said there was no evidence of malicious exploitation."

Europe Pumps Out 50% More Cybercrime Attacks Than US

From Dark Reading:

Europe Pumps Out 50% More Cybercrime Attacks Than US

"Cyberattacks originating from Europe were substantially higher than nefarious activity launched from the US during the first quarter.

Cybercrime attacks launched from Europe reached more than 50 million in the first quarter, double the volume coming out of the US, according to the ThreatMetrix Q1 Cybercrime Report released today."

The Bondnet Army

A technical overview of the Bondnet Army botnet from GuardiCore:

The Bondnet Army

"GuardiCore Labs has recently picked up Bondnet, a botnet of thousands of compromised servers of varying power. Managed and controlled remotely, the Bondnet is currently used to mine different cryptocurrencies and is ready to be weaponized immediately for other purposes such as mounting DDoS attacks as shown by the Mirai Botnet. Among the botnet’s victims are high profile global companies, universities, city councils and other public institutions."

Wednesday, May 3, 2017

WordPress Attacks Powered by Router Botnet Drop Rapidly

From SecurityWeek:

WordPress Attacks Powered by Router Botnet Drop Rapidly

"A botnet powered by compromised home routers has been apparently shut down. It is unclear if the botnet operators decided to pull the plug on their operation or if the disruption was caused by law enforcement.

Security firm Wordfence warned last month that tens of thousands of vulnerable routers from dozens of ISPs worldwide had been abused for brute-force and other types of attacks aimed at WordPress websites."

Monday, May 1, 2017

10 Cybercrime Myths that Could Cost You Millions

From Dark Reading:

10 Cybercrime Myths that Could Cost You Millions

"Don't let a cybersecurity fantasy stop you from building the effective countermeasures you need to protect your organization from attack.

Cybercrime is all over the place, with damages, according to one estimate by Cybersecurity Ventures, expected to double from $3 trillion in 2015 to $6 trillion by 2021. In a prominent 2016 ransom attack, according to the 2016 McAfee Threat Report, a criminal was supposedly able to pocket $121 million within just six months, netting $94 million after expenses. Still, too often people believe in myths that prevent them from building effective countermeasures. Here are some examples:"

Discovery of 8,800 servers sends warning to Asian cybercriminals

From Sophos Naked Security:

Discovery of 8,800 servers sends warning to Asian cybercriminals

"In one of the more curious cybercrime announcements of recent times, Interpol’s Asian centre says it has “identified” 8,800 servers used as command & control (C2) for all sorts of bad things including DDoS attacks and distributing ransomware and spam.

You read that correctly. Interpol hasn’t disrupted these servers, merely passed information on their whereabouts and malevolent purpose to police forces in eight countries, including Malaysia, Myanmar, Philippines, Singapore, Thailand and Vietnam."

Tuesday, April 25, 2017

UK Man Jailed for Running Global Cyberattack Business

From NewsMax:

UK Man Jailed for Running Global Cyberattack Business

"LONDON (AP) — A British man has been sentenced to two years in prison for creating and selling a program used in online attacks around the world.

Adam Mudd was 16 when he created Titanium Stresser, a program that carried out more than 1.7 million "denial of service" attacks on websites including gaming platforms Minecraft and Xbox Live."

Wednesday, July 22, 2015

It's official: The average DDoS attack size is increasing

From Help Net Security:

It's official: The average DDoS attack size is increasing

New global DDoS attack data from Arbor Networks shows strong growth in the average size of DDoS attacks, from both a bits-per-second and packets-per-second perspective.

Friday, July 17, 2015

A comparative view of cloud-based DDoS protection services

From Help Net Security:

A comparative view of cloud-based DDoS protection services

Six months ago we experienced a 30Gb/sec and 60M PPS attack that was targeting over 1000 IPs on our network. Although we eventually stopped the attack with the aid of our upstream providers, a number of our customers asked us why we didn't have a DDoS protection service in place. We decided on NTT's service due to their scale and network capacity. However, this solution was meant only to protect our network in times of need, and not to protect individual customers on a 24/7 basis. One customer revealed that above all else, DDoS attacks are what keep him up at night.

Thursday, July 16, 2015

Inside A Vicious DDoS Attack

From Dark Reading:

Inside A Vicious DDoS Attack

On Sunday, May 17, cybercriminals launched a vicious distributed denial of service (DDoS) attack against my company, HotSchedules, a cloud-based service supporting more than 2 million workers in restaurants, hospitality, and retail industries.  For 45 hours, from Sunday night to Tuesday afternoon, the assailants prevented employees from checking and managing their schedules  -- and never stated a motive.
 
