Category Archives: DDoS Criminals

NSA.gov goes down after ‘error during scheduled update’

Spook agency denies DDOS, blames sysadmins The USA’s National Security Agency (NSA), lately the source of near-endless controversy for spying on just about the entire internet, has itself hit trouble online after its website went down.…

More:
NSA.gov goes down after ‘error during scheduled update’

12 year old Quebec boy Anonymous Hacker Pleads Guilty to DDOS Attack on Government Websites

A 12-year-old Quebec boy is responsible for hacking several government and police websites during the student uprising in spring 2012, creating computer havoc and causing $60,000 damage, court heard Thursday. Some sites were out of service for up to two days and the boy did it in the name of the activist/hacktivist group Anonymous. The Grade 5 student from the Montreal suburb of Notre-Dame- de-Grâce, whose actions were not politically motivated, traded pirated information to Anonymous for video games, court was told. The boy appeared in youth court Thursday dressed in his school uniform and accompanied by his father. He pleaded guilty to three charges related to the hacking of the websites, including those of Montreal police, the Quebec Institute of Public Health, Chilean government and some non-public sites. Police estimate damage to the sites at $60,000 but a more detailed report will be produced in court when the boy is sentenced next month. The little hacker, whose name can’t be published and is said to have been involved with computers since the age of nine, contributed to the crash of some sites and accessed information belonging to users and administrators. He had even issued a warning to others: “It’s easy to hack but do not go there too much, they will track you down.” Court heard the boy used three different computer attacks, one which resulted in a denial of service to those trying to access the websites and flooded servers, making them ineffective. In another method he would alter information and make it appear as the homepage. His third tactic involved exploiting security holes in order to access database servers. “And he told others how to do it,” a police expert testified in Montreal on Thursday. While others were arrested in the scheme, it was the boy who opened the door to the website attacks, court heard. “He saw it as a challenge, he was only 12 years old,” his lawyer said. “There was no political purpose.” In 2000, a 15-year-old Montreal boy, know as Mafiaboy, did an estimated $1.7 billion in damage through hacking. He was sentenced to eight months in youth detention and subsequently received several job offers in cybersecurity. Source: http://www.torontosun.com/2013/10/25/que-boy-12-pleads-guilty-to-hacking-government-websites

Read More:
12 year old Quebec boy Anonymous Hacker Pleads Guilty to DDOS Attack on Government Websites

NSA site down due to alleged DDoS attack

The website for the United States National Security Agency suddenly went offline Friday. NSA.gov has been unavailable globally as of late Friday afternoon, and Twitter accounts belonging to people loosely affiliated with the Anonymous hacktivism movement have suggested they are responsible. Twitter users @AnonymousOwn3r and @TruthIzSexy both were quick to comment on the matter, and implied that a distributed denial-of-service attack, or DDoS, may have been waged as an act of protest against the NSA   Allegations that those users participated in the DDoS — a method of over-loading a website with too much traffic — are currently unverified, and @AnonymousOwn3r has previously taken credit for downing websites in a similar fashion, although those claims have been largely contested. The crippling of NSA.gov comes amid a series of damning national security documents that have been disclosed without authorization by former intelligence contractor Edward Snowden. The revelations in the leaked documents have impassioned people around the globe outraged by evidence of widespread surveillance operated by the NSA, and a massive “Stop Watching Us” rally is scheduled for Saturday in Washington, DC. DDoS attacks are illegal in the United States under the Computer Fraud and Abuse Act, or CFAA, and two cases are currently underway in California and Virginia in which federal judges are weighing in on instances in which members of Anonymous allegedly used the technique to take down an array of sites during anti-copyright campaigns waged by the group in 2010 and 2011. In those cases, so-called hacktivsits are reported to have conspired together to send immense loads of traffic to targeted websites, rendering them inaccessible due to the overload.

More:
NSA site down due to alleged DDoS attack

Norks seed online games with malware in fiendish DDoS plot

Seoul police believe country’s love of gaming will be turned upon itself South Korea’s National Police Agency (NPA) is warning users not to download unofficial online games as they may contain malware designed by the North to compromise machines which can then be used to launch DDoS attacks on the country.…

View article:
Norks seed online games with malware in fiendish DDoS plot

IBM unveils new cloud solution

IBM announced a new cloud solution that combines software analytics and cloud security services to fend off web-based DDoS attacks for organizations doing business on the web and in the cloud. The new…

View the original here:
IBM unveils new cloud solution

If there’s somethin’ strange in your network ‘hood. Who y’gonna call? Google’s DDoS-busters

Project Shield guards activists, charities from web storms Google will shelter charities and activists from distributed denial-of-service attacks by wrapping their websites in its protection technologies.…

More:
If there’s somethin’ strange in your network ‘hood. Who y’gonna call? Google’s DDoS-busters

