Category Archives: DDoS Criminals

Westboro, Northboro Verizon service hit by DDoS attack

Since March 3 — and perhaps as far back as Feb. 26 — Verizon customers in Westboro and Northboro had been experiencing regular and constant interruptions to their Internet and phone service. Dozens of Westboro residents have discussed the service outages on Facebook (and offer sharp-tongued critiques of Verizon’s response), and six have filed complaints with the state Office of Consumer Affairs and Business Regulation. The disruptions, according to Verizon spokesman Philip G. Santoro, were caused by repeated cyberattacks on one residential customer in Westboro. The cyberattack is called a dynamic denial of service, a DDOS or DOS. In an email, Mr. Santoro described the attack thusly: “Someone deliberately flooded that customer with an overwhelming amount of traffic that rendered their Internet service inoperable.” “When that happened, it caused Internet service to periodically slow down for other customers in Westborough,” he wrote. “We are working to restore service to normal as soon as possible. DOS attacks are all too common today among customers of all Internet providers. It’s important to remind Internet users to keep their firewalls operating and to keep their security software current.” Interestingly, though, when I first asked Mr. Santoro about this, he said there were no widespread outages reported. I think that is because there was nothing physically wrong with the FiOS lines — no technical problems, no trees on the line, etc. At Verizon, the lines were all reported to be working as normal. But customers were calling in complaints and opening repair tickets left and right. The state logs the complaints and passes them on to the service provider, in this case Verizon, said Jayda Leder-Luis, communications coordinator for the Office of Consumer Affairs and Business Regulation. “DOS is a cybersecurity issue, one that can affect voice services that rely on access to the Internet (like VOIP),” she wrote in an email, referring to Voice Over Internet Protocol, in which phone service is provided through an Internet connection. “Those were the kinds of complaints we were receiving.” For dozens of residential and business customers in Westboro and Northboro, the interruptions were frustrating. “It happened around 3 o’clock, every day,” said Allen Falcon, chief executive officer for Cumulus Global, a cloud computing company in Westboro. “Sometimes it was a few minutes, sometimes 45 minutes to an hour.” A few times, the interruptions occurred in the morning, just after 9 a.m., he said. Since the company’s phone service and Internet connection runs through a FiOS line provided by Verizon, when the FiOS line goes out, customers lose both phone and Internet. “For us, it’s incredibly embarrassing as a technology company, to lose our service like this,” he said. “We’re talking to someone and the phone lines goes down, the Internet goes down.” The company has workarounds, in which the office can switch its Internet and phone service to a 4G service provided by their cellphones. “But it’s slower performing and more expensive,” he said. “Some days, around 3 p.m., we have to consider, ‘Should we switch, just in case?’ “ Several customers reported that Verizon had a lot of trouble pinpointing the cause of the interruptions, and several of them had Verizon technicians visit their homes and replace their routers. Since the cause was later determined to be this DOS cyberattack, replacing their routers looks like, in hindsight, a waste of time and money. Steve Winer, a Westboro resident, said Verizon installed a new router at his home, but it made no difference. The outages continued. “I am just wondering how much time and money was wasted on this,” he wrote in an email. “I know I spent at least a couple of hours on the phone, and others shared similar stories. But, if you add up all the shipped routers and unnecessary service calls, along with the time both of us customers and (Verizon) personnel, I am sure it really adds up, and could have been avoided if someone had simply put two and two together and posted a chronic outage which began in February.” On Tuesday, Verizon apparently pinpointed the exact Internet Protocol address of the Verizon customer being attacked, and shut down the customer’s FiOS service. The slowdowns and service interruptions have stopped. Let’s hope they never return. Source: http://www.telegram.com/article/20140323/COLUMN73/303239976/1002/business

View the original here:
Westboro, Northboro Verizon service hit by DDoS attack

Gang wielding ColdFusion exploits expands botnet of hacked e-commerce sites

A German website of French automaker Citroën is the latest of the wide array of higher-profile webshop sites that have been compromised by a hacker gang leveraging Adobe ColdFusion vulnerabilities. …

Continued here:
Gang wielding ColdFusion exploits expands botnet of hacked e-commerce sites

