Monthly Archives: April 2013

WordPress Websites Target of Hacker Attack

Many websites built on the blogging and content management system WordPress are currently under attack by a group of hackers attempting to gain access to the sites to use them in Distributed Denial of Service (DDOS) attacks. The infected machines are then, in turn, attempting to gain access to other WordPress installations, to quickly grow the size of the botnet. Security experts say this is one of the most robust WordPress attacks to date, and the hackers have succeeded in building a very strong botnet of infected systems. There are currently nearly 100,000 IP addresses in use by the infected systems, and this could grow as the hackers turn additional WordPress installations into subservient systems. Two popular managed hosting services, HostGator and Resellers Panel are undergoing a very heavy attack by the botnet right now – both services specialize in WordPress hosting packages. Hackers are bute-force punching their way into the WordPress backend by trying 1,000 – 2,000 password combinations against the “admin” username on WordPress systems. WordPress users with easy-to-guess passwords are at the most risk for having their systems compromised. To avoid having your WordPress instances violated, John Dolan, a freelance security expert, suggests that users go into their WordPress settings “right now, as soon as possible, and update their passwords,” he said. “It should be changed to a complex password, not a dictionary word, and it should use a mixture of capital and lowercase letters, as well as numbers and another character, like a question mark, for example.” In addition to making sure your password is secure, Dolan also recommends that WordPress users look into a service like CloudFlare, an online security vendor that monitors your website’s incoming traffic and deflects attacks from known bots and spammers. What to do if your WordPress instance has been hijacked? “Talk to your hosting provider,” says Dolan. “They most likely have experience with this, and can help you wipe your WordPress install and restore your latest backup.” Source: http://www.szsu.com/2013/04/13/wordpress-websites-target-of-hacker-attack/

View article:
WordPress Websites Target of Hacker Attack

Amex Website Victim of DDoS Attack

Cyber attacks have become an alarming problem in recent months. Threats from China have been the main concern in America, but now a new type of hacker has surfaced. A group of Islamic internet hackers launched a distributed denial of service attack on the American Express website, temporarily shutting down the site for a few hours. As expected, this did not go over well with American Express cardholders. In a DDOS attack, site visitors are infected with a Trojan virus that redirects them to a site of the creator’s choice. Once a certain number of people visit that target site, the original site shuts down. The hackers were able to make this work successfully, but American Express’s security team quickly corrected the problem. Nevertheless, it shows how vulnerable American business is right now to Internet hackers. The hackers claimed that much of their motivation came from the YouTube video, Innocence of Muslims. Since its publication, that video has enraged the Islamic community and fueled their hatred of Americans. The cyber hackers vowed to continue their efforts until it was removed from the internet. The original video was in English, but there are now versions in Arabic, French, Spanish and other languages. It has been blocked in Indonesia, Saudi Arabia, Egypt and other Muslim states. The video was actually removed once before because of a slew of hate mail going towards the original uploader. It was re-posted shortly thereafter and has since received close to two million views. American Express is now taking extra precautions to ensure that similar events do not happen in the future. Source: http://www.lowcards.com/amex-website-hacked-islamic-attackers-11690

Read the original:
Amex Website Victim of DDoS Attack

ZeroAccess Bitcoin botnet shows no signs of slowing

FortiGuard Labs observed that the Bitcoin mining botnet, ZeroAccess, was the number one threat last quarter. Their report also reveals new analysis of the South Korea cyberattacks and two new Android …

