Hackers attacking US banks are well-funded, expert says

The Cyber fighters of Izz Ad-Din Al Qassam hacker group – also known as Qassam Cyber Fighters – are at it again. For the third time in the last half year or so, they have mounted DDoS attacks agai…

See the article here:
Hackers attacking US banks are well-funded, expert says

DoS attacks expose enterprise infrastructure vulnerabilities

Lurking in the shadows for nearly a decade, DoS and DDoS attacks are making a resurgence. Several high-profile assaults on the world's leading financial firms and other industries have recently been e…

Read More:
DoS attacks expose enterprise infrastructure vulnerabilities

Airlock launches secure cloud hosting

Airlock launched its Secure Cloud Platform which offers enterprise-level security features like intrusion detection, hardware and web application firewalls, DDoS mitigation and malware scanning. Airlo…

Read More:
Airlock launches secure cloud hosting

Call centers under attack in targeted cyber-blackmail scheme

Crooks blasting public-safety phone lines with calls The US Department of Homeland Security (DHS) has cautioned public-safety call centers against the rise of so-called telephony denial of service (TDoS) attacks, which it says have the potential to cripple local telephone exchanges.…

Read the article:
Call centers under attack in targeted cyber-blackmail scheme

iMessage DDoS attacks foreshadow a bigger threat

Over the last couple of days, a group of iOS developers has been targeted with a series of rapid-fire texts sent over Apple’s iMessage system. The messages, likely transmitted via the OS X Messages app using a simple AppleScript, rapidly fill up the Messages app on iOS or the Mac with text, forcing a user to constantly clear both notifications and messages. In some instances, the messages can be so large that they completely lock up the Messages app on iOS, constituting a ‘denial of service’ (DoS) attack of sorts, even though in this case they appear to be a prank. Obviously, if the messages are repeated an annoyingly large volume but don’t actually crash the app, they’re still limiting the use you’ll get out of the service. But if a string that’s complex enough to crash the app is sent through, that’s a more serious issue. The attacks hit at least a half-dozen iOS developer and hacker community members that we know of now, and appear to have originated with a Twitter account involved in selling UDIDs, provisioning profiles and more that facilitate in the installation of pirated App Store apps which are re-signed and distributed. The information about the source of the attacks was shared by one of the victims, iOS jailbreak tool and app developer iH8sn0w. “On Wednesday night my private iMessage handle got flooded with “Hi” and “We are anonymous” bulls**t,” iH8sn0w tells us. He immediately disabled that iMessage email and began tracking the sending email domain’s current ownership. iH8sn0w shared a proof-of-concept AppleScript with us that demonstrates just how easy it is to set up a recurring message that could saturate a person’s iMessage queue with items that would need to be cleared or read before any actions could be taken. Another iOS developer targeted, Grant Paul, shared some additional details about the attacks. “What’s happening is a simple flood: Apple doesn’t seem to limit how fast messages can be sent, so the attacker is able to send thousands of messages very quickly,” Paul says. The second part of that, he explains, is that if a user sends a ‘complex’ text message using unicode characters that force a browser to render ‘Zalgo’ text, or simply uses a message that is enormous in size, them the Messages app will eventually crash as it fails to display it properly. This will effectively ‘break’ the Messages app on iOS by forcing it to close and stop it from re-opening because it can’t render that text.” The ‘send a big message to crash the app’ method has been known for a while, as we were able to locate a month-old public posting that detailed an accidental triggering of this. The solutions involve playing around with sending a regular message, then locking the phone and activating the message notification until you’re able to time it right to delete the message thread that’s causing the problem. This is the way that Paul was able to finally delete the complex text that was causing him problems. Several of the developers we spoke to noted that multiple ‘throwaway’ emails were being used to send the spam, so while a simple ‘block’ option might work for a casual spammer, they wouldn’t work for a determined harasser. iH8sn0w notes that there is a possibility that Apple will notice these bursts of messages and block the repetitive spamming. This appears to be the only real solution as Apple does not currently allow you to block a specific iMessage sender. Once your iMessage ID is out there, you’re unable to stop people from using it. And since the latest version of iOS unifies your phone number and emails, there’s a strong possibility that if a person can ferret out your email, they can spam you with this annoying or disruptive technique. The only recourse right now is to disable that iMessage handle entirely. And if they get your phone number, it’s likely you’ll have to turn off iMessage entirely, because you can’t just change your phone number at the drop of a hat. Thankfully, this doesn’t seem to be a widespread practice, but it’s not that hard to figure out, and the only real solution will be the introduction of a block setting for Messages and better spam detection by Apple. We have informed Apple about the technique used in these cases but it has not responded with more information. We will update the article if it does so. Source: http://thenextweb.com/apple/2013/03/29/imessage-denial-of-service-prank-spams-users-rapidly-with-messages-crashes-ios-messages-app/

