Category Archives: DDoS Vendors

‘DerpTrolling’ hacker group responsible for DDoS attack on Warcraft servers

According to a CNET report, a hacker group which calls itself ‘DerpTrolling’ has recently claimed responsibility for a series of distributed denial of service (DDoS) attacks on game servers for Blizzard Entertainment’s World of Warcraft online RPG. The DDoS attack which the DerpTrolling hacker group launched on the Warcraft servers crippled the servers during the launch weekend of the Warlords of Draenor game. Claiming responsibility for the attack, DerpTrolling hackers have disclosed that they had managed to seize a massive amount of user data. According to the hacking group, the user data which has been seized as a result of the attack on Warcraft servers includes login details, password, email, and credit card information from PlayStation Network accounts as well as 2K accounts. In an elaboration of user data to which it has gained access, the DerpTrolling hacker group said in a statement to CNET: “We have 800,000 from 2K and 500,000 credit card data.” The group further declared that it has approximately “2 million Comcast accounts, 620,000 Twitter accounts, 1.2 million credentials belonging to the CIA domain, 200,000 Windows Live accounts, 3 million Facebook, 1.7 million EA origins accounts, etc.” Asserting that it has altogether seized nearly 7 million usernames and passwords from its raids, the hacker group has somewhat substantiated its claim by releasing a partial list of the hacked accounts as evidence. Source: http://uncovermichigan.com/content/22039-derptrolling-hacker-group-responsible-ddos-attack-warcraft-servers

More:
‘DerpTrolling’ hacker group responsible for DDoS attack on Warcraft servers

Drupal Patches Denial of Service Vulnerability

Details on a patched denial of service vulnerability in the open source Drupal content management system have been disclosed. The vulnerability, patched yesterday, could be abused to crash a website running on the CMS. Researchers Michael Cullum, Javier Nieto and Andres Rojas Guerrero reported the bug to Drupal and urge site owners and Drupal admins to upgrade Drupal 6.x to Drupal core 6.34 or 7.x to Drupal core 7.34. The vulnerability exposes user names in addition to threatening the availability of a Drupal site. The researchers said they were able to guess a valid Drupal user name by exploiting the bug by entering an overly long password; they give an example of a million-character password. They explain that Drupal only calculates a password hash for valid user names; by measuring the time it takes to get a response from the system with a long password, they can infer that the user name they tried is valid. “In Drupal, the way of calculating the password hash (SHA512 with a salt) by using phpass results in the CPU and memory resources being affected when really long passwords are provided,” the researchers wrote. “If we perform several log-in attempts by using a valid username at the same time with long passwords, that causes a denial of service in the server.” Depending on the server configuration—in this case Drupal 7.32 running on Apache with a MySQL default installation—the attack crashes the entire server. The researchers said this happens because the RAM and CPU limits are reached. It can also crash the database, they said. “If the Apache configuration is optimized and tuned to the hardware resources, we are able to reach all sessions available quickly and handle them for 30 seconds which performs a DOS without crashing the server or database,” the researchers said, adding that 30 seconds is the longest a script can run before it is terminated by a parser. “This helps prevent poorly written scripts from tying up the server.” The researchers said they will publish a proof of concept attack at a later time. This vulnerability was rated moderately critical by Drupal, unlike a much more serious SQL injection flaw that became public on Oct. 15. The flaw was found in a Drupal module designed to defend against SQL injection attacks. Attackers quickly wrote automated exploits targeting the vulnerability; the attacks worked without the need for a Drupal account and left no trace. Drupal quickly released an advisory urging site admins to proceed as if every Drupal 7 site that was not patched within hours of the announcement were compromised. “Attackers may have created access points for themselves (sometimes called ‘backdoors’) in the database, code, files directory and other locations. Attackers could compromise other services on the server or escalate their access. Removing a compromised website’s backdoors is difficult because it is not possible to be certain all backdoors have been found,” Drupal said in a statement. The patch was made available on Oct. 15; the vulnerability was found in a database abstraction API that sanitized queries to prevent SQL injection. Source: http://threatpost.com/drupal-patches-denial-of-service-vulnerability-details-disclosed/109502