NATO websites hit by cyber attacks

A number of NATO websites have been hit by cyber attacks, but they have had no impact on the military alliance’s operations, a NATO spokeswoman said. The attacks, which affected NATO’s main website, came amid rising tensions over Russian forces’ occupation of Ukraine’s Crimea region where a referendum is to be held on Sunday. NATO spokeswoman Oana Lungescu said on Twitter that several NATO websites have been the target of a “significant DDoS (denial of service) attack.” She said there had been no operational impact and NATO experts were working to restore normal function. Source: http://www.itv.com/news/update/2014-03-16/several-nato-websites-hit-by-ddoscyber-attacks/

View original post here:
NATO websites hit by cyber attacks

162,000 reasons to tighten up WordPress security

“Cyber-criminals continue to innovate and find vulnerabilities to exploit for their criminal activity” says Lancope CTO Tim Keanini. 162,000 reasons to tighten up WordPress security WordPress may be one of the most popular website systems used to publish on the Internet, but its open source nature – and consequent security challenges – have been highlighted this week after around 160,000 WordPress sites have apparently been used as DDoS zombies. Security research firm Securi reports that the WordPress pingback option – which allows WordPress sites to cross-reference blog posts – has been misused in recent times by unknown hackers to launch large-scale, distributed denial-of-service (DDoS) attacks. The attack vector used is not unknown as, back in the summer of last year, Incapsula reported that one of its clients was targeted in a pingback DDoS attack involving 1,000 page hits a second. Securi says it has been monitoring a swarm attack involving more than 162,000 WordPress sites and collectively generating many hundreds of IP requests to a single WordPress site. Whilst Daniel Cid, Securi’s CTO, has declined to identify the site, this suggests the attack may have been a proof-of-concept trial. On a technical level, the attack vector exploits an issue with the XML-RPC (XML Remote Procedure Call) code within WordPress and which is used for pingbacks, trackbacks and remote access from mobile Web browsers. SCMagazineUK.com notes that WordPress has known about the issue for several years, but the problem is that it a key structural issue with WordPress’s kernel architecture. Despite this, WordPress development teams have changed the default setting of sites to operate with a Web cache, meaning there is less load placed on the hosting server concerned. The hackers, however, have generated fake website addresses within their IP calls, so bypassing the web cache. Securi’s CTO says he been talking to WordPress developer teams about the issue, who are reportedly investigating a workaround. Tim Keanini, CTO of Lancope, said that the structural natures of the issue mean that it is not something that will ever go away. “Think of it as a supply chain and these criminals need compromised connected computers for their botnets – if you are connected for whatever reason to the Internet, you are a part of this supply chain,” he said, adding that cyber-criminals continue to innovate and find vulnerabilities to exploit for their criminal activity. To add to this, he explained, we – as Internet users – continue to put insecure devices on the Internet and with the Internet of Things ramping up, he warns there is just no end to the supply of targets. “What we need to do is to focus on the precision, timeliness, and leadership through these crisis – not the fact that they will just go away. They are here to stay and a part of doing business in the Internet age. When these events happen, what does leadership look like that provides business continuity and restores customer confidence? That is the question we need to be asking because hanging your head in shame does no one any good,” he said. Sean Power, security operations manager with DDoS security vendor DOSarrest, said that the vulnerabilities in old versions of WordPress mean that hackers can exploit them to be used for DDoS attacks. “This is nothing new – in fact, it was first recognised back in 2007. Attackers exploited a vulnerability in the core WordPress application and therefore it could be used for malicious purposes in DDoS attacks,” he said. “The fix for this feature was actually released in the 3.5.1 version of WordPress in January 2013 and would be picked up by most good vulnerability scanners,” he added. Power went on to say that this a prime example of how users aren’t regularly performing updates to their websites – “because if they were, we wouldn’t still be seeing DDoS attacks being carried out by websites taking advantage of this old flaw.” Source: http://www.scmagazineuk.com/162000-reasons-to-tighten-up-wordpress-security/article/337956/

See original article:
162,000 reasons to tighten up WordPress security

Over 162,000 WordPress sites exploited in DDoS attack

DNS and NTP servers are not the only publicly accessible resources that can be misused to amplify DDoS attacks. Sucuri CTO Daniel Cid revealed details of a recent incident in which they received a …

