Microsoft concludes Russian programmer didn't operate Kelihos botnet

Following the settling of the Nitol botnet lawsuit earlier this month, Microsoft has announced on Friday that it has reached a settlement with Russian software programmer Andrey N. Sabelnikov, who was…

Visit site:
Microsoft concludes Russian programmer didn't operate Kelihos botnet

Distributed Denial of Service ‘DDoS’ Attacks Increasing In Number and Intensity

Businesses are seeing an increase of Distributed Denial of Service (DDoS) attacks in comparison to last year, with attacks becoming shorter but more robust, according to a quarterly report released Oct. 16 by DDoS mitigation company Prolexic. During a DDoS incident, an attacker prevents users from being able to access a website. In order to achieve this, he typically uses malware to infect a network of computers, or botnet. The attacker can control the botnet to overwhelm a website with data and requests, forcing it to crash or become slow to the point of being unusable. For businesses, DDoS attacks can be crippling, resulting in a loss in profit or customer service until the website can be restored. Prolexic’s report found DDoS incidents have increased by 88 percent when compared to the same period of time last year. Perhaps more troubling, the incidents are becoming more intense, using higher bandwidth volumes. Prolexic President Stuart Scholly said that on average the company is seeing attacks with a bitrate of 20 gigabites per second or more every eight days. Few enterprises have networks with the capacity to withstand attacks of that size, he added. China continues to be the top source country for attacks, responsible for about 35 percent, with the United States following with 27 percent, the report found. Although the United States was the source country for only 8.76 percent of attacks last quarter, Scholly said the United States is typically the second-ranked source country after China. “Twenty gigs is the new norm,” he said. “There’s no doubt in my mind that that trend continues.” A DDoS toolkit called “itsoknoproblembro” was responsible for the majority of the high bandwidth floods this quarter, the report stated. The toolkit is especially effective because it targets vulnerable servers instead of individual computers, making the botnet easier to control and yielding a higher bandwidth, Scholly said. “What might have taken 50,000 compromised home machines before might only take a couple thousand servers now,” he said. “And it’s easier to coordinate the activities of a couple thousand high capacity machines.” The toolkit has been linked in reports to the suspected attacks on financial institutions during September, but Scholly would not comment on what companies were attacked, citing customer privacy. “What I can tell you is that this toolset is something that we’ve been observing over the years, and we’ve seen it used in multiple sectors,” he said. “It was has by no means been targeted at one individual sector.” Scholly would also not comment on what actors were responsible for the toolkit. Motivation for attacks can vary from state-sponsored activities, competing companies trying to get an economic advantage, or the overloading a server as a means of social protest, he said. Another continuing trend is the growing popularity of shorter attacks, Scholly said. “The more you expose your botnet during an attack, the greater likelihood that you have for someone to start taking it down,” he said. “So you want to accomplish your goal, and then kind of move on.” For DDoS protection against your eCommerce site please contact us . Source: http://www.nationaldefensemagazine.org/blog/Lists/Posts/Post.aspx?List=7c996cd7-cbb4-4018-baf8-8825eada7aa2&ID=929

View original post here:
Distributed Denial of Service ‘DDoS’ Attacks Increasing In Number and Intensity

HSBC websites fell in DDoS attack last night, bank admits

Hacktivists blamed for online banking blackout Updated   HSBC has blamed a denial of service attack for the downtime of many of its websites worldwide on Thursday night.…

Originally posted here:
HSBC websites fell in DDoS attack last night, bank admits

