Showing posts with label Denial-of-service attack. Show all posts
Showing posts with label Denial-of-service attack. Show all posts

Tuesday, April 2, 2013

Scant Brain Power Behind Massive DDoS Attack


It may be the most disturbing thing about last week's historic denial of service attack on a Dutch anti-spam organization -- the fact that the technology involved wasn't that complicated. That's one of the findings of security professionals studying the attack methods used on Spamhaus, along with the knowledge that the hackers used the Internet's own structure to extend their assaults on the group.
One of the largest denial of service attacks in the history of the Internet didn't take rocket science to execute. The offensive was conducted over several days last week after the anti-spam group Spamhaus placed a Dutch hosting service, located in a former NATO bunker, on a blacklist reserved for spammers.
A group calling itself STOPhaus is claiming responsibility for the series of attacks which, at their height, reached bandwidths of 300 Gbps. A 10 Gbps attack will bring most websites down.
To reach those bandwidth levels, the attackers exploited the Internet's architecture and the Domain Naming System to expand the scope of their assaults. They essentially used open servers used to resolve DNS addresses on the Internet like megaphones to amplify their attacks.
The technique was used earlier this year in a series of attacks on U.S. financial websites.

Perl Used By Swine?

Despite the magnitude of the onslaughts, security experts said they can be launched with a relatively low level of technical knowledge. "The technique isn't particularly difficult," said Matthew Prince, co-founder and CEO of Cloudflare. Prince's company came to Spamhaus's aid when the attacks threatened to overwhelm its website.
"The amount of code you'd need to write to launch this attack can almost be done in a line of Perl," Prince told TechNewsWorld. The most difficult part of the campaign is finding open resolvers to use in your attack because it requires scanning billions of IP addresses.
"It takes a lot of reconnaissance, but not a whole lot of technology itself," Henry Stern, a threat researcher with Cisco told TechNewsWorld. That reconnaisance may have gotten easier. A group calling itself the Open DNS Resolver Project has published a list of 27 million open or semi-open resolvers on the Net. The group's intentions are good ones; it wants server operators to check their IP addresses at the site and restrict access to any of their servers they find on the list.

Blowfish12@2013 blowfish12.tk Author: Sudharsun. P. R.

Friday, December 28, 2012

[virus] Fake Android app can launch DDoS attacks from your phone

Researchers at Doctor Web found a new trojan app in the Google Play store that can launch distributed denial of service attacks when opened.

Android.DDoS.1.origin, as it’s called, is Russian and disguises itself as the Google Play icon once downloaded. When opened, the app takes its victims to the actual Google Play store so as to distract the user. In the background, however, it searches for its command and control server — and if a connection is made, the app sends the infected phone’s number to the criminals. These hackers then administer commands to the app via text messages.

Commands include launching a DDoS attack or sending other text messages. Doctor Web suggests that the text message function could be used to spam others in the phone’s contact list, prompting them to either download the app or something else the hackers are pushing.

Nowadays when we think of DDoS attacks, we often are reminded of Anonymous, the hacker collective that launches a number of these attacks in the name of political protest. We’ve seen DDoS attacks take down a number of important websites including the CIA’s, financial institutions, and others. These attacks send large amounts of traffic toward a certain website’s servers in an attempt to overload the system and shut it down.

With this app, however, hackers with DDoS intentions are roping in innocent bystanders to do the dirty work. This isn’t the first time we’ve seen a campaign like this. In the case of the CIA website’s take down, Anonymous was accused of distributing links on Twitter to low-orbit-ion-canons (LOIC). These “cannons” send thousands of packets of information to a targeted server per second. When the Twitter links were clicked on, unsuspecting visitors would suddenly be roped into the attack.

Doctor Web goes on to say that the app can cause the phone to perform poorly, and can actually run up the owner’s bill by texting premium numbers.




Blowfish12@2012 blowfish12.tk Author: Sudharsun. P. R.

Infolinks In Text Ads