Showing posts with label HTTP. Show all posts
Showing posts with label HTTP. Show all posts

Tuesday, 12 May 2015

Large DDoS Botnet Of Tens Of Thousands Of Routers Discovered


Researchers have discovered a worldwide botnet consisting of tens of thousands of hijacked routers and is used to carry out DDoS attacks on websites. Reported security Incapsula in a new report . Although the hijacked routers were found in 109 different countries, found that a majority (85%) is located in Brazil and Thailand.

The routers are in turn controlled via servers which are in China and the United States. The researchers thought initially that the routers were acquired via a vulnerability in the firmware. Further investigation showed, however, that all devices were accessible through the standard ports HTTP and SSH. Was not changed in almost all cases the default password.

Thus, the attackers were able to install the "MrBlack" malware on the routers. In addition, a script on the hijacked routers installed it looked for other vulnerable routers. To avoid getting users advised to change the default password such attacks, install the latest firmware and ensure that the operator interface is not accessible via HTTP or SSH. Something that through this tool can be controlled.

Wednesday, 9 April 2014

Fake poll as a lure for Facebook Phishing Scam

The Facebook application asks users to register their votes

Cyber criminals have again found a new way to Facebook to trick users into entering their login details. They run a fake online poll for the purpose of luring. Potential victims to a phishing site.

A pop-up window requesting for user account information

Symantec reports that the scammers run an online poll with the question: "Who better boys or girls" Once the visitor has cast his vote will be prompted to log in to the Facebook account and asked whether the visitor is male or female. After logging the victim sees the message that his voice has been sent. Scammers host the site on a subdomain ([http://] Smart Apps. [deleted]. com) to indicate that it is an application and the to appear. matter professionally in this context is the number of voters also raised periodically.

A comparison of the previous vote count and the current vote count

While it does seem that way at first glance Facebook has nothing to do with the campaign. When visitors log in reality they give their login information to the cyber criminals.

The scammers probably realize only too well that many Facebook users, this kind of thing every day without too much thought do. It is not inconceivable that they have already succeeded in many account data store.

Prevent
To a victim of a Facebook scam to be, it is important that you never put your password on domain other than facebook.com enter. The real login page of Facebook is secured with an SSL certificate which can be used by the padlock in the address bar of the browser and the HTTPS recognized connection.

Monday, 31 March 2014

Barracuda launches Threat Glass

Barracuda Networks, the provider associated with the cloud storage solutions and ICT security, introduces Threat Glass, an online tool for searching, analysis and exchange of information on websites with malware. With Threat Glass users can see reviews of the infected websites with screenshots of the stages of infection and analyze network issues.

Daily popular websites cyber criminals exploited to. Malware to visitors loose Threat Glass of Barracuda Networks offers both casual users and the research community the opportunity to bring this persistent problem, identify and understand better. Threat Glass was developed as a front-end to a large-scale automated system that uses lightweight visualization for the independent detection of vulnerabilities and abuse thereof (exploits). The platform analyzes millions of websites every week. The websites that are submitted for inspection from various data feeds, including the top 25,000 websites by Alexa, social feeds and suspicious sites that are detected by the worldwide network of customers Barracuda, which spans more than one hundred fifty thousand organizations. Besides screenshots of the infection Threat Glass offers different views of network traffic, including DNS, HTTP and Net flow, in both graphic and text format. The system has about ten thousand live web-based malware attacks mapped to date and adds daily information on new events added.Detection engines from Barracuda Labs have numerous malware infections found in reputable websites. In recent months Barracuda Labs has published analyzes of popular websites like Cracked.com, Php.net and Hasbro.com.Information on this and thousands of other infected websites is now available through Threat Glass