Showing posts with label DDOS Attack. Show all posts
Showing posts with label DDOS Attack. Show all posts

Tuesday, 10 November 2015

ProtonMail Collects $ 50,000 Against DDoS attacks


The encrypted e-mail service ProtonMail that make the past few days with DDoS attacks received is now back online and has raised $ 50,000 to protect themselves against such attacks. Because of the attacks users could not in their email.

Last Sunday, after three days of hard work, ProtonMail claimed victory over the attackers. Which had the free encrypted email service extorted. Initially ProtonMail went on to pay the amount requested, some $ 6,000. Despite paying the attacks continued. Because of the attacks decided ProtonMail to deploy additional protection against DDoS attacks.

According to the e-mail service are anti-DDoS solutions very expensive and can cost more than $ 100,000, which is a burden on the budget. Therefore, the public was asked for donations, some in three days, $ 50,000 has produced.

Saturday, 7 November 2015

Encrypted Mail Service ProtonMail Extorted Via DDoS Attack


The free encrypted email service ProtonMail has been the victim of extortion, with the extortionists perform for several days of heavy DDoS attacks against the company's website. That's what the email service via a blog posting disclosed.

Because of the attack, users can not get to their e-mail, although the service yesterday as online was. On November 3 ProtonMail received an email from a group of criminals who had previously companies through DDoS attacks have extorted. The group now focuses on Swiss hosting providers. The threat was followed by a DDoS attack that the service went offline for about fifteen minutes. Approximately 11 hours later, a new DDoS attack. Initially which only focused on ProtonMail, but spread to the Swiss data center where the servers are.

This also went to the websites of different tech companies and banks offline. The attack eventually went over 100Gbps over.It did not just attacked more the data center from the Internet ProtonMail, but also routers in Zurich, Frankfurt and other locations where the ISP nodes has listed. Then the email service decided to pay the extortionists, but despite the transfer of 15 bitcoin (5100 euros), the attacks continued. According to ProtonMail is now working with several providers to repel the attack, but were unprecedented in both size and scope.

This morning ISP was attacked so that the e-mail service offline went. "Finding a working solution is therefore not simply" know ProtonMail so late. Due to the nature of the attack should be fairly pricey solutions are enabled which are a burden on the finances of the company. Therefore it was decided a donation campaign to start. A total of 326 people so far donated approximately $ 11,000.

Friday, 6 November 2015

Encrypted Mail ProtonMail Service Back Online After DDoS Attack


Users of the free encrypted email service ProtonMail can back to their e-mail after the service became inaccessible due to multiple DDoS attacks. The attacks were only directed at first ProtonMail, but spread out to the Swiss data center where the servers are.

This also went to the websites of different tech companies and banks offline. "Despite our efforts do not manage to stop the attack, but we are trying to come back online," as ProtonMail said earlier in a blog posting know. This morning followed another attack. A few hours before the early e-mail service via Twitter to a data center in Switzerland "brave enough" to host servers ProtonMail.

Many providers would be afraid because of the scale of the DDoS attacks that will make the service. Despite the request and the recent attacks to the website of ProtonMail is now accessible again. The email service has been developed with the help of scientists from Harvard, the Massachusetts Institute of Technology and the European research lab CERN.

Sunday, 1 November 2015

Less Than 1.2 Million Customer Data Stolen By Talk Talk


When the attack on the British provider TalkTalk took place last week and which two teenagers were arrested, less than 1.2 million customer data stolen, so the affected company has announced. At first it was unclear whether the attackers had managed to access data.

That is still the case, according to a statement from the provider's own website. The specific number of affected customers is not given, except that it is "less" than 1.2 million e-mail addresses, names and phone numbers. Less than 28,000 credit and debit card data of which the middle six figures were removed. Less than 21,000 unique bank accounts and codes, and fewer than 15,000 birth dates. TalkTalk will now inform all affected customers.

The stolen credit and debit card details can not be used for financial transactions, according to the provider. However, as a precaution decided to share bank data of the subscribers affected by the major UK banks to allow them to take extra measures. Subscribers are also advised to get a year's free to leave monitor their credit. In addition TalkTalk advises subscribers to be alert. "Although the scale of the attack is much smaller than initially believed, we advise you to be alert and to take all precautions to protect yourself from fraudulent calls and e-mails."

Thursday, 29 October 2015

MySQL Servers Used For DDoS Attacks


A group of criminals infects MySQL servers with malware and then let them carry out DDoS attacks. It reports the American security company Symantec in a blog posting.