Original post:
Over 162,000 WordPress sites exploited in DDoS attack

Over 160,000 legitimate WordPress sites used for DDoS attack

Distributed Denial of Service (DDoS) attacks aren’t new and 2013 was one of the worst years when it comes to such attacks that too through the use of large botnets and / or specialised DDoS tools; however, use of legitimate WordPress blogs and sites to carry out such attacks is something that isn’t widespread, but is becoming a trend lately. According to Sucuri Research over 162,000 legitimate WordPress blogs and sites were a part of huge DDoS attacks on one of its client’s website. The attacker(s) used WordPress websites as indirect amplification vectors through a simple one line command. “Any WordPress site with XML-RPC enabled (which is on by default) can be used in DDOS attacks against other sites”, notes Sucuri CTO and OSSEC Founder Daniel Cid in a blog post. Cid explained that the DDoS attack was a large layer 7 HTTP-based distributed flood attack through which the perpetrators forced legit WordPress sites to send out thousands of requests per second to the victim’s servers. All the GET requests being sent to victim’s servers had a random value that bypassed their caching mechanism thereby forcing to load the whole page on every request, which killed the server quickly. “One attacker can use thousands of popular and clean WordPress sites to perform their DDOS attack, while being hidden in the shadows, and that all happens with a simple ping back request to the XML-RPC file” revealed Cid. Cid provides a couple of workarounds to ensure that your WordPress site isn’t DDoSing someone else’s site. First is to disable the XML-RPC (pingback) functionality from your site. This can be done by removing the xmlrpc.php or disabling the notifications in your blog’s settings. However, the thing is as soon as you upgrade your WordPress, the file come right back. Another solution is that users use some cloud based security solution or proxy site that will ensure that such misuse is prohibited. “This is a well known issue within WordPress and the core team is aware of it, it’s not something that will be patched though. In many cases this same issue is categorized as a feature, one that many plugins use, so in there lies the dilemma”, concludes Cid. Source: http://www.techienews.co.uk/977737/160000-legitimate-wordpress-sites-used-ddos/

Read this article:
Over 160,000 legitimate WordPress sites used for DDoS attack

DDoS Attacks May Be Entering a New Era

It seems cybercriminals are no longer content just to bring down Web sites with their distributed denial-of-service (DDoS) attacks. Now, these cybercrooks are demanding ransom from Web site owners to call off their DDoS assaults, leaving victims between a rock and a hard place — either pay up or watch their sites go dark. Distributed denial-of-service (DDoS) attacks are booming, and may be reaching new levels that include more blackmail. According to recent reports, we could be entering a new phase of site attacks. Prolexic, a security firm, issued a report this month that said attacks in general, in particular DDoS, were up 32 percent in the last year over 2012. DDoS attacks generally utilize networks of hijacked computers, which then bombard targeted Web sites with requests that overwhelm them, causing the sites to crash. While such attacks have been common for years, new benchmarks are appearing. In February, security firm Cloudfare reported that it recently helped protect one of its clients against the largest DDoS attack on record. The unnamed Web site, according to Cloudfare, was subjected to 400 gigabytes per second, nearly a third larger than the 2013 attack on antispam Web site Spamhaus. The Spamhaus attack, also fended off by Cloudfare, had been the largest on record to that point. $300 Ransom Last month, domain registration company Namecheap reported it had been assaulted by a coordinated attack on 300 of its registered sites. This week, social networker Meetup.com said attackers demanded a $300 ransom in exchange for calling off a DDoS attack. The site refused, and was brought down for several days, including over the Oscars weekend when many Meetup users scheduled get-togethers. In a blog post, CEO Scott Heiferman said that his company did not want to negotiate with criminals, especially since the low ransom demand apparently meant the attackers were amateurs who might be encouraged to engage in more such efforts. Reportedly, such ransom demands, especially when no user confidential data is involved, are not uncommon but are not frequently made public. A New Era Has Dawned Lawrence Orans, research vice president at industry research firm Gartner, told us that we may indeed be in a new era. He said, “[The] DDoS attack landscape changed in September, 2012, when attackers began to launch attacks using botnets of compromised servers, instead of botnets of compromised PCs.” He added that these server botnets enabled attackers to launch more powerful attacks, and the key event in that month occurred when cyberattacker group Izz Ad-Din Al Qassam “started to launch attacks, using botnets of servers, against major North American banks.” A report late last year from the Ponemon Institute said that nearly 20 percent of U.S. data center outages resulted from organized attacks on Web sites. Orans noted that DDoS attacks can span from several hours to several days, and ISPs are currently charging “a 15 percent premium over bandwidth costs to offer a ‘clean pipe’ service to monitor and mitigate against DDoS attacks.” Some estimates peg the average cost of a DDoS outage at about $630,000. To counter this, Orans said that enterprises in verticals commonly targeted for DDoS attacks “should consider specialty DDoS mitigation providers,” or DDoS mitigation services provided by ISPs. Source: http://www.toptechnews.com/news/DDoS-Attacks-Entering-a-New-Era/story.xhtml?story_id=0120013PJXVC

