2007 – The Review from the Crystal Ball

This post is from the Heise Security website and it attempts to predict the trends for 2007.

It’s the season of the end-of-the-year reviews. We have used our crystal ball to jump forwards a year to provide you the ultimate review of 2007 — here and now.

2007 was the year of the super bots: Never before has malicious software been equipped with so many functions that help it to hide from antivirus software and to resist removal. The majority of malicious software programs used root kits, and their number doubled again on last years figure to over 500. Local privilege escalation vulnerabilities in Windows were increasingly exploited; accounts with restricted user rights were used to gain system rights. Initially, the protective functions in Windows Vista, which has been available for end customers since January, made it more difficult for malicious code to infiltrate the system. The crimeware scene responded and numerous vulnerabilities appeared as the year progressed and these were exploited to cancel or bypass the majority of the security functions. The user account protection (UAC), in particular, proved to be ineffective: Most users just confirmed any respective requests, since they did not undertand the displayed information.

Continue reading

Richard Stiennon’s Top Ten Threats for 2007

Richard Stiennon has announced his top ten threats for 2007 on his blog at ZDNet. His top ten threats are as follows.

  1. 100% Growth in revenue for cyber crime
  2. DDoS in support of phishing attacks
  3. Successful DDoS attack against a financial services firm
  4. Attacks against DNS are the threat of the year
  5. No abatement in identity theft
  6. More attacks against wireless networks
  7. MySpace grows up and gets secure
  8. YouTube abuse threatens site
  9. Network infrastructure shows signs of overloading
  10. Spread of Windows Vista will have zero impact on the overall threatscape

View the entire contents of the report HERE

DDoS Attacks – Possible Solutions

Attack Of The Bots

One of the biggest ongoing challenges in networking continues to be the struggle against distributed denial of service (DDoS) attacks. Unlike the similarly-named denial of service (DoS) attack, which is easily controlled by filtering all packets from a particular source IP address, a distributed DOS attack usually includes traffic generated by large numbers of host computers. These hosts may be in multiple geographic regions, and often are served by multiple ISPs.

The intent of these attacks is the same—to overwhelm Internet sites with so many packets that they lose connectivity, disrupting operations and potentially causing large financial losses. Sites under attack may find all their bandwidth consumed, or simply that their firewalls or servers cannot withstand so much traffic. Occasionally attackers will find an actual weakness or vulnerability in the site, but this is not necessary for a DDoS attack to succeed. Every organization with a public Internet site is a potential DDoS victim.

Reasons behind DDoS attacks may include extortion, market competition, political sabotage or even cyber terrorism. The mechanism is usually the same—most attackers use botnets.

Botnets are collections of autonomous software robots or “bots,” running on multiple infected computers (sometimes called “zombies”) without the knowledge or consent of those systems’ owners. Located mostly in Windows PCs, bots wait in hiding until a hacker secretly signals them. Hackers often use Internet relay chat as a way to command botnets, remotely telling them to generate spam, attack a website or infect other computers (and thus add to the size of the botnet and its value to the hacker who controls it).

More than a million bots are estimated to exist on the public Internet, and some botnets consist of more than 20,000 infected PCs. When a botnet of that size targets a single website, even the largest sites with huge servers and prodigious bandwidth may not be able to withstand the attack. According to the Computer Security Institute, corporations such as Amazon, Microsoft, Yahoo, CNN and eBay have been victims of DDoS attacks. And DDoS attacks can be launched against more than just host computers or Web servers—they have been directed at DNS servers, email systems and network routers.

Read More..

Cafepress.com Gets Hit By DDoS Attack!

CafePress

CafePress.com, which provides online stores for thousands of blogs and web sites, has been hit with a distributed denial of service attack (DDoS) which has disrupted service for many of its merchants during the critical final shopping days before Christmas.

The attack began Tuesday evening and was continuing to cause “significant service interruptions” late Thursday. The cafepress.com main site and a sampling of online stores were accessible early Friday.

EveryDNS Suffers DDoS Attack

Attack_of_the_bots_1"EveryDNS, sister company to OpenDNS (which runs the PhishTank anti-phishing initiative), has been hit by a massive distributed denial-of-service attack. The attack started sometime Friday afternoon and, from all indications, was targeting Web sites that used free DNS management services provided by EveryDNS. At the height of the DDoS bombardment, EveryDNS was being hit with more than 400mbps of traffic at each of its four locations around the world. From the article: ‘"We were collateral damage," Ulevitch explained… Because law enforcement is involved, Ulevitch was hesitant to release details of the actual target but there are signs that some of the targets were "nefarious domains" that have since been terminated.’"

OpenDNS, which makes use of EveryDNS services, was affected for a time, until they spread their authoritative DNS more broadly. The EveryDNS site is now reporting that the attack is continuing but has been mitigated and is not affecting operations.

IntruGuard go to Europe

Planeetta_logo
After reviewing their current signature based
Intrusion Prevention System (IPS) and evaluating several other IPS
solutions available on the market, Planeetta selected the IG200 to
protect its customer maintained servers and network operation center
(NOC) from a growing threat of DDoS attacks, protocol anomaly based
hacking, scans and other zero-day exploits. Such network floods were
occurring on a monthly basis and with only a narrow based DDoS attack
on just one customer; connectivity to other accounts was hampered. The
existing IPS device was overtaken with flood traffic and failed. Prior
to the IntruGuard deployment, Planeetta took a painstaking effort with
their Internet Service Provider to determine all sources of attack and
instituted ACLs to block the assault. This method took many hours to
bring the attack under control.

