Category Archives: DDoS Criminals

The Evolution of Web Application Firewalls

Technological advances related to computing and the Internet have affected every one of us. The Information Revolution that the Internet has made possible is affecting society just as dramatically as the Industrial and Agricultural Revolutions of the past, but there is an unpleasant side to progress. Criminal use of the Internet, or hacking, is an unavoidable part of information technology development. Hackers have gained unauthorized and undesirable access to information, sometimes with far-reaching consequences. Innovations in hacking have in turn led to the development of protection methods and devices commonly known as web application firewalls (WAF) . An application firewall is a form of firewall which controls input, output, and/or access from, to, or by an application or service. It operates by monitoring and potentially blocking the input, output, or system service calls which do not meet the configured policy of the firewall. A Web Application Firewall does much more than a consumer’s computer firewall. Consumer-level applications work by blocking software access to certain ports. Web applications such as Apache, WordPress and Microsoft’s Office all require an extra level of protection against malicious users. WAFs offer this extra protection and work by analyzing all data passing through them and checking its conformity to pre-set rules. A WAF fulfills a web-user’s need to protect both internal and public web applications, whether locally (on-premises) or remotely (cloud-hosted), against unauthorized access attempts. These attacks revolve around hacking and illegal access to web applications. According to statistics, every year, cyber attacks are increasing by 30%, while successful breaches are increasing at twice that rate, 60% a year: In plain English, more attacks are getting through. Basic consumer-level cyber security measures are essential and are an urgent call on companies’ financial resources, but these are not enough. If a company has a website then that website must be protected using a WAF against unauthorized intrusion by hackers. The need to protect customers’ data is even more important than the need to keep the website live. If there is a security breach the negative effects of the attendant publicity and loss of trust are immeasurable. So how have application firewalls been evolving? Web application firewalls have been evolving rapidly and becoming more sophisticated with the objective of protecting websites and customer data from increasingly sophisticated attacks and unauthorized access. Hackers’ methods have become more devious and WAF sophistication has increased correspondingly as part of the information security industry’s fight back against criminals stealing data and malicious hacking. The more evolved and developed WAF solutions are capable of preventing attacks and unwanted intrusion on any website. Modern web application firewalls generally have default settings that give no false negatives and errors and all modern WAFs are designed to work perfectly without the need for any user knowledge of source code. A WAF has become crucial in detecting and preventing any attack that that is masquerading as network access by a legitimate user. Understanding interactions Web Application Firewalls need to do much more than just see the code: They need to be able understand every line of code passing through them and to evaluate any risk that it represents. This risk evaluation ability enables a WAF to analyze visitors based on reputation behaviors. The old adage of prevention being the best cure still holds true and is very relevant here. Instead of blocking an attack as and when it occurs, a WAF should see it coming by understanding and tracking visitor behavior. It should be proactive. More than In-Depth Inspection From the historical perspective of web application firewalls, they have always performed an in-depth inspection of any access routes to the protected sites. However, the modern evolution of web application firewalls comes with more than in-depth inspection of access routes in the sense that modern WAFs are deployed in-line in the form of reverse proxies. These are crucial in preventing any form of access log collection that may be used later to audit the protected site or perform any form of analysis on the protected web applications. Simplicity of use is vital, so the modern web application firewall has evolved to the extent that it can be deployed out of the box with no user setting changes necessary. New-age WAFs such as those from the aforementioned Incapsula are constantly learning and are able to stop threats that have never been seen before by analysis of their code and finding similarities to previous threats. They are updated frequently and monitoring is available on some plans to ensure maximum protection for your site and your customers. Modern firewalls have enabled an increase in firewall features that revolve around transparent proxy and bright modes, which can enable WAFs to easily integrate with other network security technologies such as vulnerability scanners, protection applications, distributed denial of service prevention, database security solutions, and web fraud detection. Another major noticeable evolution has to do with the fact that modern WAFs are perfectly packaged to include content caching, as well as web access management modules, which are specially designed to provide simple sign-in features, especially for distributed web applications. Concluding thoughts There are massive advances going on in the field of web application firewalls. Modern firewalls are perfectly devised to provide maximum protection against hacking, easy detection and filtering of both known and unknown threats, while at the same time, minimizing false alerts. Are you aware of the level of protection that your web application firewall offers? Does it protect you against a DDOS attack? Does it protect your customers’ login and credit card details adequately? Source: http://tech.co/evolution-web-application-firewalls-2015-01

Visit site:
The Evolution of Web Application Firewalls

Anonymous vows to take down jihadist websites to avenge ‘Charlie Hebdo’ victims #OpCharlieHebdo