To hijack the servers, the attackers use a "user-defined function" (UDF). It is in this case to code that can be invoked from within MySQL to provide features which can not offer the database management system. Its use to access MySQL servers is not new and was already discussed in 2005. In this case, the attackers use a UDF to install Chikdos malware on the server. This malware, in late 2013 already in the news.

At the latest campaign attackers Symantec may use an automated scanner or a worm to compromise the MySQL servers and install a UDF. However, the exact method of infection has not been identified. Once the servers are infected, they download a DDoS tool for executing DDoS attacks on websites.

To get around this kind of attack, administrators advised not to run with administrative rights to the SQL server. The SQL server must be patched regularly, and must be safe programming SQL Injection can be prevented. Furthermore, administrators can check for the presence of new user accounts and ensure that remote management is configured securely.

Downloader.Chikdos hashes

Sunday, 25 October 2015

Botnet Security Cameras Used For DDoS Attack


It is not just routers and computers that need to be secured, because researchers have identified a botnet of hacked about 900 security cameras discovered that was used to carry out DDoS attacks on a cloud service. This was reported by security firm Imperva.


The cameras are located in various countries, but were concentrated primarily in India. Investigators found the cameras malware that searches for certain devices via Telnet and SSH. This relates to devices on BusyBox run a Linux distribution for embedded systems, and are vulnerable to brute force attacks. In this case it appeared that all hacked cameras were accessible via the default login password. The researchers therefore call on administrators to always change default passwords, whether it's a router, access point or security.

Friday, 23 October 2015

Customer Data British ISP TalkTalk Possible Stolen


UK ISP TalkTalk customers have been warned that their data as possible in an attack on the ISP's network is stolen. In a statement, the UK providers it on October 21 a "major and sustained cyber attack" took place on the website.

A day later the Metropolitan Police Cyber ​​Crime Unit decided to launch an investigation. Although the investigation is TalkTalk suggests that the attackers may have accessed customer data. It would be names, addresses, birth dates, email addresses, phone numbers, TalkTalk account information and credit card and / or bank details. Sources have opposite the BBC that there was a DDoS attack. This data is not captured, but it happens that DDoS attacks are used as a distraction while attackers break into the network.

TalkTalk would become "all necessary measures" have been taken to secure the site, but details are not given.Furthermore, the provider has informed all major banks, so they can keep in suspicious activities in the accounts of TalkTalk customers watched. TalkTalk would in Britain have more than 4 million subscribers. The shares of the provider fell at the opening of the stock market by 11%, as reported the British newspaper City AM

Vulnerabilities In Network Time Protocol (NTP) DoS Permit



In the Network Time Protocol (NTP) Multiple vulnerabilities have been identified that could allow attackers to systems that make use of NTP can cause a Denial of Service (DoS). NTP is a protocol that allows systems to synchronize the time for different services and applications.

It is present in network devices and embedded devices', as well as desktop and server operating systems, including Mac OS X, various Linux distributions and BSD-based systems. Decided last year to start the Linux Foundation on the occasion of the Heart Bleed vulnerability Core Infrastructure Initiative (CII) with the aim of securing popular open source projects on the Internet. Cisco is part of the CII and focuses on researching NTP.

Researchers at Cisco have a total of eight vulnerabilities discovered in NTP, which in ntp-4.2.8p4 been resolved. Also five other leaks are history. In addition to a Denial of Service are also bug fixes are causing memory corruption or path traversal were possible. The only vulnerability that is too general, according to the developers of NTP abuse is concerned a bug allowing attackers with NTP servers for DDoS attacks can deploy. In August, warned the FBI for DDoS attacks that uses the Network Time Protocol.

Monday, 17 August 2015

BitTorrent Clients Can Strengthen DoS Attacks



Several BitTorrent clients and BitTorrent Sync application to abuse for performing DRDoS attacks, warns researcher Florian Adamsky from City University London. Reflective DRDoS stands for Distributed Denial of Service.

In a traditional DDoS attack (Distributed Denial of Service) attackers have lots of infected computers or servers attacks a website. In the case of a DRDoS-attack is sent to a "reflector" movement, which then forwards it to the final target. DRDoS attacks are especially effective if they send more traffic to the target than they have received from the attacker.

BitTorrent

BitTorrent-Adamsky discovered that different protocols can be used to reinforce this way Denial of Service attacks. The problem is present in the UTP, DHT, Message Stream Encryption- and BitTorrent Sync protocols. Especially via BitTorrent Sync attack can be effective, since the attack traffic by a factor of 20 can be strengthened. In the case of popular torrent clients such as uTorrent and Vuze can increase attacks fold, respectively 39 and 54.