More Banks Come Under Denial-of-Service Attack

Capital One and SunTrust came under attack this week using denial-of-service techniques that are evading defenses meant to blunt such attacks. Capitol One and SunTrust Banks have become the latest targets of hackers who have leveled attacks at U.S. financial institutions in alleged retaliation for the posting of a movie on YouTube that has offended some Muslims. On Oct. 8, a group calling itself the Izz ad-Din al-Qassam Cyber Fighters posted a message on Pastebin stating that Capital One, SunTrust Banks and Regions Financial would each suffer an eight-hour attack starting with Capital One the next day. Even with the advanced warning, the financial institutions suffered outages, with Capital One’s site frequently inaccessible during the eight-hour period. “Some Capital One customers experienced intermittent online access due to a large volume of traffic going to the Website and servers,” the bank said in a statement posted to its Web site. ”Other banks have experienced similar issues in recent weeks due to targeted efforts designed to flood online systems, also known as a distributed denial-of-service attack.” On Oct. 10, SunTrust Banks suffered some performance issues, as did Regions Financial the next day, according to media reports. The attacks are the latest data floods in a campaign that started in mid-September. Under the name “Operation Ababil,” a group of alleged Iranian protestors called for supporters to attack the Bank of America, JPMorgan, Citigroup and Wells Fargo. Yet the crowd-sourced hacktivism effort caused little damage. Instead, a second attack coming from hundreds—or at most, thousands—of compromised servers made up the most effective part of the data flood. Using compromised servers and customized malware, the attackers have hit targeted sites with between 70G bps and 100G bps of peak traffic, according to experts. The attacks—launched from servers used to publish corporate Websites and blogs but running vulnerable content management software—sent packets of data crafted to evade typical defenses, even those specifically designed to curtail denial-of-service (DoS) attacks. “They had far fewer machines involved and with much larger bandwidth,” Dan Holden, director of security for network-protection firm Arbor Networks, said of the earlier attacks. “These are Web or hosting servers that have been compromised and are obviously poorly administered.” Typical defenses against distributed denial-of-service attacks attempt to minimize the impact of an attack by intercepting the request as far away from the target Website as possible. By blocking attacks in other networks, the customer is not impacted by a massive influx of data. However, the latest attacks are using evasion techniques to get around standard denial-of-service defenses, said Phil Lerner, vice president of technology at security firm Stonesoft. By crafting the data to look like valid encrypted Web requests, the network packets are allowed to get through to the customers’ own computers to decipher the information. Even if that system blocks the request as invalid, the avalanche of data buries the computer, which can’t keep up. “DDoS [distributed denial-of-service] mitigation is not a cure-all,” Learner said. “You don’t have enough protocol decoding capabilities, and you are only doing partial defenses, or none at all, on the evasion detection.” Companies need to adopt security defenses that handle such evasion techniques, he said. In July, a researcher at cloud-security firm Qualys demonstrated that evasion techniques can cause problems for Web application firewalls (WAFs) as well. A variety of tricks, sometimes just adding a single character, could bypass the security offered by WAFs, according to the research. Source: http://www.eweek.com/security/more-banks-come-under-denial-of-service-attack/