Original post:
Drupal Patches Denial of Service Vulnerability

Sophisticated Android-based botnet a danger to enterprise networks

A new, more sophisticated and more stealthy version of the NotCompatible Android Trojan continues to strengthen one of the most long-lived and advanced mobile botnets ever to exist (since mid-2012). …

View article:
Sophisticated Android-based botnet a danger to enterprise networks

Asian mobiles the DDOS threat of 2015, security mob says

Beware traffic from hacked Vietnam, India and Indonesia fondleslabs Vietnam, India and Indonesia will be the distributed denial of service volcanoes of next year due to the profieration of pwned mobiles, according to DDoS security bod Shawn Marck.…

More here:
Asian mobiles the DDOS threat of 2015, security mob says

Fasthosts outage blamed on DDoS attack

Fasthosts’ five-hour collapse today has been blamed on a Distributed Denial of Service attack and a security flaw spotted on its Windows 2003 shared web server kit. The company explained the torrid morning it had suffered in an emailed statement to The Register . Earlier today, after we reported that Fasthosts had gone titsup, Reg reader x2uk suggested that the firm had been targeted by hackers. “Some of our customers’ domains seem to have been shifted onto their DNS overnight which may mean something nefarious is afoot,” he told us. Fasthosts finally responded to our questions just as it was telling its biz customers on Twitter that the service was coming back to life. It said: As a result of a denial-of-service attack, Fasthosts shared hosting customers experienced a loss of DNS performance, and as a result, periods of website downtime. In accordance with its procedures, Fasthosts acted swiftly to resolve the root cause, and has now implemented measures to return the majority of its hosting customers back to full performance. We apologise for any disruption incurred by our customers this morning as a result of this issue. If any customer has outstanding issues, we ask that they contact our technical support team who will assist them. Incredibly, the company’s strife didn’t end there: it has also been battling a serious security hole in its Microsoft servers. Fasthosts said: As a result of our routine and extensive security monitoring, Fasthosts today identified a vulnerability specific to part of its Windows 2003 shared web server platform. The small affected proportion of our large hosting platform was immediately isolated, and work is being undertaken to investigate and fix the issue as swiftly as possible. As a precautionary measure, some shared hosting servers on this specific platform have been taken offline, resulting in a small proportion of our hosting customers experiencing downtime. All efforts are being focused on returning this platform to service. Fasthosts added that “the security of our customer data remains of paramount importance to us.” It claimed to have “excellent levels of security monitoring, systems and resources to keep our customers’ data safe from threats.” However, the company made no mention of compensation for businesses affected by Monday morning’s outage. “We apologise unreservedly for the inconvenience caused to those customers affected today, and we remain committed to providing the highest possible standards of service,” Fasthosts said. Source: http://www.theregister.co.uk/2014/11/17/fasthosts_outage_blamed_on_ddos_hack_attack_and_windows_2003_vuln/

Follow this link:
Fasthosts outage blamed on DDoS attack

Holy cow! Fasthosts outage blamed on DDoS hack attack AND Windows 2003 vuln

Monday, bloody Monday Fasthosts’ five-hour collapse today has been blamed on a Distributed Denial of Service attack and a security flaw spotted on its Windows 2003 shared web server kit.…

More:
Holy cow! Fasthosts outage blamed on DDoS hack attack AND Windows 2003 vuln

The Bitcoin Forum At Bitcointalk.org Went Offline Due to DoS attack

Bitcointalk.org, the Bitcoin Forum, is currently offline with the official explanation being a DOS attack. In the past, Bitcointalk.org has faced hacks, man-in-the-middle attacks, and DDOS. According to isitdownrightnow, a service that tells you the status of websites worldwide, bitcointalk.org has been down since at least 17:00 PT. This is corroborated by the first reports on twitter of the bitcointalk.org outage:   In the meantime, users can use Bitcointa.lk, which stores all of the Bitcointalk.org messages and has an additional list of features, as well. Bitcointalk confirms the DoS attack: Source: https://www.cryptocoinsnews.com/bitcoin-forum-bitcointalk-org-currently-offline-due-to-dos/  