View article:
ZeroAccess Bitcoin botnet shows no signs of slowing

Top Banks Offer New DDoS Attack Details

Increasingly, U.S. banking institutions are reluctant to acknowledge – much less discuss – the ongoing distributed-denial-of-service attacks against their online services. Perhaps that’s because they’re concerned that consumers will panic or that revealing too much about the attacks could give hacktivists information they could use to enhance their DDoS abilities. But in recent regulatory statements, the nation’s largest banks are candid about DDoS attacks and their impact. In their annual 10-K earnings reports, filed with the Securities and Exchange Commission, seven of the nation’s top 10 financial services institutions provide new details about the DDoS attacks they suffered in 2012. In its report, Citigroup even acknowledges that DDoS attacks have led to unspecified losses. Citigroup , which filed its 10-K report March 1, notes: “In 2012, Citi and other U.S. financial institutions experienced distributed-denial-of-service attacks which were intended to disrupt consumer online banking services. While Citi’s monitoring and protection services were able to detect and respond to these incidents before they became significant, they still resulted in certain limited losses in some instances as well as increases in expenditures to monitor against the threat of similar future cyber-incidents.” The bank also points out that these attacks are being waged by powerful adversaries. “Citi’s computer systems, software and networks are subject to ongoing cyber-incidents, such as unauthorized access; loss or destruction of data (including confidential client information); account takeovers; unavailability of service; computer viruses or other malicious code; cyber-attacks; and other events,” Citi states. “Additional challenges are posed by external extremist parties, including foreign state actors, in some circumstances as a means to promote political ends.” When contacted by BankInfoSecurity , Citi and other institutions did not comment further about DDoS attacks or the information in the 10-K reports. These banks, as well as other U.S. financial institutions, are now in the midst of the third wave of DDoS attacks attributed to the hacktivist group Izz ad-Din al-Qassam Cyber Fighters – a group that has claimed since September that its attacks are being waged to protest a YouTube movie trailer deemed offensive to Muslims. ‘Technically Sophisticated’ In their 10-K reports, Citi, as well as JPMorgan Chase & Co. , Bank of America , Goldman Sachs Group , U.S. Bancorp , HSBC North America and Capital One acknowledge suffering from increased cyber-activity, with some specifically calling out DDoS as an emerging and ongoing threat. HSBC North America, in its 10-K report filed March 4, notes the global impact of DDoS on its customer base. “During 2012, HSBC was subjected to several ‘denial of service’ attacks on our external facing websites across Latin America, Asia and North America,” the bank states. “One of these attacks affected several geographical regions for a number of hours; there was limited effect from the other attacks with services maintained. We did not experience any loss of data as a result of these attacks.” And U.S. Bank, in its 10-K filed Jan. 15, describes DDoS attacks as “technically sophisticated and well-resourced.” “The company and several other financial institutions in the United States have recently experienced attacks from technically sophisticated and well-resourced third parties that were intended to disrupt normal business activities by making internet banking systems inaccessible to customers for extended periods,” U.S. Bank reports. “These ‘denial-of-service’ attacks have not breached the company’s data security systems, but require substantial resources to defend and may affect customer satisfaction and behavior.” U.S. Bank reports no specific losses attributed to DDoS, but it states: “Attack attempts on the company’s computer systems are increasing, and the company continues to develop and enhance its controls and processes to protect against these attempts.” Other DDoS Comments Here is what the other institutions reported about DDoS attacks suffered in 2012: Chase: “The firm and several other U.S. financial institutions continue to experience significant distributed denial-of-service attacks from technically