DDoS makes a phishing e-mail look real

Attack_of_the_bots
Just as Internet users learn that clicking on a link in an e-mail purporting to come from their bank is a bad idea, phishers seem to be developing a new tactic — launch a DDoS attack on the Web site of the company whose customers they are targeting and then send e-mails "explaining" the outage and offering an "alternative" URL.

Imagine this scenario: You try to log onto your online bank but find the site isn’t working. So you figure, oh well, I will pay the bills later. Let me check my e-mail.

As you wade through the spam in your inbox trying to find some genuine messages, you notice a new e-mail that seems to have been sent by your bank. Normally, you delete these without even reading them because they are obviously from phishers.

However, in this case, the subject line is: "YourBank: Un-planned online banking outage".

The body of the e-mail, which contains logos from the bank and is not littered with spelling errors and grammatical mistakes, goes something like this:

The online banking system is currently experiencing problems and will be unavailable for at least a few days.
Until we can restore our systems, we request that you connect to our alternate Web site which will act as a backup.
Bookmarks and direct access will not work to our main site and we apologise for any inconvenience caused.
Click here to access the temporary site.

Would you be tempted? Do you know anyone that may be fooled?

I sure do.

But is this threat real?

UK bans denial of service attacks

OldbaileyA law was passed yesterday that makes it an offence to launch a denial of service attack in the UK, punishable by up to ten years in prison.

There had been concern that Britain’s Computer Misuse Act, written in the days before the World Wide Web, allowed denial of service attacks to fall through a loophole. These are attacks in which a web or email server is deliberately flooded with information to the point of collapse.

The 1990 legislation described an offence of doing anything with criminal intent "which causes an unauthorised modification of the contents of any computer"; the question was whether that covered denial of service attacks. When a court cleared teenager David Lennon in November 2005 on charges of sending five million emails to his former employer – because the judge decided that no offence had been committed under the Act – the need for amendment seemed obvious.

Lennon’s lawyer had successfully argued that the purpose of the company’s server was to receive emails, and therefore the company had consented to the receipt of emails and their consequent modifications in data. District Judge Kenneth Grant concluded that sending emails is an authorised act and that Lennon had no case to answer, so no trial took place. That ruling was overturned and Lennon was sentenced to two months’ curfew with an electronic tag. But by that time, amendments to the 1990 legislation were already included in the Police and Justice bill.

It was passed yesterday, becoming the Police And Justice Act 2006. The Act also increased the penalty for unauthorised access to computer material from a maximum of six months’ imprisonment to two years.

The 2006 Act expands the 1990 Act’s provisions on unauthorised modification of computer material to criminalise someone who does an unauthorised act in relation to a computer with "the requisite intent" and "the requisite knowledge."

The requisite intent is an intent to do the act in question and by so doing:

    * to impair the operation of any computer,
    * to prevent or hinder access to any program or data held in any computer, or
    * to impair the operation of any program or data held in any computer.

The intent need not be directed at any particular computer or any particular program or data.

The wording is wide enough that paying someone else to launch an attack will still be a crime, with a maximum penalty of 10 years in prison. Supplying the software tools to launch an attack or offering access to a botnet could be punished with up to two years in prison.

Layered Technologies Partners with netZentry to Offer Hosting Customers Complete DDoS Protection

Netzentry
netZentry, a leading developer of advanced network security and Distributed Denial of Service (DDoS) attack detection and mitigation solutions, is partnering with Layered Technologies (http://www.layeredtech.com), a premier provider of dedicated servers, to offer hosting customers this extra protection from external network attacks.

"Customers electing to add netZentry received more control and extra security on a targeted individual server basis from denial of service attacks," said Todd Abrams, President of Layered Technologies (LT). "Layered Technologies decided to provide netZentry’s DDos offering after viewing the additional protection power customers could utilize. We urge LT customers to exploit this valuable extra defense."

netZentry’s DDoS protection software, CleanTraffic, is the cornerstone of Netzentry’s Partner Program. CleanTraffic carefully tracks each DDoS attack at every stage of the attack and an automated email report is immediately sent to the customer being affected. Email notifications consist of a visual report that documents:

• Attack detection
• Attack mitigation
• Specific mitigation actions taken

CleanTraffic allows service providers and enterprises to defend tens of thousands of their clients and servers against threats in a customized manner, at a low total cost of ownership.

"Targeted attacks are becoming increasingly common," said Rangaswamy Vasudevan, CEO of netZentry. "netZentry’s CleanTraffic is the only solution that offers fine-grain protection to
maintain accessibility of individual services even when under attack. We are pleased to partner with Layered Technologies to extend this value-add service to their customers."

U.K. company brings anti-DDoS appliances to the U.S.

Picture_2_1
Webscreen Technology is relaunching its denial-of-service mitigation appliances in the United States after 18 months of concentrating its efforts abroad.                                                 
The company was founded in the United States in 2001 and was bought by a group of U.K. investors in 2005. With its return to the United States it is announcing Webscreen 3.0, an upgrade to its flagship product that adds bandwidth optimization tools.