Original post:
DDoS Attacks May Be Entering a New Era

Why is Meetup Site Down? Hacker Attempts to Extort $300 From CEO Scott Heiferman

The Meetup site is down after a hacker attempted to extort $300 from the site’s CEO Scott Heiferman. The social networking site was the victim of a DDoS attack that was allegedly paid for by one of Meetup’s competitors. The attack began on Thursday when CEO Scott Heiferman received an email that reads: Date: Thu, Feb 27, 2014 at 10:26 AM Subject: DDoS attack, warning A competitor asked me to perform a DDoS attack on your website. I can stop the attack for $300 USD. Let me know if you are interested in my offer. As soon as Heiferman received the email, the attack began and overwhelmed Meetup’s servers. The site went down and stayed that way for nearly 24 hours. The success of the site being back up was short-lived as Meetup was hit again and again with numerous DDoS attacks over the course of the weekend. Why is Meetup Site Down? Hacker Attempts to Extort $300 From CEO Scott Heiferman – photo from Twitter Stating his reasons for not paying the hacker behind the attack, Heiferman wrote on Meetup’s blog: We chose not to pay because: 1. We made a decision not to negotiate with criminals. 2. The extortion dollar amount suggests this to be the work of amateurs, but the attack is sophisticated. We believe this lowball amount is a trick to see if we are the kind of target who would pay.  We believe if we pay, the criminals would simply demand much more. 3. Payment could make us (and all well-meaning organizations like us) a target for further extortion demands as word spreads in the criminal world. 4. We are confident we can protect Meetup from this aggressive attack, even if it will take time. As of right now, the site is still down as the Meetup team continues to secure its servers. When users attempt to log onto the site, they are met with the following error message: Over the past several days, Meetup has suffered a prolonged denial of service (DDoS) attack, resulting in intermittent service outages for our website and apps. We’re working urgently to bring Meetup back and restore full functionality. We appreciate your patience. Heiferman encourages all Meetup users to stay informed by receiving updates via Twitter, Facebook or the company’s blog. Why is Meetup Site Down? Hacker Attempts to Extort $300 From CEO Scott Heiferman. Source: http://americanlivewire.com/2014-03-03-meetup-site-down/

Taken from:
Why is Meetup Site Down? Hacker Attempts to Extort $300 From CEO Scott Heiferman

Miscreant menaces Meetup, minuscule money mania mashed

$300 or the trendy website gets it … and the website got it Meetup.com has gone public with one of the most paltry ransom demands The Register has seen – but rather than pay up to end a distributed denial-of-service (DDoS) attack, the klatch organizer instead put up with its site being repeatedly hosed offline, we’re told.…