sophisticated and well-resourced third parties which are intended to disrupt consumer online banking services. The firm has also experienced other attempts to breach the security of the firm’s systems and data. These cyber-attacks have not, to date, resulted in any material disruption of the firm’s operations, material harm to the firm’s customers, and have not had a material adverse effect on the firm’s results of operations.” BofA: “Our websites have been subject to a series of distributed denial of service cybersecurity incidents. Although these incidents have not had a material impact on Bank of America, nor have they resulted in unauthorized access to our or our customers’ confidential, proprietary or other information, because of our prominence, we believe that such incidents may continue. Although to date we have not experienced any material losses relating to cyber-attacks or other information security breaches, there can be no assurance that we will not suffer such losses in the future.” CapOne: “Capital One and other U.S. financial services providers were targeted recently on several occasions with distributed denial-of-service attacks from sophisticated third parties. On at least one occasion, these attacks successfully disrupted consumer online banking services for a period of time. If these attacks are successful, or if customers are unable to access their accounts online for other reasons, it could adversely impact our ability to service customer accounts or loans, complete financial transactions for our customers or otherwise operate any of our businesses or services online. In addition, a breach or attack affecting one of our third-party service providers or partners could impact us through no fault of our own. Because the methods and techniques employed by perpetrators of fraud and others to attack, disable, degrade or sabotage platforms, systems and applications change frequently and often are not fully recognized or understood until after they have been launched, we and our third-party service providers and partners may be unable to anticipate certain attack methods in order to implement effective preventative measures. Should a cyber-attack against us succeed on any material scale, market perception of the effectiveness of our security measures could be harmed, and we could face the aforementioned risks. Though we have insurance against some cyber-risks and attacks, it may not be sufficient to offset the impact of a material loss event.”   No Mentions of Attacks Among the top 10, the only institutions that do not specifically reference DDoS in their 10-K reports are Morgan Stanley, Bank of NY Mellon and Wells Fargo , a bank that has recently suffered significant online outages. Wells Fargo spokeswoman Sara Hawkins tells BankInfoSecurity that the bank’s online and mobile-banking channels were inaccessible for portions of the day on April 4, when it saw “an unusually high volume of website and mobile traffic … which we believe is a denial of service attack.” Reporting Protocol Doug Johnson , who oversees risk management policy for the American Bankers Association, says banking institutions are required to report all suspicious cyber-activity either through their filings with the SEC or in the Suspicious Activity Reports to the Financial Crimes Enforcement Network , a bureau of the U.S. Department of the Treasury. All financial institutions, regardless of size, must report SARs to FinCEN, an agency that collects, analyzes and shares financial intelligence. However, only companies with more than $10 million in assets are required to file reports with the SEC. Banking institutions are required to report cyber-attacks in their SEC filings, Johnson says. “Online banking platforms, obviously, are extremely important to banking retail consumers, and so that would be one of those systems which would be very important to report on a suspicious activity report,” Johnson says. “One thing that is also very important to do is to go and have that conversation with your primary federal regulator, at the field level, to find out what you would do, as an institution, for generalized security breach reporting.” Breach reporting requirements vary from state to state, Johnson adds. For protection against your eCommerce site click here . Source: http://www.bankinfosecurity.com/top-banks-offer-new-ddos-details-a-5667/p-3  

