Will we ever can the spam monster?

An unending battle against email-borne nasties and botnets Spam may be the best known security threat in the world. Anyone with email or a Facebook account has experienced it, despite providers’ best efforts to block it from their inboxes.…

Continue Reading:
Will we ever can the spam monster?

Secondhand DDoS: Why hosting providers need to take action

Unfortunately, the sheer size and scale of hosting or datacenter operator network infrastructures and their massive customer base presents an incredibly attractive attack surface due to the multiple entry points and significant aggregate bandwidth that acts as a conduit for a damaging and disruptive DDoS attack. As enterprises increasingly rely on hosted critical infrastructure or services, they are placing themselves at even greater risk from these devastating cyber threats – even as an indirect target. What is secondhand DDoS? The multi-tenant nature of cloud-based data centres and shared, hosted environments can be less than forgiving for unsuspecting tenants. A DDoS attack, volumetric in nature against one tenant, can lead to disastrous repercussions for others; a domino effect of latency issues, service degradation and potentially damaging and long lasting service outages. The excessive amount of malicious traffic bombarding a single tenant during a volumetric DDoS attack can have adverse effects on other tenants as well as the overall data centre or hosting providers operation. In fact, it is becoming more common that attacks on a single tenant or service can completely choke up the shared infrastructure and bandwidth resources, resulting in the entire data centre can be taken offline or severely slowed – AKA, secondhand DDoS. Black-holing or black-hole routing is a common, crude defense against DDoS attacks, which is intended to mitigate secondhand DDoS. With this approach, the cloud or hosting provider blocks all packets destined for a domain by advertising a null route for the IP address (es) under attack. There are a number of problems with utilising this approach for defending against DDoS attacks: Most notably is the situation where multiple tenants share a public IP address range. In this case, all customers associated with the address range under attack will lose all service, regardless of whether they were a specific target of the attack. In effect, the data centre or hosting operator has finished the attacker’s job by completely DoS’ing their own customers. Furthermore, injection of null-routes is a manual process, which requires human analysts, workflow processes and approvals; increasing the time to respond to the attack, leaving all tenants of the shared environment suffering the consequences for extended periods of time, potentially hours. The growing dependence on the Internet makes the impact of successful DDoS attacks-financial and otherwise-increasingly painful for service providers, enterprises, and government agencies. And newer, more powerful DDoS tools promise to unleash even more destructive attacks in the months and years to come. Enterprises which rely on hosted infrastructure or services need to start asking the tough questions of their hosting or datacentre providers, as to how they will be properly protected when a DDoS attack strikes. As we’ve seen on numerous occasions, hosted customers are simply relying on their provider to ‘take care of the attacks’ when they occur, without fully understanding the ramifications of turning a blind eye to this type of malicious behavior. What to do to mitigate an attack and protect the infrastructure Here are three key steps for providers to consider to better protect their own infrastructure, and that of their customers. Eliminate the delays incurred between the time traditional monitoring devices detects a threat, generates an alert and an operator is able to respond; reducing initial attack impact from hours to seconds by deploying appliances that both monitor and mitigate DDoS threats automatically. The mitigation solution should allow for real-time reporting alert and event integration with back-end OSS infrastructure for fast reaction times, and the clear visibility needed to understand the threat condition and proactively improve DDoS defenses. Deploy the DDoS mitigation inline. If you have out-of-band devices in place to scrub traffic, deploy inline threat detection equipment quickly that can inspect, analyse and respond to DDoS threats in real-time. Invest in a DDoS mitigation solution that is architected to never drop good traffic. Providers should avoid the risk of allowing the security equipment to become a bottleneck in delivering hosted services—always allowing legitimate traffic to pass un-interrupted, a do no harm approach to successful DDoS defense. Enterprises rely on their providers to ensure availability and ultimately protection against DDoS attacks cyber threats. With a comprehensive first line of defense against DDoS attacks deployed, date centre and hosting providers are protecting its customers from damaging volumetric threats directed at or originating from or within its networks. Source: http://www.information-age.com/technology/security/123458517/secondhand-ddos-why-hosting-providers-need-take-action

Link:
Secondhand DDoS: Why hosting providers need to take action

MAC BOTNET uses REDDIT comments for directions

17,000 Macs compromised by malicious miscreants A zombie network that feasts on the computer brains of infected Macs has press-ganged 17,000 compromised machines into its ranks, Russian anti-virus firm Dr Web warns.…