An additional problem is that detect attacks via BitTorrent are difficult due to the dynamic port ranges and encrypted handshake used by the clients. Across TorrentFreak Adamsky reports that the attack is simple to implement. An attacker only needs to have a valid info-hash or in the case of BitTorrent Sync on the "secret". BitTorrent has been informed and has in a recent beta version patched the issue. UTorrent however still vulnerable and Vuze has yet to roll out an update.

Wednesday, 5 August 2015

Trojan Horse Hijacks Linux Routers Via Shellshock Leak



Worldwide, nearly 1500 Linux routers hijacked by a Trojan, that the devices then switch to attack other systems and servers. The PNScan Trojan, as malware by the Russian Doctor Web is called, uses the Shellshock leak last September before taking on Linux routers with ARM, MIPS- or PowerPC architecture.

In addition, the Trojan also installs other malware on hacked routers already present. Shell Shock is the name for a vulnerability in Bash. This is a Unix shell commands with which it can be given to the system. It is used for many applications and many programs running in the background. Last September, the vulnerability was found and patched, but still there are vulnerable systems on the Internet.

If PNScan the router is installed on the Shellshock leak, there is other malware installed on the device. The malware then perform a scan on a range of IP addresses. After this, the malware can perform different attacks. Also, the malware that is installed in addition to the router is able to carry out attacks. It is in this case to DDoS attacks and attempts to take over phpMyAdmin installations.

Besides PNScan there has also been discovered a variant of the Trojan horse. This version does not use the Shellshock leak, but uses weak passwords to gain access via SSH. Worldwide in 1439 were found infected with PNScan routers.

Saturday, 25 July 2015

FBI Warns Businesses For Extortion Through DDoS Attacks



The FBI has warned businesses through extortion DDoS attacks on their websites, as these attacks take place more often. The past few months have also several security companies to this form of extortion warned .

The attacks are carried out by a group that DD4BC (DDoS for Bitcoin) names and since last July is active. The FBI warning that Public Intelligence published ( PDF ), the group is not mentioned, but the method does is mentioned is identical. There is first a DDoS attack on the website of the company which usually takes place about an hour and has a size of 20 to 40 Gbps.You then send an e-mail with the demands of the attackers. That require an amount to be paid in bitcoin.

If the victim does not meet the requirements there will be a powerful DDoS attack within 24 hours, which lasts an hour and again has a size of 40 to 50 Gbps. This attack is succeeded by a warning. According to the FBI know most attacked companies to turn down the DDoS attacks by enabling the anti-DDoS services from third parties instead of paying the ransom. Where the attackers had first mainly on gambling sites provide, since April this year, other sectors targeted and larger amounts are required.

Red Hat Patches Leak That Gave Local Users Root Privileges


Red Hat has released security updates for two vulnerabilities allowing a local user to the file / etc / passwd could adapt and root privileges could get. The vulnerabilities are in the libuser library, which is standard on all Red Hat-derived Linux distributions is present.

During an internal investigation discovered security company Qualys different libuser-related vulnerabilities. The first vulnerability is present in the "user helper" and a local user allows to edit the file / etc / passwd. This would be possible to cause a local denial of service. Qualys does not exclude that it is possible for a local user to gain root privileges on the system, but to make the company failed an exploit that realizes this. That did succeed with a second leak in libuser itself.This allows a local user to gain root privileges.

Red Hat released yesterday updates to the vulnerabilities of, after being informed in advance. However, there is a commotion about the publication of Qualys. The company would information about the vulnerabilities, including exploits, published before the Red Hat updates to users could be deployed. Something for discussion on the oss-sec mailing list and Reddit made.

Tuesday, 14 July 2015

Teen Gets Community Service Because Of DDoS Attack On Spamhaus



A British teenager in Britain was sentenced to community service of 240 hours for his role in a major DDoS attack on anti-spam organization Spamhaus in 2013. At the peak was 300Gbps there to traffic sent to the website, which collapsed as a result, reports the BBC .

The teen would have offered as "mercenary" to get websites fee from the air. The attack against Spamhaus would possibly other parties were involved. After his arrest, was found a sum of 101,000 euros in his bank account. On his computer, investigators found the source code of the software that the attack was carried out. According to the judge there would be no likelihood of recurrence and the teenager really regret his actions. He therefore decided not to impose imprisonment.Spamhaus may know agrees with the judge's ruling, CIO Richard Cox so late.