View original post here:
More Banks Come Under Denial-of-Service Attack

U.S. banks warned of another Distributed Denial of Service ‘DDoS’ attack

Just as one type of attack against U.S. banks has subsided, the banks are being warned to get ready for another, called “Project Blitzkrieg,” aimed at online theft. Iran denies launching cyberattacks on U.S. banks The distributed-denial-of-service (DDoS) attacks that briefly disrupted the online services of a half-dozen major financial institutions late last month — Wells Fargo, U.S. Bancorp, PNC Financial Services Group, Citigroup, Bank of America and JPMorgan Chase — ended abruptly about two weeks ago, even though the group that claimed credit for them had threatened to continue them. Izz al-Din al-Qassam Cyber Fighters, the military wing of Hamas, the Islamic party that governs the Gaza Strip, had said in a Pastebin message that the attacks would continue until a trailer of the independent film “Innocence of Muslims,” which they said insults the prophet Mohammed, was taken off the Internet. But now, says a blog post by Mor Ahuvia, cybercrime communication specialist at security firm RSA, another wave of attacks is looming, this one aimed at stealing big money. “A cyber gang has recently communicated its plans to launch a Trojan attack spree on 30 American banks as part of a large-scale orchestrated crimeware campaign,” Ahuvia wrote. “Planned for this fall, the blitzkrieg-like series of Trojan attacks is set to be carried out by approximately 100 botmasters. RSA believes this is the making of the most substantial organized banking-Trojan operation seen to date.” RSA said the gang leadership appears to come from Russia, and plans to use a “Gozi-like Trojan” that RSA is calling Gozi Prinimalka. Prinimalka is derived from the Russian word meaning “to receive.” “According to underground chatter, the gang plans to deploy the Trojan in an effort to complete fraudulent wire transfers via Man-In-The-Middle (MiTM) manual session-hijacking scenarios,” Ahuvia wrote. “If successfully launched, the full force of this mega heist may only be felt by targeted banks in a month or two. The spree’s longevity, in turn, will depend on how fast banks and their security teams implement countermeasures against the heretofore-secret banking-Trojan,” she wrote. Brian Krebs, who writes the blog KrebsonSecurity, said in a recent post that the RSA analysis “seemed to merely scratch the surface of a larger enterprise that speaks volumes about why online attacks are becoming bolder and more brash toward Western targets.” But he also said this particular threat could be a hoax — that there is some suspicion in the cybercrime world that it could be a sting operation by Russian law enforcement, since the announcement has been so public. Krebs said the threat appears to be coming from a series of posts on Underweb forums by a Russian hacker nicknamed “vorVzakone.” His name translates to “thief-in-law,” which Krebs said, “in Russia and Eastern Europe refers to an entire subculture of elite criminal gangs that operate beyond the reach of traditional law enforcement. The term is sometimes also used to refer to a single criminal kingpin.” Krebs said vorVzakone called the campaign “Project Blitzkrieg,” and according to a translation of one of his messages, said he hopes to recruit 100 botmasters to take advantage of authentication weaknesses in U.S. bank systems before they can improve their protection. The botmasters would have to qualify with an online interview and be trained, and would then get to share in the profits. In vorVzakone’s message, he said: “The development of the system took 4 years of daily work and around $500.000 was spent. Since 2008 by using this product not less than $5m was transferred just by one team.” Jason Healey of the Atlantic Council, a cybercrime expert and former White House security official, said it sounds to him like the group is “trying to be the Russian online equivalent of Ocean’s Eleven — call it Ocean’s Odinnadsat’ — or a group that wants to be seen in that light. They can get some cool points, either way.” Most security experts say the financial sector is the best prepared of any in the U.S. to deal with direct attacks. But these attacks will, of course, not be aimed directly at the banks, but at their customers. And vorVzakone also wrote that the operation will flood cyberheist victim phone lines while the victims are being robbed, in an effort to prevent account holders from receiving confirmation calls or text messages from their banks.” In an interview, Brian Krebs said cyber thieves, “almost always target the line of least resistance, and that is the customer. That doesn’t excuse the banks from their obligation to be constantly upgrading their defenses against such attacks. There are thousands of financial institutions in the U.S. and many of them are woefully behind in updating their customer-facing security measures.” He noted that banking law does not protect commercial and business customers at the same level as individual customers, and said banks need to do much better at flagging abnormal transaction behavior, such as, “a sudden addition of many new employees to an organization’s payroll, particularly if those people are spread all over the country geographically.” “You’d be amazed at how many times a month some bank lets this happen, and with disastrous results,” Krebs said. Still, if vorVzakone and his presumed colleagues are serious about their plan, why broadcast it so blatantly? Is that an indication that the whole thing may be a fraud? Krebs said there is reason for skepticism, noting in his blog post that vorVzakone even posted a homemade movie on YouTube, in which he. “introduces himself as ‘Sergey,’ the stocky bald guy in the sunglasses. He also introduces a hacker who needs little introduction in the Russian underground — a well-known individual who used the nickname ‘NSD.’” Krebs then quotes one Russian expert saying vorVzakone’s “language and demeanor is that of street corner drug dealer or a night club bouncer,” not someone who can organize and run a sophisticated cyberheist operation. Krebs himself is not quite as harsh, but said such projects “are announced all the time on the underground, but usually they are in fairly closed, secretive forums. The forums on which this project was announced were moderately secret, but it’s fairly unusual for miscreants to create YouTube videos of such projects and to promote them so openly.” Healey said the public bragging is a mistake. “To succeed with a Trojan, you want it to be somewhat secret with few people involved,” he said. “The few who are involved should be well known and trustworthy. That is the opposite of what Ocean’s Odinnadsat’ has done.” He said that and the fact that they are recruiting people who may be unknown to them “makes it more likely that the intel and threat companies, and law enforcement, can get the code beforehand.” Another problem that could undermine the operation is simple organizational weaknesses. “My sense is that such a project would require a decent amount of operational cohesion and security, and cooperation,” Krebs said. “From what I’ve seen of the underground, the more people you involve in a scheme, the more likely it is to fall apart.” But he said whether this threat is real or not, the need for protection is crucial. The best way for customers to avoid theft is to prevent their computer from being infected. “The trouble is,” Krebs said. “It’s becoming increasingly difficult to tell when a system is or is not infected. That’s why I advocate the use of a Live CD approach to online banking. That way, even if the underlying hard drive is infected with a remote-access, password stealing Trojan like Gozi, your online banking session is protected.” Source: http://www.networkworld.com/news/2012/101012-us-banks-warned-of-another-263227.html?page=1