Hacker group Anonymous has vowed to avenge those killed in the deadly attack on the offices of French satirical magazine Charlie Hebdo by taking down jihadist internet sites and social media accounts. In a video uploaded to the Anonymous Belgique YouTube channel, a figure wearing the group’s signature Guy Fawkes mask condemned the attack that killed 12 individuals, which includes eight journalists. The video description addresses the message to “al-Qaeda, the Islamic State and other terrorists.” “We are fighting in memory of these innocent people today who fought for freedom of expression,” stated the disguised person in the video. The group integrated a link to anonymous data sharing internet site Pastebin with a list of Twitter accounts it claims are linked to jihadists. The group is using the hashtag #OpCharlieHebdo to urge other customers to assistance them take down the accounts by reporting them to Twitter, or participating in a Distributed Denial of Service (DDoS) attack – a practice normally used by the hacker group. “Anonymous should remind each citizens (sic) that the press’s freedom is a fundement of the democracy. Opinions, speech, newspaper articles with no threats nor pressure, all these issues are rights you can’t modify,” read a statement posted to Pastebin by the group Thursday. “Expect a massive reaction from us, simply because this freedom is what we’ve been often fighting for.” Read A lot more: Each ‘Charlie Hebdo’ suspects killed as police storm constructing Wednesday’s attack in Paris has not been linked to ISIS – numerous reports have suggested it is much more most likely to be connected to the Yemen-based al-Qaeda in the Arabian Peninsula. On Friday, Charlie Hebdo suspects Cherif Kouachi, 32, and Stated Kouachi, 34, had been killed just after police stormed the constructing exactly where they were holed up for extra than five hours. The third suspect Hamyd Mourad, 18, surrendered to police early Thursday. Source: http://www.finditwestvalley.com/world/anonymous-vows-to-take-down-jihadist-websites-to-avenge-8216charlie-hebdo8217-victims-h46362.html

Read More:
Anonymous vows to take down jihadist websites to avenge ‘Charlie Hebdo’ victims #OpCharlieHebdo

State of the Internet: Attack traffic, DDoS, IPv4 and IPv6

Akamai today released its latest State of the Internet report, which provides insight into key global statistics such as connection speeds and broadband adoption across fixed and mobile networks, over…

Read More:
State of the Internet: Attack traffic, DDoS, IPv4 and IPv6

German government sites faced DDoS attacks

A German official says Chancellor Angela Merkel’s website and several other German government sites have been blocked, and a pro-Russian organization has claimed responsibility. A pro-Russian organization calling itself CyberBerkut claimed on its website Wednesday to have blocked the official sites of Merkel and the German Parliament ahead of a visit to Berlin by Ukrainian Prime Minister Arseniy Yatsenyuk. Merkel has been a leading figure in attempts to calm the Ukraine crisis. Merkel spokesman Steffen Seibert said several government websites were unreachable Wednesday morning because of a “serious attack clearly caused by a multitude of external systems” — what is known as a distributed denial of service, or DDoS, attack. Seibert says the attack is still being analyzed, and he did not say who was believed to be responsible. Source: http://www.nytimes.com/aponline/2015/01/07/world/europe/ap-eu-germany-merkel-cyberattack.html?_r=0

Read More:
German government sites faced DDoS attacks

DDoS attack on Swedish Parliament’s website

The official website of the Swedish Parliament was taken down on Tuesday, in what officials labelled “an outside attack”. The website, riksdagen.se, was taken down at 11am on Tuesday, with visitors met by a blank screen. By 2pm, the website was up and running again, but officials confirmed that the problem had not been caused by any internal IT troubles. “It went down because of an attack from the outside,” Riksdag spokesperson Anna Olderius told the TT news agency. “But we refuse to comment on security issues in any more detail than that.” The cyber attack marks the second against the website in the past two years. In October 2012, the website went down together with that of the country’s central bank other government websites, news networks, and university home pages. Hacktivist network Anonymous claimed responsibility for the October attacks. “You don’t fuck with the internet,” the group wrote online, in what was apparently a response to police raids on the previous hosts to The Pirate Bay and WikiLeaks. The attacks were carried out via a Distributed Denial of Service (DDoS), where a website is bombarded with communication requests so that the servers become overloaded and the site crashes. As yet, no one has claimed responsibility for Tuesday’s attack. Source: http://www.thelocal.se/20141230/cyber-attack-hits-government-website