Wednesday, 17 June 2015

Banks worldwide extorted through DDoS attacks


A group of cyber criminals who extorted in the past, online casinos and gambling sites via DDoS attacks now focuses on leading banks, trading platforms and other financial institutions. Before warns security firm Arbor Networks. The group calls itself DD4BC criminals (DDoS for Bitcoin), and since last July active . In recent months, both the number and the scale of the attacks increased.

The company's website is first attacked shortly, so the group can determine the effectiveness of the DDoS attack. If it is successful there will be a mail in which a certain amount is required. Is not paid, then there is a severe and prolonged DDoS attack. In a warning to customers Arbor Networks describes 37 attacks / campaigns that carried the group. The actual number of victims is higher, because not all victims of the attacks on their website made ​​public, especially if they paid the amount requested.

The amount varies by asking the attackers attack. Some victims had to pay 100 bitcoin, what with the current exchange rate with 21,000 euro contract. Still, Arbor Networks advises companies not to pay the ransom. This will encourage criminals merely had to return to extort more money to continue their attacks. The group denies this and claims that the company only targets at once. Meanwhile there is also a reward of 110 bitcoin (23,000 euros) offered for information that the group can be unmasked.

Wednesday, 3 June 2015

Researchers: VPN Service Hola Big Security Risk



The free VPN service Hola appears not to be used for DDoS attacks, malware also communicated over the network. In addition, the software is such a big security risk that users can better remove VPN service, say researchers at security company Vectra.

Last week Hola came into the news because it resold the bandwidth of users to other parties. Someone who knew the company did then the bandwidth to be used for a DDoS attack. Also, researchers discovered several vulnerabilities, making it possible to track users and to execute arbitrary code on computers. The CEO of Hola promised improvement and suggested that the vulnerabilities were corrected, although researchers contradict this.

Malware

The DDoS attack via the VPN service is no exception, because cyber criminals Hola appear to have been longer in sight.During investigation of the Hola protocol Vectra researchers discovered five malware instances that also use the protocol."Not surprisingly, this means that the bad guys already realized the potential of Hola before the power of public reports published by the good guys", so put them in this analysis .

The investigation revealed further problems upwards. In addition to behave like a botnet contains Hola according to researchers various opportunities that seem to have been a targeted by introducing a human-driven cyber attack on the network from which the computers of the Hola-user stand.

It also appears Hola additional software without knowledge or consent of the user to download and install. This is possible because Hola after installation installs its own certificate on the computer. This additional code can be installed and run without the user would not be informed. "These capabilities allow a skilled attacker to execute almost everything," said the researchers. They also advise users to remove the software.

Samples Hashes:

Tuesday, 2 June 2015

VPN Service Hola Promises Improvement After DDoS Attack


VPN service Hola has promised change after the bandwidth of users were used to carry out a DDoS attack and leaks were discovered in the software, but researchers are not convinced. Hola is an extension for Google Chrome offers users a free VPN connection.

What many people do not know is that the company behind the VPN service sells the users of bandwidth via a service called Luminati. Luminati gives parties that pay access Hola network. Recently knew anyone to use this service for a DDoS attack on the 8Chan website. Hola got them to endure a storm of criticism and the founder of 8Chan advised users to uninstall the software.

In addition, several vulnerabilities were discovered in the software that could allow an attacker to execute arbitrary code in the worst case to the computer. In a statement CEO Ofer Vilenski states that there is "growing pains" and that some allegations in the media are unjustified. However, the company will take various measures.

Bandwidth sharing

The first measure concerns about sharing of bandwidth. Through a P2P network called Hola thought it was clear to users that their bandwidth was used. Something not subsequently turns out to be, according Vilenski. Therefore, it still will be clearer for users to communicate. Furthermore, the CEO that there are not used as much bandwidth users, namely 6MB per day.

This bandwidth should be accessible only to business customers. In the case of DDoS attack that took place last week did a 'spammer' to pretend to be a company and were not noticed by Luminati. To avoid repetition have changed several processes.In addition, a Chief Security Officer will be appointed.

Vulnerabilities

Further Vilenski points to two vulnerabilities that were discovered and now would be patched. Hola also run some code by a third party and there will be a "bug bounty" program to be launched, in which hackers and researchers who report vulnerabilities are rewarded. Despite the words of the CEO are the researchers who discovered the vulnerabilities unconvinced.

According to them, the problems still exist and Hola has only made ​​cosmetic changes so that their demonstration of the leak has stopped working. "Many of the problems are ignored, and some claims are simply not true", so leave them on the website Adios-Hola.org know.