Read the original:
Miscreant menaces Meetup, minuscule money mania mashed

The rise of UDP-based DDoS attacks

The DDoS war is ramping up with the use of network time protocol (NTP) amplification to paralyse, not just individual organisation’s networks, but potentially large proportions of general internet traffic. The largest ever DDoS attack to date with a DNS amplification hit the anti-spam company, Spamhaus last year. This attack reached 300 Gbps, taking Spamhaus offline and also affecting the DDoS mitigation firm, CloudFare. With the volume of traffic that was going through peering exchanges and transit providers, the attack also slowed down internet traffic for everyone else. However, in the last couple of months these UDP amplification attacks seem to have moved on to NTP, taking advantage of an exploit available in older, unpatched NTP systems. These servers are usually used for time synchronisation and utilise the UDP protocol on port 123. Like DNS, they will respond to commands issued by any client to query certain information, unless they are properly secured. These attack styles are not new, but their historically infrequent usage and the potential for mass disruption means they warrant more attention. Coverage of these attack styles in both industry and mainstream press is to be welcomed in my opinion, because these attacks are relatively defensible and coverage will hopefully get more administrators to secure or patch their NTP servers. What is all the fuss about? DNS amplification attacks ramp up the power of a botnet when targeting a victim. The basic technique of a DNS amplification attack is to spoof the IP address of the intended target and send a request for large DNS zone files to any number of open recursive DNS servers. The DNS server then responds to the request, sending the large DNS zone answer to the attack target rather than the attacker, because the source IP was spoofed. The DNS amplification attack on Spamhaus saw request data (the data the attacker sent to the DNS servers) of roughly 36 bytes in length, while the response data (the data from the DNS server to the attack target) was around 3000 bytes, meaning the attackers increased the bandwidth used by 100x. Not only is that a large increase in attack bandwidth, but these packets from the DNS servers arrive at the target in a fragmented state due to their large size and have to be reassembled, which ties up the routing resources as well. NTP amplification attacks work by spoofing the IP of the attack target and sending a ’monlist’ command request to the NTP servers. This command will return the IP addresses of the last 600 clients that have used the NTP server to synchronise time. By issuing this command a small request packet can trigger much larger UDP response packets containing active IP addresses and other data. The volume of the response data is related to the number of clients that communicate with any particular NTP server. This means that a single request which consists of a single 64-byte UDP packet can be increased to 100 responses each, which contain the last 600 client IP addresses that have synchronised with the server. Each of those 100 responses will be a UDP packet of around 482 bytes which gives the attacker a bandwidth amplification of around 700x [482 bytes x 100 responses = 48200 bytes / 64 bytes = 753.125]. With this level of amplification available and several popular DDoS attack tools already including a module for abusing ’monlist’ we could be on for a new record in DDoS attack size this year unless the vulnerabilities are patched soon. For example, if DNS amplification created a 300 Gbps, then NTP amplification means we could potentially see a 2.1 Tbps (21,000 Gbps) attack. There is no network that could absorb an attack of that size; it would have an enormous knock-on effect on general Internet traffic as the Spamhaus attack did with peering points, transit providers and content delivery networks being overloaded. This isn’t to say that DNS and NTP are the only amplification attack methods. There are other amplification and reflection-style tactics as well and, while not as popular as more tried-and-true DDoS methods, they represent a real threat if you are not prepared for them. Fixing the problem The easiest way to fix this and remove your NTP servers from being an attack vector for a DDoS is to update your NTP servers to version 4.2.7 which removes the ‘monlist’ command. Otherwise you can disable query within your NTP server via a configuration change: nano /etc/ntp.conf [Your configuration file might be located elsewhere] #Restrict general access to this device Restrict default ignore Restrict xxx.xxx.xxx.xxx mask 255.255.255.255 nomodify notrap Noquery This change will prevent your NTP server from being used to launch DDoS attacks against other networks, but an update to the latest version is still recommended. Conclusion DDoS attacks have been around in one form or another since the very beginnings of the internet, but the motivations, as well as the scale of these attacks seem to have grown significantly. In the early days it was just extortion; a hacker would ask for payment to stop the attacks. Nowadays, some businesses may pay for competitors to be attacked, as a few hours offline could be worth millions. You also have DDoS being used as a method of political activism by groups such as Anonymous, as well as the potential for a government to use DDoS to disrupt another country’s infrastructure. Systems administrators need to ensure their systems are reviewed regularly for patches and known vulnerabilities. If systems are left unpatched then at best you can be used as a vector to attack another network or organisation, but at worst those vulnerabilities could be exploited to take your systems offline or steal your data. Source: http://blogs.techworld.com/industry-insight/2014/02/the-rise-of-udp-based-ddos-attacks/index.htm

Read more here:
The rise of UDP-based DDoS attacks