Read More:
The Bitcoin Forum At Bitcointalk.org Went Offline Due to DoS attack

Blizzard confirms World of Warcraft target of DDoS attack

Update 5:50 a.m. PST: The servers are now down for maintenance, and the attack is over. If further ones happen, we’ll announce accordingly. Update 8:15 p.m. PST The DDoS attacks continue. Blizzard is rolling out updates to the backend services at a breakneck pace right now, some of which are having unintended consequences and further complicating an already messy situation. However, it should be noted that this is to be expected when combating such a large scale attack. In no way is Blizzard responsible for the server outages on this scale — responsibility rests with the script kiddies and bot net controllers. It’s hard to know just how big this attack is, but with the sustained issues it’s causing, and the severity of response from Blizzard, it’s safe to assume that it’s big . Battle.net is a hardened internet service that has withstood onslaughts like this before. For it to fail at such a critical juncture is nothing but catastrophic for the short term, and could have serious long term implications. We have some idea, shown above, of just how global this attack is. We’ll update this post as the night continues, providing you with the latest. In the mean time — we recommend you catch up on your lore, and not concern yourself with logging in. Original Post: WoW Insider received reports earlier today that Blizzard may be the target of a significant DDoS effort — and community manager Bashiok has confirmed it on the World of Warcraft forums. Bashiok goes on to outline additional issues Blizzard is currently attempting to resolve: instance servers timing out, disconnects from the continent servers, and performance and phasing issues with garrisons. Source: http://wow.joystiq.com/2014/11/13/blizzard-confirms-world-of-warcraft-target-of-ddos-attack/

Visit site:
Blizzard confirms World of Warcraft target of DDoS attack

Dormant IP addresses RIPE for hijacking

‘That’s not us spamming, honest’ cries hosting firm Spammers are using loop holes in the internet routing registry to commandeer address space and pump out junk mail, and potentially launch denial of service attacks and steal traffic.…

Read the original:
Dormant IP addresses RIPE for hijacking

Your computer might be launching a DDoS attack

India stands first in a list of 50 countries where distributed denial-of-service (DDoS) originate and cybercriminals can get DDoS attacks on hire for Rs. 300 for a three-minute assault. These were the findings of a research titled ‘The continued rise of DDoS attacks’, conducted by engineers and analysts at Symantec, evaluating data between January and August 2014, based on its 41.5 million attack sensors and records of thousands of events per second in 157 countries. A DDoS attack is an attempt to deny a service to users by overwhelming the target with activity. Botnets bombard the server with requests which it is unable to understand or process. It is ‘distributed’ as multiple sources attack the same target. The legitimate user gets messages such as ‘the server is undergoing technical problems and will be right back’. Any home computer can be part of a botnet due to installation of malicious software. While the study said 26 of all the DDoS traffic originated in India, (followed by the U.S., Singapore, Vietnam and China), Tarun Kaura, director, Technology Sales, Symantec India, told The Hindu that it did not mean people launching DDoS attacks were located in India, as the attacks were orchestrated remotely. He said, “It does not mean the hackers are Indians or that the targets are Indians. But it indicated India’s emergence as a hotbed for launching the attacks due to low cyber security awareness and inadequate security practices. This is because sources for the attacks are countries that have a high number of bot-infected machines and a low adoption rate of filtering of spoofed packets.” In spoofed packets, a sender can make it appear like the data packet has arrived from a different source. The study further said “booter” services were available on rent so a DDoS attack could be “hired” at Rs. 300 ($ 5) for a few minutes against targets. Booter services are web-based services that do DDoS attacks for hire at low prices. Higher prices fetch longer attacks and gamers use them as a monthly subscription service to kick at competitors. DDoS attacks are a favourite with hacktivists and cyber gangs to threaten rivals, settle personal grudges, and to distract IT security response teams. Most attacked sectors globally are the gaming, software, and media industries. In future, attacks were likely to increase in mobile and Internet of Things (IoT) devices, and users should protect their servers and know their network’s “normal” behaviour to respond to attacks, the study said. Source: http://www.thehindu.com/news/cities/bangalore/your-computer-might-be-launching-a-ddos-attack/article6580933.ece

Read More:
Your computer might be launching a DDoS attack