Webscreen appliances sit outside corporate firewalls and protect Web sites from distributed DoS attacks by evaluating what traffic can be trusted and what traffic can’t. It constantly ranks traffic from trusted to untrusted so the most suspect traffic is dropped first during attacks.

The devices are typically installed in learning mode for a week to determine normal traffic patterns before they are switched on in defense mode. Inspection is performed based on an algorithm, and the device uses no pattern matching to determine suspicious traffic.

The device begins to block traffic only when attacks are severe enough to degrade performance of a Web server, the company says.

Version 3.0 enables reserving bandwidth for key applications and users even in the midst of an attack. This can reserve capacity for essential business tasks and reduce the need for adding bandwidth to Internet links to overcome the volume of unnecessary traffic.

The software maps where attacks are coming from and distributes this data among all the Webscreen devices protecting the various Internet access points in a network. This helps ward off attacks if they shift from one site to another.      

Webscreen Partners with Crossbeam

Picture_1_7
Webscreen Technology Ltd
, the UK
based network integrity solutions vendor has today announced a strategic
technology partnership with Crossbeam Systems®, Inc ., the leader in
unified threat management (UTM) for the world’s largest networks ,
strengthening Webscreen’s claim to be the world leader in DDoS defence
system technology.

Webscreen’s technology has been developed to provide maximum
protection against the full gamut of threats designed to bring down
Internet connected servers and disrupt critical services, particularly a
problem for Web-based enterprises and public service organisations who
need to maintain 24/7 access for their users. Using an anomaly based,
heuristic, algorithm Webscreen’s WS Series of network appliances monitor
all incoming traffic for signs of malicious attempts to flood the
system’s resources, blocking any suspicious activity at the network
perimeter and permitting legitimate traffic to pass through.

Customers choosing to run Webscreen’s intelligent screening
technology can now take advantage of Crossbeam’s highly-flexible UTM
platforms offering best-of-breed security applications, including
firewall, VPN, intrusion prevention and content filtering from the
world’s leading vendors. Crossbeam’s unique UTM platform enables
companies of all sizes to consolidate their security infrastructures
without compromising security policies, while also generating
significant cost benefits for the organization.

Established in the US in 2001 Webscreen Technologies was acquired by
a privately funded, UK team of security professionals in October 2005
and is now providing protection for some of the most high profile
ebusiness websites in the world including ISPs, ASPs and system
integrators where service availability is a key requirement. The ISP
community in particular is growing rapidly, and Webscreen is proving its
worth not only to protect the Data Centre infrastructure, but also to
differentiate the ISP service proposition. Today, Webscreen protects
over 5 million websites worldwide and across many vertical market
sectors.

Robin Hill, Webscreen’s VP of Sales commented "This agreement is
highly important to our overall growth plans for Webscreen and
represents both an excellent endorsement for the technology itself and
also a major opportunity for us to extend our global reach through
Crossbeam’s worldwide network of partners. Crossbeam is a highly
respected company whose innovative approach is recognised by all leading
industry watchers as the way forward for corporate security deployments.
We are delighted to be included in the company’s portfolio of leading
security technologies."

Crossbeam Systems is the leader in unified threat management (UTM)
for the world’s largest networks, and has redefined UTM by offering
traditional and cutting-edge applications that meet the specific needs
of any enterprise or service provider.

"The market demand for UTM is clearly evident as more and more
companies are looking for simplified security architecture to protect
the integrity of their public networks. The addition of Webscreen to the
Crossbeam platform further enhances our UTM offering and enables
companies to rapidly deploy the right defence in depth solution for any
part of the network," said Joel Silberman, vice president of ISV
partnerships and business development at Crossbeam Systems. "In
addition to traditional UTM applications such as anti-virus and
intrusion detection/prevention systems, we can now offer end-users the
assurance of uninterrupted access to their critical resources under the
most severe external DDoS attack."

Up to One Million Zombies

Picture_2
Messagelabs are reporting that cyber criminals are assembling a million zombies into one of the largest bot-nets ever. This article speculates that the purpose will be to launch phishing attacks against consumers who are ready to shop this holiday season. Other possibilities are spreading malware or launching massive DDoS (Distributed Denial of Service) attacks. One million bots is overkill for DDoS so the phishing attacks are more likely.

Or maybe in the spirit of fall harvest (here in the Northern Hemisphere) a group of pharmers are gathering in their herds ready to distribute them to the highest bidder in chunks of 20,000 or so. Either way, prepare for more attacks, more profits for cyber criminals, and more innovation as this year’s crop cyber attacks matures.

Claranet offers DDoS Protection

Picture_1_6
Claranet, one of Europe’s largest Managed Services Provider (MSP) has announced a partnership with Prolexic Technologies to provide its clients with the highest level of protection against Distributed Denial of Service (DDoS) attacks.

Gaming and payment solution providers have typically been prime targets for web attacks.