DDoS Attacks Grow Shorter But Pack More Punch

If there was ever a riddle asking the listener to name something that has become bigger and shorter at the same time, distributed denial-of-service attacks (DDoS) would be an acceptable answer. According to a new report from Arbor Networks about the third quarter of 2013, the average attack size now stands at 2.64 Gbps for the year, an increase of 78 percent from 2012. The number of attacks monitored by the firm that are more than 20 Gbps experienced massive growth, to the tune of a 350 percent increase so far this year. Meanwhile, the length of the vast majority of attacks (87 percent) has gone down to less than an hour. “Shorter duration attacks are not inherently harder to detect, but they can be harder to mitigate,” says Gary Sockrider, solutions architect for the Americas, Arbor Networks. “Many organizations today rely on network- or cloud-based mitigation of DDoS attacks. Because they rely on rerouting attack traffic to scrubbing centers, there is a small delay in mitigation while routing or domain name changes propagate. “Ideally you want to have mitigation capabilities on your own network that can react immediately without the need for redirection. I think it’s safe to say that if you have absolutely no mitigation capabilities, then shorter attacks are better. However, if your only protection has inherent delays, then shorter attacks potentially cannot be stopped.” Barrett Lyon, founder of DDoS mitigation firm Prolexic Technologies and now CTO of Defense.net, says that shorter DDoS attacks also have the added benefit of minimizing an attacker’s exposure. “The longer it runs, the more things are obviously clogged up and the more reactive network engineers become,” he observes. “When network engineers start researching a problem like that — congestion in their network or why is this computer slow — it exposes the botnet and makes it much vulnerable than it would be otherwise. So if it’s a short attack but big, [attackers] can kind of quickly see and size up their target. They can quickly determine … what’s the best bang for the buck when it comes to attacking.” A clear trend of increasing attack sizes has emerged during the past several years, Sockrider says. “I believe there [is] a combination of factors enabling this trend,” he says. “First, there is increased availability of simple-to-use tools for carrying out attacks with little skill or knowledge. Second, there is a growing proliferation of DDoS-for-hire services that are quite inexpensive. Third, increasingly powerful workstations and servers that get compromised also have significantly faster connections to the Internet from which to generate attacks.” The largest monitored and verified attack size during the quarter was 191 Gbps, according to the firm. Fifty-four percent of attacks this year are more than 1 Gbps, up from 33 percent in 2012. Some 37 percent so far this year are between 2 Gbps and 10 Gbps. Another general trend is of attacks moving to the application layer. In fact, while volumetric attacks are still common, they are now frequently combined with application-layer and state exhaustion attacks, Sockrider says. In some cases, DDoS attacks have served as diversions meant to draw attention from other activities, such as bank fraud. For example, a report published in April by Dell SecureWorks noted how DDoS attacks were launched after fraudulent wire and automatic clearing house (ACH) transfers. “Most people that follow DDoS trends are aware of the really high-profile attacks against government and financial institutions, but in reality the most common targets are actually business and e-commerce sites,” Sockrider says. “We’re also seeing increased attacks in the online gaming industry, where attacks are waged for competitive advantage. Additionally, some organizations are taking collateral damage because they reside in a data center, and they happen to share infrastructure with a high-profile target. The bottom line is that in the current environment, every organization is a potential target.” Source: http://www.darkreading.com/attacks-breaches/ddos-attacks-grow-shorter-but-pack-more/240162741

See more here:
DDoS Attacks Grow Shorter But Pack More Punch

The Internet of Things: Vulns, botnets and detection

Does the Internet of Things scare you? It probably should. This DerbyCon video discusses why embedded device security is laughably bad, handling vendor notification, and setting up a dev environment t…

See the original post:
The Internet of Things: Vulns, botnets and detection

What Is a DDoS Attack?

What Is a DDoS Attack? Before we can understand just how groundbreaking this recent attack was, let’s first go over exactly what a denial of service attack is. It is one of the least complicated attacks that a hacker can pull off. Basically the goal is to shut down a webserver or connection to the internet. Hackers accomplish this by flooding the server with an extremely large amount of traffic. It would be like taking a wide open freeway and packing it full of the worst rush hour traffic you could imagine. Every connection to and from the freeway would grind to a halt. This would make visiting the website (or the road) next to impossible, or at the least extremely slow! In some cases, the server might overload and shut down completely. When this happens, it doesn’t mean that the website was necessarily hacked. It just means that the website was kicked off the internet for a period of time. This may not sound like that big of a deal, but if your company relies heavily on its online presence, this interruption of service could take a huge cut out of profits. DoS v. DDoS The next item to be clarified is the difference between a DoS (Denial of Service) attack and a DDoS or (Distributed Denial of Service) attack. This distinction is pretty simple: a DoS attack comes from one network or computer whereas a DDoS comes from multiple computers or networks. DDoS attacks are most always bigger than a DoS attack because the strength of the attack can be multiplied by a huge amount of computers. Source: http://www.scientificamerican.com/article.cfm?id=what-is-ddos-attack

Read More:
What Is a DDoS Attack?