Visit site:
MAC BOTNET uses REDDIT comments for directions

New OS X backdoor malware roping Macs into botnet

New malware targeting Mac machines, opening backdoors on them and roping them into a botnet currently numbering around 17,000 zombies has been spotted and analyzed by malware researchers of Russian AV…

See more here:
New OS X backdoor malware roping Macs into botnet

The History of DDoS Attacks as a Tool of Protest

Although the web is only a quarter of a century old, it already has a rich history as a platform for worldwide protest. One common tool used by online activists is the distributed denial of service attack, or DDoS: a technologically crude tactic that involves sending so many requests to a target website that it crashes. In recent years, politically motivated DDoS attacks have been launched on the websites of financial giants and local government departments. This year, websites affiliated with the football World Cup were brought down in protest against FIFA. “DDoS has been around as an activist tactic probably since the early 90s,” Molly Sauter, a research affiliate at Harvard University’s Berkman Center for Internet and Society and doctoral student at McGill University, told me. Sauter is the author of the upcoming book The Coming Swarm: DDoS Actions, Hacktivism and Civil Disobedience , which details the history of the DDoS attack from an obscure, insular activity carried out by artists and intellectuals to a hallmark of 21 st century protest. The earliest example of a DDoS attack that Sauter found in her research was implemented by the Strano Network, an Italian collective that launched an attack in 1995 to protest against the French government’s nuclear policy. Back then, DDoS attacks were laborious, manual affairs, requiring participants to constantly remain at their computer. And because having an internet connection was relatively expensive, they couldn’t last for long. The attack in this case only endured for about an hour. The next major milestone was the use of DDoS by the Electronic Disturbance Theater (EDT). Originating in the 90s, and attracting the attention of the media by the end of the decade, the hacktivist group described DDoS as akin to a “virtual sit-in.” One thing that separated them from their predecessors was their use of tools developed in-house, which allowed anyone outside of the organisation to join in. Their kit, called FloodNet, directed a user’s traffic to a target predetermined by the EDT, which included the websites of politicians and the White House. Those wishing to join the “sit-in” simply selected their target from a drop down menu, clicked attack, and relaxed while FloodNet automatically bombarded the offending server. The well-known hacker collective Anonymous took this idea of crowd-sourced activism further, and popularised the idea of voluntary botnets. Often used by criminals, a botnet is a large number of systems, all linked together, which give whoever is in charge of them a whole lot of processing power to wield. DDoS is incredibly simplistic, at a purely technological level. By using the hacker-designed software Low Orbit Ion Cannon, and its subsequent upgrades, participants could connect their computer to a vast network and have it donate resources to DDoS attacks. And that pretty much brings us up to today. “DDoS is incredibly simplistic, at a purely technological level,” Sauter said. “While there might be individual innovations in ways of masking or multiplying traffic, it’s not actually going to get much more advanced than that.” But it’s not just the technical details of DDoS that have mutated over the years. The scale of attacks using the device has developed, too. “Groups have become better at attracting, acknowledging and manipulating media coverage in order to attract more participants,” Sauter explained. While earlier groups just did their own thing, Anonymous managed to engage those outside of their immediate cohort more readily. With their iconic imagery, popular Twitter accounts and evocative videos, the media had a lot of material to work with. The press lacked any sort of official spokesperson of Anonymous to talk to—“So they just tended to reproduce these artifacts in media coverage, which did the work of recruitment for Anonymous,” Sauter observed. “Anonymous didn’t have to do a lot of ‘active’ outreach. That was being done for them.” What actually constitutes a ‘successful’ DDoS attack has also changed. “In the 90s, you could sit in front of your computer with your friends, go to whitehouse.gov, click refresh a bunch of times, and you had a significant chance of the website crashing,” said Sauter. An industry has since emerged to offer protection from DDoS attacks, so crashing a major service today is rarer, though still possible with some serious fire-power. But there’s another way to measure the success of DDoS actions than just website down time. Sauter explained that, when it comes to activism in general, “The logic of change is that you have an action, you get covered in the press, then politicians and the public react to the press coverage, not so much the action itself.” This overall impact is perhaps more important than how long a specific website is technically inaccessible. As Sauter said, “The question of what success means is fairly up in the air.” Some argue that DDoS as a protest tool should be formally recognised as political speech, and enjoy the same free-speech protections as street marches, for example. Jay Leiderman, a criminal defense lawyer, has argued that DDoS is a first amendment issue in defence of the “PayPal 14,” a group of WikiLeaks supporters involved in a DDoS attack against the e-commerce business. Attorney Stanley Cohen, who represented one of the accused, described the act as an “electronic sit in,” and members of Anonymous also created a petition, pushing for politically motivated DDoS to be legalised. CIVIL DISOBEDIENCE AND OTHER TYPES OF ORGANISED LAW BREAKING ONLINE ARE STILL CONSIDERED VERY MUCH FRINGE ACTIVITIES. But DDoS can of course also be used for much less sympathetic purposes. “The biggest problem that activist DDoS faces in terms of its fight for legitimacy is criminal DDoS,” said Sauter. “DDoS is a very popular tactic in terms of harassment, extortion and other criminality.” For example, botnets for DDoSing purposes are reportedly already being created to exploit the Shell Shock bug, a recently revealed weakness in Linux and Unix operating systems. Furthermore, Sauter suggested that online activism in general still isn’t really accepted because it remains an alien concept to many people. “Civil disobedience and other types of organised law breaking online are still considered very much fringe activities because there isn’t an understanding that civil disobedience is something that you can do on the internet,” Sauter said. “That I hope is something that will change, but it will take a legal challenge.” But Sauter feels that political DDoS will continue to gain popularity when it comes to activism, and that it might even have something more to give. Whether it’s the Electronic Disturbance Theater protesting against neoliberalism, or Anonymous rising up to fight what they see as injustices, DDoS actions do not exist in a vacuum. Today, politically motivated DDoS is often part of a broader activist culture in the information age. Sauter suggested it could therefore introduce activists to other ideas, “such as information exfiltration, and leaking, and the construction of alternative infrastructures to replace the corporate-dominated and government-surveilled that are currently the main ways of socialising and communicating online.” In short, DDoS attacks in activist circles can be about more than just crashing a few servers. Source: http://motherboard.vice.com/en_uk/read/history-of-the-ddos-attack

