Category Archives: DDoS Vendors

Massive DDoS attack targets Spamhaus

The DDoS attacks mounted against Spamhaus over a week ago have escalated in the last few days, reaching a never previously experienced level of some 300 gigabits per second at peak hours, says Akamai.

Read More:
Massive DDoS attack targets Spamhaus

Wells Fargo warns of ongoing DDoS attacks

Wells Fargo warned on Tuesday that its website is being targeted again by a distributed denial-of-service (DDOS) attack. The bank said most of its customers were not affected. “For customers who are having difficulty accessing the site and mobile banking, we encourage them to try logging on again as the disruption is usually intermittent,” Wells Fargo said in a statement. Wells Fargo is one of several large U.S. banks that have been targeted by cyberattacks in the past six months. A group claiming responsibility for the attacks, the Izz ad-Din al-Qassam Cyber Fighters, said Wells Fargo is being targeted due to the continued availability online of a video clip that denigrates Islam. The 14-minute trailer, available on YouTube, caused widespread protests last September in predominantly Muslim countries. Google restricted viewing in countries including India, Libya and Egypt but kept it available in most countries because it didn’t violate the company’s guidelines. The Izz ad-Din al-Qassam Cyber Fighters wrote on Pastebin on Tuesday that it was also targeting Citibank, Chase Bank, SunTrust and others. The group drew up a mock invoice, calculating the cost to a bank of a DDOS attack at about US$30,000 per minute. It contained a formula for how much the banks should lose based on the number of times the offensive video has been watched. The group did not spell out how the attacks would cost the banks money or why it was attacking those banks. For DDoS protection click here . Source: http://www.itworld.com/security/349835/wells-fargo-warns-ongoing-ddos-attacks

Continued here:
Wells Fargo warns of ongoing DDoS attacks

Anti-spam Spamhaus up again after 75Gbps Distributed Denial of Service (DDoS) Attacks

The website of non-profit spam fighter Spamhaus is online again after a huge DDoS attack knocked it offline on Sunday, but attackers are continue to target another anti-spam sites that help ISPs combat spam from infected IP addresses. Spamhaus, which provides several anti-spam DNS-based blocklists and maintains the “register of known spam operations”, came under a huge DDoS attack on Sunday, which knocked its web server and mail server offline until Wednesday. Spamhaus spokesperson Luc Rossini on Monday denied a report that Anonymous was behind the attack and pointed to a “Russian criminal malware gang” as the source. On Tuesday Spamhaus sought cover from the attack with DDoS protection provider CloudFlare, which today reported the attack on Spamhaus reached a peak of about 75 gigabits per second. The attackers used a cocktail of DDoS attack methods, but the primary one that helped generate that volume of traffic was a “reflection attack”, according to Matthew Prince, CloudFlare’s CEO. “The basic technique of a DNS reflection attack is to send a request for a large DNS zone file with the source IP address spoofed to be the intended victim to a large number of open DNS resolvers,” Prince explained, noting that 30,000 open DNS resolvers were recorded in the attack, which used spoofed IP addresses CloudFlare had issued to Spamhaus. “The resolvers then respond to the request, sending the large DNS zone answer to the intended victim. The attackers’ requests themselves are only a fraction of the size of the responses, meaning the attacker can effectively amplify their attack to many times the size of the bandwidth resources they themselves control.” Source: http://www.cso.com.au/article/456917/anti-spam_spamhaus_up_again_after_75gbps_ddos_attack/

Read the original:
Anti-spam Spamhaus up again after 75Gbps Distributed Denial of Service (DDoS) Attacks

Researcher ropes poorly protected devices into botnet to map the Internet

A fascinating but technically illegal experiment conducted by an anonymous researcher has witnessed over 420,000 Internet-connected devices being roped into a botnet that functioned as a distributed p…

Read More:
Researcher ropes poorly protected devices into botnet to map the Internet

Researcher sets up illegal 420,000 node botnet for IPv4 internet map

Potentially risks thousands of years in jail An anonymous researcher has taken an unorthodox approach to achieve the dream of mapping out the entire remaining IPv4 internet – and in doing so broken enough laws around the world to potentially put him or her behind bars for thousands of years.…

Originally posted here:
Researcher sets up illegal 420,000 node botnet for IPv4 internet map