Saturday, 30 May 2015

VPN Service Hola Used For DDoS Attack On 8Chan


The popular free VPN service Hola has recently been used to carry out a DDoS attack on the 8Chan website. Hola is as an extension for Google Chrome easy to install and use, which besides being free explains the popularity. In order not to pay for the traffic of users makes the VPN service using a P2P system where the traffic of users is through the connection of other users.

What many users do not know is that the company behind the VPN service sells the users of bandwidth via a service called Luminati. Luminati gives people to pay for access to the Hola network, for example, to commercial traffic anonymous routing.In this way Hola remains free to users. Via Luminati However, it is also possible to use the bandwidth of Hola users for DDoS attacks.

On May 24 was Luminati used as botnet to attack the 8Can website, so let investigator Nikoloz Kokhreidze Monday already know. The founder of 8Chan, Fredrick Brennan, then placed a warning on the website that users Hola better not use. "Hola is the most unethical VPN've ever seen," he observes. In a response to Business Insider Hola let know that the party that the DDoS attack conducted could use any VPN service. In addition, it should also be obvious to users how Hola works, but is there because of all the fuss surrounding private details are put on the website.

Thursday, 28 May 2015

Linux Malware Allows Routers On Facebook And Twitter Defraud

Linux / Moose Overview
Researchers have discovered a new form of Linux malware that tries to take over routers subsequently on social networks like Facebook, Twitter, YouTube, Instagram and other sites to commit fraud with. The malware is called Moose ( pdf ) and scans the internet in search of Linux routers with an accessible Telnet service. Once found, will perform a brute force attack to gain Telnet access to the router.

Moose will modify the DNS in the event of a successful attack, steal the unencrypted network traffic to and from the router, perform man-in-the-middle attacks and offer proxy services for the malware creator. In practice, the malware will steal HTTP cookies from the aforementioned social networking sites to perform with fraudulent actions, such as "track", "view" and "like" of users and content on the websites.

In addition, the malware infected routers will also be used to scan for new vulnerable systems. According to researchers from the Slovak anti-virus company ESET malware is remarkable, because most Linux malware going around and it has developed features on routers to perform DDoS attacks. ESET also denounces the security of routers to be desired and allows this type of malware can strike.

"Witness the primitive techniques Moose used to access other devices, it is unfortunate that the security vendors of routers do not take seriously", say the researchers conclude. That also recommend IT experts to check the routers acquaintances on firmware updates and safe settings if they are nearby.

Saturday, 11 April 2015

Group bombarded SSH Servers With 300,000 Passwords



A group of cyber criminals that has been active since June last year conducts large-scale attacks against SSH servers, whereby through more than 300,000 unique passwords attempting to log in. Once access to the server is obtained finally installed a DDoS rootkit.

Through this rootkit can execute the attackers acquired server DDoS attacks. The cyber criminals by Cisco and Level 3 as "SSHPsychos" and "Group 93" indicated. The group would generate as much traffic with the login attempts that all joint attacks on SSH from other parties combined into nothing fall. The attacks appeared from different netblocks (ranges of IP addresses) to arise. In cooperation with backbone provider Level 3 was decided that the group netblocks disabling used.


As part of the process, Level 3 warned the responsible providers, which the group cybercriminals suddenly used a new network for their scans and attacks. Because of this sudden transition decided Cisco and Level 3 to remove the routing options for both the old and new netblock. According to Cisco, this will "hopefully" slow down the activities of the group for a certain time.

The networking giant notes that "detectors and protectors" can no longer sit on the side as cybercriminals in such flagrant attack systems. However, the measures affect only the part of the Internet that is provided by Level 3. Cisco calls than other parties in order to block malicious traffic from this group on the Internet. "By working together, we can eliminate a group that makes no effort to hide their malicious activities," the company said.

Saturday, 4 April 2015

Criminals Steal $ 1 Million Through Malware And Phone Trick



Cyber ​​criminals have managed to steal through a combination of malware and a phone trick more than $ 1 million of companies, says IBM. The attacks on the organizations start with a spear phishing email containing an infected link or attachment. Once the link or attachment is opened the computer becomes the Upatre malware infected. This malware then downloads the Dyre banking Trojan.

This Trojan is designed specifically to steal money from online bank accounts. To bypass the two-factor authentication using more banks cyber criminals use a trick. Once employees log on to the bank site shows the malware on the infected computer a message stating that there are problems with the bank site and a special phone number to be dialed to login.


Once the employee number calling sucked in the login details for online banking and simultaneously used for the transfer of large sums to other accounts. One organization was also due to a DDoS attack, which is likely to serve as a distraction. According to IBM let these attacks show that employees often the weak link in the security and are therefore more in security awareness and training should be invested.