Lauri Pitkanen, Chief Security Officer and Co-founder at Planeetta
explained, ”Compared to other solutions available on the market, the
IG200 was the clear choice because of its split-second automated
response, full duplex Fast Ethernet throughput, software upgrade
capability to gigabit throughput, and ease of administration and
monitoring. The ability to create virtual protection zones using the
Virtual Identifier (VID) feature in the IG200 was extremely powerful
and allowed us to separate our operations center from customer servers.
We use the IG200 to block denial of service network floods targeting an
individual customer where such an attack affects all customers. Since
its installation, the IG200 has successfully thwarted several attacks
and helped us trace the source of each.”

Ashok Jain, CEO of IntruGuard Devices, Inc. commented, ”Web Hosting
has to go on un-interrupted. Companies like Planeetta, that understand
the value of their customers’ trust, are quickly realizing the IG
product family can help them keep their wide-ranging services on-line
at all times and maintain mandatory service level agreements.”

Planeetta Internet Oy is a provider of web hosting services in Europe,
serving over 5000 customers with an excess of 50 servers in its data
center. Thorough security services include protection against worms,
viruses, spyware, and other malicious attacks to protect their
operations. Services include web site and email support. The company is
located in Helsinki, Finland.

IntruGuard’s mission is to secure high-value Internet services and
network infrastructure by delivering built-for-purpose systems for
Intrusion and Day Zero DoS and DDoS Attack Prevention. The company
serves e-commerce, web hosting/ISP, financial institutions, and managed
service providers that are under pressure to deliver guaranteed network
and application performance under all conditions. IntruGuard’s IG200,
IG2000, and IG2200 DDoS Firewall security appliances will defeat any
intruder attempting to mount a rate-based attack on servers, subnets or
networks. These appliances deliver maximum performance, intelligence,
and ease of deployment. The company is headquartered in Sunnyvale, CA.

To learn more about IntruGuard, please visit: www.intruguarddevices.com.

For more information about Planeetta Internet Oy, please visit: www.planeetta.net/.

Amazon.com DDoS’ed by Customers Vote Winner

Amazonlogo
In case you were hoping to take advantage of the Amazon Customers Vote deal for a $100 Xbox 360 on Thanksgiving, Amazon.com was reportedly not reachable from least 2-2:15pm EST (11am-11:15am PST). Presumably, the traffic caused by the $100 Xbox seekers was simply too much.

Some people are complaining that they couldn’t even load the Amazon homepage…

Update: There are over 500 comments in a thread on the Amazon Customers Vote Forum with disgruntled customers chiming in, in addition to other blogs which have noted the outage. Plenty of people are not happy and some are filing Better Business Bureau complaints.

Looks like a great case of a traffic flood that caused DDoS like behavior.

Websites struggling for legal recourse for DoS attacks

Pcprologo
Websites blocked by ISPs when under a distributed denial of service attack (DDoS) face millions of pounds in lost business because ISPs refuse to take responsibility for hosting infected computers on their networks.

Typically, a distributed denial of service attack relies on an attacker remotely controlling numerous and widely distributed computers infected by viruses and Trojans. The attacker uses these ‘botnets’ to send a flood of requests to a website, which is often unable to cope and its servers fail, taking the website offline.

It’s a relatively simple and cheap operation for the attacker. Keith Laslop, President of DDOS mitigation outfit Prolexic told us: ‘I’ve seen them on forums where you can hire bots for next to nothing. Four cents a bot. So you could take down a site very cheaply. You could get enough together for, say, a 50Mbits DDOS attack. You could take someone out with that.’

DOS attacks are also becoming increasingly common. During the first six months of 2006, Symantec observed an average of 6,110 DoS attacks per day.

More…

PROLEXIC PROTESTS INNOCENCE

Prolexic_logo
Anti-DDoS firm not involved in criminal activity says spokesman

One of the indicted companies in the major Giordano Internet sports betting bust, Prolexic Technologies was quick to protest its innocence following the public announcement of the New York case this week.

Prolexic is a well respected company in the forensic and DDOS field, and it took immediate steps to point out that it was simply an anti-DDOS contractor to the Playwithal site.

In statement that claims it is wrongly accused of criminal activity, the company commented: "Earlier today, New York authorities issued a 33-count indictment regarding an illegal online gambling operation.

"Prolexic Technologies, which provides Distributed Denial of Service (DDoS) solutions, was named in the indictment as the Web host provider to an Internet sportsbook. Prolexic Technologies provides a service that, amongst other things, masks a client’s IP address in order to mitigate DDoS attacks. When a trace route is performed, it appears that Prolexic Technologies is the host server, when in fact that is not the case.

"Our job is to prevent DDoS attacks, which are one of the most costly cybercrimes on the Internet," said Keith Laslop, president of Prolexic Technologies. "Prolexic Technologies in the past has worked closely with U.S. and U.K. law enforcement agencies in regard to tracking DDoS attackers, and was instrumental in the arrest of a high-profile Russian mafia figure that used DDoS to take Web sites hostage until paid a ransom. We have a history of cooperating with law enforcement authorities, and our name will be cleared of any wrong doing. Meanwhile, we are continuing to operate, as the leader in DDoS defense services."