Chameleon botnet grabbed $6m A MONTH from online ad-slingers

Click fraudster bot fingered after analysts crack its signature A web analytics firm has sniffed out a botnet that was raking in $6m a month from online advertisers.…

See more here:
Chameleon botnet grabbed $6m A MONTH from online ad-slingers

Distributed Denial of Service-DDoS: 6 Banks Hit on Same Day

Six leading U.S. banking institutions were hit by distributed-denial-of-service attacks on March 12, the largest number of institutions to be targeted in a single day, says security expert Carl Herberger of Radware. The attacks are evolving, and the bot behind them, known as Brobot, is growing, he adds. This recent wave of DDoS attacks has proven to be the most disruptive among the campaigns that date back to September, says Herberger, vice president of security for the anti-DDoS solutions provider. “The Brobot has grown, the infection rate has increased, and the encrypted attacks have become more refined,” Herberger says. “As a result, it all is more effective. They’ve clearly gotten better at attacking more institutions at once.” Radware offers DDoS-mitigation tools to several high-profile clients, including U.S. banking institutions targeted in the recent attacks, Herberger says. As a result, the company has insights about numerous industrial sector attacks as well as online traffic patterns. Herberger declined to name the institutions affected, citing Radware’s non-disclosure agreements. But according to online traffic patterns collected by Internet and mobile- cloud testing and monitoring firm Keynote Systems Inc., JPMorgan Chase & Co., BB&T and PNC Financial Services Group suffered online outages on March 12. The three banks declined to comment about the attacks or confirm whether they had been targeted this week. Chase, however, acknowledged an online disruption in a March 12 post to the Chase Twitter f e ed . The post states: “*ALERT* We continue to work on getting Chase Online back to full speed. In the meantime, pls. use the Chase Mobile app or stop by a branch.” On March 13, the bank came back with this tweet: “We’re sorry it was such a rough day and we really appreciate your patience.” Phase 3 Attacks The hacktivist group Izz ad-Din al-Qassam Cyber Fighters on the morning of March 12 posted an update in the open forum Pastebin about its third phase of attacks. In it, the group mentions nine targets struck during the previous week. The group claims it is waging its attacks against U.S. banking institutions over a Youtube video deemed offensive to Muslims. The nine latest targets identified by the hacktivists – Bank of America, BB&T, Capital One, Chase, Citibank, Fifth Third Bancorp, PNC, Union Bank and U.S. Bancorp – have either declined to comment or have denied suffering any online disruptions. But Keynote Systems says Chase, BB&T and PNC suffered major online failures between 12:30 p.m. and 11 p.m. ET on March 12. Outages suffered by Chase resulted in a nearly 100 percent failure rating between the hours of 2 p.m. ET and 11 p.m. ET, says Ben Rushlo, Keynote’s director of performance management. “That means the site was unavailable most of that time. That’s pretty massive.” BB&T also had significant issues, but not quite so severe, Rushlo says. Between 12:30 p.m. and 2:30 p.m. ET, and then again briefly at 5:30 p.m. ET, BB&T’s online-banking site suffered intermittent outages, he adds. PNC’s site suffered a significant outage for a 30-minute span beginning bout 3:30 p.m. ET, Rushlo says. “On a scale relative to Chase, they were affected 10 times less.” Rushlo stresses that Keynote cannot confirm the cause of the online outages at the three banks because the company does not monitor DDoS activity; it only monitors customer-facing applications. Nevertheless, the online analysis Keynote conducts is in-depth, Rushlo contends. “We’re actually going behind the logons to emulate what the customer sees or experiences when they try to conduct online-banking,” he says. Defeating DDoS Radware’s Herberger says some institutions have successfully mitigated their DDoS exposure, while others are only succeeding at masking the duress their online infrastructures are experiencing. “There has been a lot of quick provisioning to address these attacks,” he says. “But if something changes, like it has now, then the whole game changes and the whole equilibrium changes. It’s not really solving the problem; it’s just addressing a glitch.” More banking institutions need to go beyond Internet protocol blocking to address attacks that are aimed at servers and site-load balancers, he says. But many organizations have failed to take the additional steps needed to successfully and consistently deflect these emerging DDoS tactics. “The thing that’s kind of frustrating to all of us is that we are six months into this and we still feel like this is a game of chess,” Herberger says. “How is it that an industry that has been adorned with so many resources – with more than any other industrial segment in U.S. – missed the threat of hacktivist concerns? There seems to clearly be industrial sector vulnerabilities that were missed in all of the historical risk assessments.” For DDoS protection click here . Source: http://www.bankinfosecurity.com/ddos-6-banks-hit-on-same-day-a-5607