However, what began as every CEO’s nightmare ultimately became a source of pride and valuable lessons for me. HotSchedules had fended off many such attacks over the past 16 years without any interruption to service. This one was exceptionally ferocious, and I believe that other companies can benefit from what we learned.

Tuesday, July 14, 2015

The most damaging ramifications of DDoS attacks

From Help Net Security:

The most damaging ramifications of DDoS attacks

More than half of IT security professionals (52 percent) said loss of customer trust and confidence were the most damaging consequences of DDoS attacks for their businesses, according to a survey conducted at RSA Conference 2015 and Infosecurity Europe 2015 by Corero Network Security.

In addition, 22 percent of respondents indicated that DDoS attacks have directly impacted their bottom line – disrupting service availability and impeding revenue-generating activity.

Lad who attacked Spamhaus in DDoS attack avoids prison, given a second chance

From Sophos Naked Security:

Lad who attacked Spamhaus in DDoS attack avoids prison, given a second chance

Just over two years ago, we wrote about a massive DDoS attack against Spamhaus.

To explain, Spamhaus is a project that "tracks the internet's spam senders" for the purpose of publishing blocklists of known spammers, and assisting law enforcement "to identify and pursue spammers worldwide."

Thursday, July 2, 2015

Rise in DDoS reflection attacks using abandoned routing protocol

From Help Net Security:

Rise in DDoS reflection attacks using abandoned routing protocol

There's been an increase in the use of outdated Routing Information Protocol version one (RIPv1) for reflection and amplification attacks, according to Akamai.

RIPv1 is a fast, easy way to dynamically share route information using a small, multi-router network. A typical request is sent by a router running RIP when it is first configured or powered on. From there, any device listening for the requests will respond with a list of routes and updates that are sent as broadcasts.

Thursday, May 28, 2015

High schooler allegedly hired third party to DDoS his school district

Not cool dude!


From Sophos Naked Security:


High schooler allegedly hired third party to DDoS his school district


A 17-year-old high school boy may face state and federal charges for allegedly having paid a third party to launch a distributed denial of service (DDoS) attack that crippled the West Ada school district in Idaho, US, for a week and a half earlier this month.


Because he's a minor, he can't be named.

Wednesday, May 13, 2015

Default Credentials Lead to Massive DDoS-For-Hire Botnet

From ThreatPost:


Default Credentials Lead to Massive DDoS-For-Hire Botnet


Tens of thousands of home and office-based routers have been hijacked over the last several months to form a botnet used to stage a DDoS campaign.

Active DoS Exploits for MS15-034 Under Way

From ThreatPost:


Active DoS Exploits for MS15-034 Under Way


UPDATE – Microsoft’s characterization of MS15-034 as a remote code execution vulnerability certainly has a lot of Windows server admins on edge waiting for the other shoe to drop.

Thursday, March 12, 2015

New DDoS attack and tools use Google Maps plugin as proxy

From Help Net Security:

New DDoS attack and tools use Google Maps plugin as proxy

Attackers are using Joomla servers with a vulnerable Google Maps plugin installed as a platform for launching DDoS attacks.

A known vulnerability in a Google Maps plugin for Joomla allows the plugin to act as a proxy. Attackers spoof (fake) the source of the requests, causing the results to be sent from the proxy to someone else – their denial of service target. The true source of the attack remains unknown, because the attack traffic appears to come from the Joomla servers.

Thursday, February 19, 2015

Don’t dig a well when your house is on fire

Whether your SMB/SOHO relies on a hosting provider or is looking to use the services of one inquire as to whether or not they use DDoS protection.  If they do, ask them about it.  If they don't, keep looking.

From SecurityBistro:

Don’t dig a well when your house is on fire

Relying on human intervention to mitigate DDoS attacks is like digging a well when your house is on fire.  When it comes to ensuring service availability and maintaining uptime and SLAs, hosting providers should use minimal (if any) manual intervention when defending against a DDoS attack.  Instead, real-time DDoS mitigation will allow providers to eliminate data center outages and collateral damage within the hosted environment.  The following is a real-world example of real-time DDoS protection, utilizing purpose built DDoS protection technology, coupled with sophisticated visibility, reporting and analytics capabilities.

Tuesday, February 17, 2015

Lizard Squad is back: group 'attacks Xbox Live and Daybreak Games'

From The Guardian:

Lizard Squad is back: group 'attacks Xbox Live and Daybreak Games'

Notorious hacking group Lizard Squad has reportedly launched a fresh series of attacks against games and game services this weekend, including Xbox Live.

Anarchist hackers start cyber war with ISIS

From The Hill:

Anarchist hackers start cyber war with ISIS

The global hacker collective known as Anonymous is storming the international political scene with a brash hacking campaign against the Islamic State in Iraq and Syria (ISIS).