Claranet is adding to its existing DDoS mitigation with Prolexic’s Clean Pipe solution. The solution responds in real time to DDoS attacks, impeding them at multiple layers and enabling legitimate traffic to continue to reach its destination.

Other DDoS mitigation solutions – in particular hardware devices – are unable to withstand the rapidly increasing magnitude of today’s attacks.

Marino Zini, Claranet Director of Managed Services said, ‘DDoS is an escalating problem and we have a responsibility to provide our customers with clean, consistent bandwidth.’

Gus Cunningham, UK MD, Prolexic said, ‘With online gaming businesses at particular risk and the increasing ferocity of attacks we have been seeing, it is essential that ISPs look at a dynamic solution that can cope with large and persistent attacks.’

Canadian academic talks on cyber extortion

Staffphotosmcmullan
Perhaps it’s because people involved in the Internet gambling sector tend to be well briefed on the Distributed Denial of Services brand of cyber extortion, but a CBC report this week on a talk on the subject really contained nothing new or exciting.

Addressing the Nova Scotia Responsible Gambling Conference in Halifax, university criminologist researcher John McMullan said that his new research into cyber crime, conducted over the past five years, suggests the global, $10-billion-a-year online gambling industry is regularly held for ransom by sophisticated hackers and organised criminals.

McMullan shared the well known information that online gambling sites have been targeted for "digital shakedowns" at peak times, such as the approach of the Super Bowl and other major sporting events.

He goes on to describe the equally well known DDOS modus operandi of deploying zombie PC armies to swamp victim sites with unwanted electronic messages and virtually shut them down, followed by demands for cash – typically in the range $40-60 000 to cease the disruption.

McMullan told conference delegates that the hackers often have a business hierarchy, running organisations that are global and invisible, with the masterminds recruiting people, often via e-mail, to carry out the crime, never meeting in person.

"They recruited different people, like hackers and worm writers, and crackers. There were people who were involved in picking up the money, bankers who were able to move the money around," said McMullan, who is a criminologist at St Mary’s University in Halifax.

McMullan said there have been a number of arrests [more well reported information] in Latvia, Russia and Eastern Europe. In recent years, online betting websites have beefed up security, but McMullan said the criminals are getting smarter, too.

"For every ability to develop a better security architecture, you can be sure the hackers and cyber extortionists are out there scanning your security, trying to find out how to defeat it."

He said these modern criminal groups use the anonymity of the internet, as well as different bank accounts and shell companies, to skim the profits from online gambling.

Florida man charged in botnet attack on Akamai

Picture_1_5
A federal court in Boston on Tuesday heard charges that 32-year-old John Bombard of Seminole used a variant of the Gaobot e-mail worm to turn computers–including systems at two universities whose names have not been disclosed–into an arsenal of "zombies" or "bots" that he could control remotely.

He then used this network of hijacked computers, known as a "botnet," to send a massive amount of traffic to the domain name system (DNS) servers of the Global Traffic Management division of Akamai, prosecutors alleged. Cambridge, Mass.-based Akamai provides caching services for Web sites belonging to big-name companies like Yahoo, Google, Microsoft and Apple Computers, among others.

This distributed denial-of-service attack, launched June 15, 2004, rendered many of Akamai’s clients’ Web sites temporarily inaccessible, according to the charges.

The charges of hacking, or "intentionally accessing a protected computer without authorization," carry potential penalties of up to two years’ imprisonment and a $200,000 fine.

The case comes as botnet controllers are using increasingly sophisticated tactics. Major arrests were made over the summer, but attackers have kept up by writing new worms to maintain their zombie armies. In the meantime, Web browser manufacturers are striving to introduce more secure upgrades, like Microsoft Internet Explorer 7.

National Australian Bank hit by DDoS Attack

Picture_1_4
The attack, which was first detected at 6am, saw the blocking of access
to the NAB’s site and slow log-ons for the bank’s internet banking
customers occured intermittently throughout the day, NAB spokesperson
Megan Lane said.

Thus
far, the NAB was not aware of the source or motivation of the attack,
Lane said, but the event had been referred to the Australian High Tech
Crime Centre (AHTCC) – a section of the Australian Federal Police.

The
incident was not the first time the NAB had been targeted by a DoS
attack, she said, but this instance was one of the “more significant”
efforts to block access to the company’s website.

AFP spokesperson Nicholas Pedley confirmed that a referral from the NAB
had been received and said the AFP was investigating this matter.

“The
AFP takes any activity of this nature seriously and is working closely
with the NAB to resolve the matter as quickly as possible,” he said.

In announcing the DoS attack, the NAB has renewed its campaign warning of the dangers of hoax emails, Lane said.

However,
the bank was uncertain as to whether the DoS attack was being used as a
pretext to soften up customers for a phishing attack through creating
the expectation of special emails from the bank explaining the
interruptions to the website.

“We just think it’s timely to remind customers that we will never ask them for their details,” she said.