Follow this link:
Distributed Denial of Service-DDoS: 6 Banks Hit on Same Day

Amid banking DDoS attacks, Obama convenes cybersecurity meeting with CEOs

President Barack Obama is shining yet another light on the rising cybersecurity threat in the US, sitting down with more than a dozen CEOs inside the White House Situation Room to discuss how government and the private sector can work together to better protect the nation’s citizens and critical infrastructure. “What is absolutely true is that we have seen a steady ramping up of cybersecurity threats,” Obama said in an interview on ABC’s Good Morning America . “Some are state-sponsored [and] some are just sponsored by criminals.” The timing could not be more apropos: Tuesday offered a bumper crop of cybersecurity red flags to add weight to the president’s statement. For one, a top US official told the Senate Intelligence Committee that cyber attacks are becoming the top global threat. It’s “grown to be right up there” with terrorism, said FBI director Robert Mueller, who said cybersecurity risks now keep him awake at night. Ironically, Mueller, along with First Lady Michelle Obama, Vice President Joe Biden and other political targets were made the victims of a doxxing campaign, which published online supposedly authentic personal information like mortgage statements and credit reports. Meanwhile, JPMorgan Chase and five other banks were hit with denial of service (DDoS) attacks in a renewed offensive on the financial industry yesterday. Attacks on banks have become an ongoing issue, spearheaded in 2012 with the launch of “Operation Ababil” by Islamist hacking collective Izz ad-Din al-Qassam. That attack wave was in protest of “The Innocence of Muslims,” an anti-Islam video that mocked the Prophet Muhammad. On New Year’s Day the group said that that the cyber-attacks will continue, noting in an online manifesto that “rulers and officials of American banks must expect our massive attacks! From now on, none of the U.S. banks will be safe from our attacks.” Indeed, attacks in February and last week have continued the trend, with Chase becoming the latest victim of a website slowdown. In January, a Ponemon Institute survey revealed that more than two-thirds of banks in the US have suffered DDoS attacks within the last 12 months. Gen. Keith Alexander, head of the Pentagon’s US Cyber Command, told Congress at Tuesday’s hearing that Wall Street firms were hit by more than 140 attacks in the last six months. Chase confirmed that CEO Jamie Dimon is among those accepting the president’s invitation to the meeting. Another participant will be Exxon Mobil CEO Rex Tillerson, the oil giant confirmed, but the rest of the group will not be revealed until after the summit, the White House said. Obama issued an executive order Feb. 12 aimed at improving the public sector’s ability to warn enterprises of imminent cyberthreats. It directs the government to share threat information with critical infrastructure owners, and for government agencies to develop a security framework that business can voluntarily adopt. The intention is that unclassified threat reports “that identify a specific targeted entity” will be shared, and that classified reports will be shared with “critical infrastructure entities authorized to receive them.” The White House is also seeking a comprehensive piece of legislation to further information-sharing initiatives in order to protect critical infrastructure such as the power grid, water supply equipment, transportation hubs, and so on. US House of Representatives Intelligence Committee Chairman Mike Rogers (R-Mich.) and Rep. Dutch Ruppersberger (D-Md.) introduced a new version of the Cyber Intelligence Sharing and Protection Act (CISPA) last month, which would make it easier for business and government to work together concerning threats, attacks and remedies in order to shore up defenses. For instance, the House bill as written would offer broad protection from lawsuits to companies that give over user data to the Department of Homeland Security, which in turn would share it with intelligence agencies on a need-to-know basis. In the GMA interview, Obama noted the ramifications of inaction: “Billions of dollars are lost to the consequences. You know, industrial secrets are stolen. Our companies are put into competitive disadvantage. There are disruptions to our systems that…involve everything from our financial systems to some of our infrastructure.” For DDoS protection click here . Source: http://www.infosecurity-magazine.com/view/31244/amid-banking-ddos-attacks-obama-convenes-cybersecurity-meeting-with-ceos/

View original post here:
Amid banking DDoS attacks, Obama convenes cybersecurity meeting with CEOs