Visit link:
The History of DDoS Attacks as a Tool of Protest

Global DDoS attack numbers decline, attacks from China rise

In the second quarter of 2014, Akamai observed attack traffic originating from 161 unique countries/regions, which was 33 fewer than the first quarter of the year. The highest concentration of attacks…

Read More:
Global DDoS attack numbers decline, attacks from China rise

Researcher details nasty XSS flaw in popular web editor

First denial, then anger, then DDoS , then patching. A tool that’s popular with Microsoft’s in-house developers, the RadEditor HTML editor, contains a dangerous cross-site scripting (XSS) vulnerability, researcher GS McNamara says.…

See the original post:
Researcher details nasty XSS flaw in popular web editor

PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai

First time the cache network has seen drop in use of 32-bit-wide IP addresses Broadband and IPv6 are hot – and distributed denial-of-service attacks and IPv4 are not. Well, that’s according to Akamai.…

Link:
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai

Shellshock: ‘LARGER SCALE ATTACK’ on its way, warn securo-bods

Not just web servers under threat – though TENS of THOUSANDS have been hit The Shellshock vulnerability has already become the focus for malicious scanning and at least one botnet but crooks are still testing the waters with the vulnerability and much worse could follow, security watchers warn.…

Follow this link:
Shellshock: ‘LARGER SCALE ATTACK’ on its way, warn securo-bods

Telegram under 150Gbps DDoS attack

Cross platform messaging app Telegram has been a target of massive distributed denial of service (DDoS) attacks for two days in a row over the weekend with the largest in tune of 150Gbps. The DDoS attacks started on Saturday – September 27 – and according to Telegram the scale of the attack was in tune of tens of Gbps. “A DDoS attack on Telegram in progress, tens of Gigabitsec. Users in some countries may have connection issues. We’re working on it, folks!” tweeted Telegram. Prior to the official confirmation, users started complaining of connectivity issues as well as not being able to send messages successfully. These complaints were picked up by Telegram administrators and upon investigation they zeroed it down to DDoS attack. Telegram soon managed to recover from the attack, but DDoS perpetrators launched another massive attack and this time in tune of of 150Gbps. “Detecting a 150+ Gbit/s DDoS now, an attack three times as large as yesterday’s.” tweeted Telegram. Users are still complaining about connectivity issues and there has been no confirmation from Telegram on whether they have been able to resolve the issue or not. Source: http://www.techienews.co.uk/9718714/telegram-150gbps-ddos-attack/

Continued here:
Telegram under 150Gbps DDoS attack