See more here:
DDoS attack on Swedish Parliament’s website

‘Bitcoin Baron’ claims credit for City of Columbia, KOMU DDoS attacks

He cited a 2010 SWAT raid in Columbia as his motivation behind the DDoS attacks. An individual is taking credit for the distributed denial of service attacks on the websites of the City of Columbia and KOMU-8 on Friday. KOMU posted about the attack on its Facebook page at 3:48 p.m. Friday, about three hours after the station had reported on a similar attack on the City of Columbia’s website earlier Friday. KOMU’s article included a statement from Assistant City Manager Tony St. Romaine indicating the activist group Anonymous was behind the attacks. Shortly after their site was attacked, KOMU received an email from a third party who indicated that he, not Anonymous, was behind both attacks. KOMU General Manager Marty Siddall said the individual referred to himself as “Bitcoin Baron.” Through his Twitter, Bitcoin Baron has connected himself to multiple other DDoS attacks. Bitcoin Baron said in a video that his motivation behind the attacks was a 2010 Columbia SWAT raid on the house of Jonathan Whitworth, who was presumed to be a marijuana dealer. During the raid, one of Whitworth’s dogs was fatally shot in front of his wife and child. “I decided that this should go viral once more to show everyone the true nature of how you and every police department does things,” Bitcoin Baron said in his video. Bitcoin Baron said in a tweet that no data was affected by any of the DDoS attacks. Prasad Calyam, assistant professor of computer science with a technical focus in cyber security, said DDoS attacks occur when a user creates a large amount of fake traffic that accesses a site’s servers all at once to crash the site. “(A DDoS attack) is a sort of brute force attack, where many machines are compromised to act like regular users in order to block real users from reaching the site,” he said. Calyam said DDoS attacks cannot be stopped as they occur, and he advised that locally blocking a website is the best way to deal with an attack. “(That is) because it’s hard for an Internet provider to block people from accessing your site,” he said. “The only way to prevent attacks is through an intrusion detection system, which can be really expensive … There are open source intrusion detection systems available, but they must be maintained and managed by experts.” Siddall said KOMU is working with their third-party Internet provider to prevent future attacks. Source: http://www.themaneater.com/stories/2014/12/29/bitcoin-baron-claims-credit-city-columbia-komu-ddo/

More here:
‘Bitcoin Baron’ claims credit for City of Columbia, KOMU DDoS attacks

Sony FINGERS DDoS attackers for ruining PlayStation’s Xmas

Malefactors turned festivities into a turkey for online gamers Sony has blamed distributed-denial-of-service (DDoS) attackers for causing PlayStation’s network to go titsup on Christmas Day.…

Originally posted here:
Sony FINGERS DDoS attackers for ruining PlayStation’s Xmas

Update: Columbia’s website back online after cyber attack; KOMU down from DDoS attack

UPDATE: This story has been updated to include details of another denial of service attack on KOMU and additional comments on FBI involvement in investigating the attack on Columbia’s website. COLUMBIA — The city’s official website is back online after being down since Wednesday night, when a cyber attack flooded the server with information requests. But the hacker responsible might have found a new target in KOMU. The city’s site, gocolumbiamo.com, was back up as of 12:35 p.m. The site provides information and updates to the public about city services and events. Deputy city manager Tony St. Romaine said city officials have been in touch with the FBI about the incident. Joel Sealer, a spokesman for the FBI in Kansas City, said only that city officials had been in contact with the agency, but he would not comment on or confirm the existence of an investigation. St. Romaine said the activist hacker group Anonymous was the source of the attack on the city’s site, but a YouTube video posted by Bitcoin Baron denies that affiliation and claims sole responsibility for the attack. In the video’s introduction, Bitcoin Baron states that the attack is in retaliation for a February 2010 incident where Columbia police killed one dog and wounded another during a drug raid. The YouTube video then shows footage from the raid. The city’s website was hit by a distributed denial of services attack, which sent requests from multiple sources to the site’s server to overload its bandwidth capacity. City staff became aware of the problem at around 11 p.m. Wednesday and shut down access to the site to sort out the problem. KOMU.com’s outage began around 3 p.m. Friday, and KOMU posted on its Facebook page at 4 p.m. Saturday to address the distributed denial of service attack. In the post, KOMU calls the attack a “direct result” of its reporting on the city’s website being taken down. Its story noted that city officials believed Anonymous was responsible, but a third party contacted the news station to claim responsibility and threaten to take down KOMU.com as well. Attacks of this nature generally don’t result in the theft of information or other security loss, St. Romaine said. “Your system is not getting hacked into, and data is not getting compromised,” he said. Source: http://www.columbiamissourian.com/a/183192/update-columbias-website-back-online-after-cyber-attack-komu-down/

Continue Reading:
Update: Columbia’s website back online after cyber attack; KOMU down from DDoS attack

PlayStation clambers back online 48 hours after DDoS attack CRIPPLED network

Titsup gaming service struggling to return to life Sony’s PlayStation network is slowly returning to normal service roughly 48 hours after it was hit by another major denial-of-service attack on Christmas Day.…

See the article here:
PlayStation clambers back online 48 hours after DDoS attack CRIPPLED network

PlayStation clambers back online 48 hours after DDoS attack PARALYSED network

Titsup gaming service struggling to return to life Sony’s PlayStation network is slowly returning to normal service roughly 48 hours after it was hit by another major distributed denial-of-service (DDoS) attack on Christmas Day.…

View article:
PlayStation clambers back online 48 hours after DDoS attack PARALYSED network