See more here:
Top Banks Offer New DDoS Attack Details

Anonymous launches massive cyber assault on Israel

Hacktivist group Anonymous has launched a second massive cyber attack against Israel, dubbed #OpIsrael. The collective threatens to “disrupt and erase Israel from cyberspace” in protest over its mistreatment of Palestinians. Dozens of Israeli websites were unavailable as of early Sunday. In a video message posted on YouTube, Anonymous said that on April 7, “e lite cyber-squadrons from around the world have decided to unite in solidarity with the Palestinian people against Israel as one entity to disrupt and erase Israel from cyberspace.” Addressing the Israeli government, the group stated: “Y ou have NOT stopped your endless human right violations. You have NOT stopped illegal settlements. You have NOT respected the ceasefire. You have shown that you do NOT respect international law.” Earlier on Saturday, an Anonymous affiliated group identifying itself as The N4m3le55 cr3w announced that they “have gathered 600 websites and 100 plus servers we will be attacking” throughout Israel. The list includes banks, schools, businesses and a host of prominent government websites. “That is just our targets,” the group warned. “We cannot speak on what the rest of Anonymous will be attacking but we can guarantee it will be in the 1000?s.” The massive cyber attack falls on the eve of Holocaust Memorial Day. Anonymous has accused the Israeli government of mistreating its own citizens, violating treaties, attacking its neighbors, threatening to shut down the Internet in Gaza and ignoring “repeated warnings ” about human rights abuses. “The estimations are that [the cyber-attacks] will reach an unusual level that we have never seen before,” Deputy Information Security Officer Ofir Cohen said in an e-mail sent to Knesset employees on Thursday, The Jerusalem Post reported. Cohen added that the E-government – the Israeli government’s information security body – and the Knesset’s internet service provider (ISP) are working to block the attack. On Wednesday, thousands of Israeli Facebook users were infected by a virus, although its effects at this point appear to be minimal. On Friday, Israeli radio reported that scores of large organizations had closed their websites to shield them from hacker attacks. Despite the impending threat, Lior Tabansky, a fellow at the Yuval Ne’eman Workshop for Science, Technology, and Security of Tel Aviv University, told the Times of Israel that distributed denial of service (DDos) attacks, which work by overwhelming targeted servers with traffic which stems from multiple systems, are the only tool at the hackers’ disposal. “Unless they have names and passwords, [DDoS] is really their only attack strategy. Unfortunately, there is little a company can do to stop it, but it is not the major cyber-threat many people, especially in the media, believe it to be. It’s more of an annoyance, and if they do manage to intimidate sites into submission, the victory will be one of public relations.” However, other experts have warned that the hackers may attempt to deploy malware such as “Trojan horses”, which can steal information and harm host computer systems. Anonymous launched the first ‘OpIsrael’ cyber-attacks in November 2012 during Operation Pillar of Defense, an eight day Israeli Defense Force (IDF) incursion into the Gaza s trip. Some 700 Israeli website suffered repeated DDos attacks, which targeted high-profile government systems such as the Foreign Ministry, the Bank of Jerusalem, the Israeli Defence Ministry, the IDF blog, and the Israeli President’s official website. The Israeli Finance Ministry reported an estimated 44 million unique attacks on government websites over a four day period. Following ‘OpIsrael,’ Anonymous posted the online personal data of 5,000 Israeli officials, including names, ID numbers and personal emails. The group also took part in an attack in which the details of some 600,000 users of the popular Israeli email service Walla were released online. Source: http://rt.com/news/opisrael-anonymous-final-warning-448/

Read More:
Anonymous launches massive cyber assault on Israel

Bitcoin exchange: Greedy traders to blame for DDoS attack

Bears bearing botnets? The soaring value of crypto-currency Bitcoin stuttered slightly last night – after a main exchange for the currency was flooded with network traffic and Bitcoin wallet site Instawallet was suspended.…