Continue reading here:
U.S. banks warned of another Distributed Denial of Service ‘DDoS’ attack

Proxy service users download malware, unknowingly join botnet

In yet another example of if-it's-too-good-to-be-true-it-probably-isn't, hundreds of thousands of users signing up for a cheap and supposedly legitimate proxy service have ended up downloading malware…

Taken from:
Proxy service users download malware, unknowingly join botnet

Expert’s Warning: More Distributed Denial of Service ‘DDoS’ attacks Coming At You

Brace yourself: more distributed denial of service (DDoS) attacks are coming at financial institutions, predicted Scott Hammack, CEO of Hollywood, Fla.-based Prolexic Technologies, a leader in helping big business defend itself against DDoS. “Absolutely, we will see more attacks on banks,” said Hammack in an interview. He traced the current wave of attacks – which have crippled the websites of money center banks including Bank of America and JP Morgan Chase – to probes that began in January. “The attackers did several months of reconnaissance, probing websites for vulnerabilities,” said Hammack. The core DDoS method is to overwhelm a website with a flood of extraneous data. There is so much data coming in that legitimate requests simply cannot be handled. The current attackers, Hammack suggested, come at this with enormous skill, sophistication and funding. He indicated he had no guess about the possible end game or what the objectives of the attackers might be beyond highlighting the vulnerabilities of big banks to attacks. He indicated that the attackers – or people close to them – have frequently posted notices of what institutions they have taken down on Pastebin, a website believed to be frequented by members of the hacker and cyber-criminal community. According to Hammack, the attackers have used the itsoknoproblembro DDoS tool kit and they have come to the battle with deep knowledge of the classic anti DDoS mitigation schemes. Since they know how financial institutions protect themselves at first sight of DDoS, they also know how to maneuver around those protections, said Hammack. Hammack warned: “This is sophisticated in the way Stuxnet was.” Stuxnet’s authorship is unknown, but some have said it was approved by the White House and involved high level cyber security experts from the U.S. and Israel. It specifically targeted Iran’s nuclear program. So far, no credit unions are known to have been targeted in the present wave of DDoS attacks. However, Hammack indicated that in his opinion only the very largest banks are currently prepared to deal with this attack. “A lot of smaller financial institutions have no protection,” he said. “If they get hit they will be out for days.” Source: http://www.cutimes.com/2012/10/01/experts-warning-more-denial-of-service-attacks-com?ref=hp

Link:
Expert’s Warning: More Distributed Denial of Service ‘DDoS’ attacks Coming At You

Protection against DDoS and targeted attacks

Corero Network Security announced its First Line of Defense solution, which blocks L3-L7 DDoS and advanced targeted server attacks. Cyber criminals/terrorists have reached a level of complexity tha…

See the original post:
Protection against DDoS and targeted attacks