Continued here:
iMessage DDoS attacks foreshadow a bigger threat

Week in review: Massive DDoS attack targets Spamhaus, Amazon S3 buckets leaking, and cyber espionage deterrence

Here's an overview of some of last week's most interesting news, podcasts, videos and articles: What do users look for in a security solution? Users are aware of the dangers in the Internet and …

Visit site:
Week in review: Massive DDoS attack targets Spamhaus, Amazon S3 buckets leaking, and cyber espionage deterrence

DDoS Attack Strikes American Express site

American Express confirms it was hit by a distributed-denial-of-service attack that disrupted online-account access for about two hours during the late afternoon on March 28. AmEx spokeswoman Amelia Woltering says the card brand is still investigating the attack. She did not confirm whether the strike was linked to Izz ad-Din al-Qassam Cyber Fighters, the hacktivist group that’s been targeting U.S. banking institutions since mid-September. But that group claims credit for this attack, as well as an unconfirmed attack against Bank of America, according to updates posted to a blog and on Twitter March 28. “The Bank of America and American Express have gotten out of reach today due to Izz ad-Din al-Qassam group’s attacks,” the blog posting says. “The Qassam group’s attacks to these banks have caused the banks to be unable to offer service to their customers and this [will] lead to their protests.” The attack began about 3 p.m. ET on March 28, Woltering says, and caused intermittent disruptions. She says there is no evidence to suggest that customer data or account information was exposed or compromised during the attack. “Our site experienced a distributed-denial-of-service (DDoS) attack for about two hours on Thursday afternoon,” AmEx says in a statement. “We experienced intermittent slowing on our website that would have disrupted customers’ ability to access their account information. We had a plan in place to defend against a potential attack and have taken steps to minimize ongoing customer impact.” Big Week for DDoS The attack comes just days after news of the Spamhaus DDoS attack , which caused a ripple effect that adversely affected online activity.   That attack saw unprecedented traffic of 300 gigabytes per second, three to five times greater than the biggest attacks against U.S. banks, says Dan Holden, an online security expert for DDoS-mitigation provider Arbor Networks. Still, the European attack – a strike against The Spamhaus Project , a Geneva-based not-for-profit organization dedicated to fighting Internet spam operations – is not believed to be related to the attacks on U.S. banks. “The DNS reflection attacks [like the one used against Spamhaus] can consume a great deal of bandwidth, but they are different than what we’ve seen against the banks,” Holden says. “These guys would not be able to do the sophisticated, targeted attacks that are being launched against U.S. banks.” The attacks against U.S. banks, experts say, are much more complex and sophisticated, and their intensity has escalated in the last week. Earlier this week, TD Bank and Keybank confirmed their online banking sites had been hit by DDoS attacks, and industry experts say hacktivists’ attacks waged during this so-called third campaign are becoming increasingly sophisticated. Izz ad-Din al-Qassam Cyber Fighters, the hacktivist group taking credit for attacks against U.S. banking institutions, in an update posted to the online forum Pastebin on March 26, says it most recently targeted BB&T, PNC Financial Services Group, JPMorgan Chase & Co., Citibank, U.S. Bancorp, SunTrust Banks, Fifth Third Bancorp, Wells Fargo & Co., and others. Since Feb. 25, when the group launched its third phase of DDoS attacks , weekly updates have appeared on Pastebin on Mondays and Tuesdays about previous-week targets. The hacktivist group says its attacks are in protest of a YouTube movie trailer deemed offensive to Muslims. For DDoS protection click here . Source: http://www.bankinfosecurity.com/ddos-strikes-american-express-a-5645

Read this article:
DDoS Attack Strikes American Express site

BIGGEST DDoS in history FAILS to slash interweb arteries

Bombardment without collateral damage – amazing Analysis   The massive 300Gbit-a-second DDoS attack against anti-spam non-profit Spamhaus this week didn’t actually break the internet’s backbone, contrary to many early reports.…

More here:
BIGGEST DDoS in history FAILS to slash interweb arteries