Taken from:
Bitcoin exchange: Greedy traders to blame for DDoS attack

Mt. Gox under largest DDoS attack as bitcoin price surges

The largest bitcoin exchange said Thursday it is fighting an intense distributed denial-of-service attack it believes is intended at manipulating the price of virtual currency, which has seen volatile price swings in the past few days. Mt. Gox, which is based in Tokyo, said the attacks have caused its worst trading lags ever and caused error pages to be displayed to traders, according to a post on Facebook. By its own calculation, 80 percent of the bitcoin trades in U.S. dollars are executed on Mt. Gox’s trading platform and 70 percent of all trades in other currencies. The lag of six or seven seconds before a trade is executed “is not acceptable,” said Gonzague Gay-Bouchery, marketing for Mt. Gox, in a phone interview. But he cautioned that Mt. Gox’s trading platform isn’t like those of the New York Stock Exchange or the Nasdaq. The price surge, which saw bitcoin hit as much as US$142 per coin on Wednesday, has caused malicious opportunists to try and game the system, according to Mt. Gox. Attackers have waited until bitcoin’s price hits a high, sell their bitcoins and then start a DDoS attack that destabilizes the exchange. They hope bitcoin holders will panic and sell, causing the price to drop. The attackers can then buy the cheaper bitcoins and try the attack again when the price floats higher. The latest DDoS attack started last night Japan time and intensified around 5 a.m. this morning, Gay-Bouchery said. Mt. Gox uses a Florida-based security vendor, Prolexic, to fend off attacks, but “they have been slower than usual to catch what happened,” he said. Gay-Bouchery said he wasn’t sure when the attacks would subside. He warned bitcoin traders not to panic or invest more money than they’re willing to lose. Traders should also use Mt. Gox’s options for two-factor authentication in order to prevent their accounts from being hacked. Mt. Gox is in the midst of a major technical overhaul of its exchange. Gay-Bouchery said Mt. Gox is rebuilding its trading platform from the ground up. The system is in testing now, but Mt. Gox hopes to have it live by the end of the year. “It takes a lot of time to make something bulletproof,” he said. “We cannot release something half-baked.” The trading platform will be separated from the front-end website, which will make it immune from the problems it has faced in the last few days, he said. Mt. Gox doesn’t release much information on its systems in order not to tip off hackers. Mt. Gox has seen a surge in people applying to trade on its platform. In 2012, between 9,000 to 11,000 people signed up per month, Gay-Bouchery said. In January, those numbers doubled, and in February, the numbers tripled. The exchange saw more than 60,000 people sign up in March, which has caused delays in verifying accounts. Mt. Gox will raise trading limits if people supply identification to comply with anti-money laundering rules. The exchange is also working with external companies to streamline the verification process and beefed up its internal account verification team to more than 20 people. “I really would like to stress that people trust us with a lot of money right now,” Gay-Bouchery said. “We want to do everything by the book. We may appear slow in many respects but we are taking our time to do it right.” For DDoS protection click here . Source: http://www.networkworld.com/news/2013/040413-mt-gox-under-largest-ddos-268385.html?page=1

See the article here:
Mt. Gox under largest DDoS attack as bitcoin price surges

Lessons Learned in Historic DDoS Attack on Spamhaus

The DNS amplification vulnerability, which was exploited to the fullest in the attacks on Spamhaus, return incoming requests to a DNS server with as much as 100 times as much data. When the attackers have faked the source address for those incoming requests, the responses can overwhelm the victims’ servers — and possibly spill over and clog the Net. What is the aftermath of the massive Distributed Denial of Service attacks recently on the anti-spam Spamhaus organization? As the largest such attack in history, the digital assault on Spamhaus slowed network performance in some regions of Europe and elsewhere, raised alarms about whether the Net could reach a breaking point, and has become a historic event that could mark a turning point. According to reports in The New York Times and elsewhere, a key figure in the attacks appears to be Sven Olaf Kamphuis, who is associated with CyberBunker, the Dutch hosting facility where the attacks originated. After the Europe-based Spamhaus put CyberBunker on its spam blacklist, because of what Spamhaus said were substantial streams of spam e-mails coming from that hosting facility, the DDoS attacks began. Kamphuis maintains a Facebook page, in which he champions hosting services such as CyberBunker for providing open Net access, and he rails against Spamhaus for acting like an arbitrary authority. Like ‘The Mafia’ CyberBunker has said it will allow customers to host anything except “child porn and anything related to terrorism.” Spamhaus is backed by a variety of e-mail services, and experts have testified in court that many e-mail services would be rendered useless by the flood of spam if not for the organization’s efforts. But this massive wave of DDoS attacks — in which Web servers are overwhelmed by a flood of bogus traffic — broke some boundaries, according to Garth Bruen, an adviser to the consumer-oriented Digital Citizens Alliance. Bruen told USA Today that the attacks from CyberBunker were like “the kind of things we saw the mafia do to take control of neighborhoods 50 years ago.” He added that what was particularly “troubling” is that CyberBunker is a commercial ISP “working with shadowy figures in undisclosed locations.” Open DNS Resolvers The attacks have highlighted some ongoing weaknesses in the Internet’s infrastructure . Key among these are open Domain Name System resolvers, which allow attackers to engage in so-called DNS amplification. One of the weaknesses of open resolvers is that they do not authenticate a sender’s address before replying. This vulnerability, which was exploited to the fullest in the attacks on Spamhaus, return incoming requests to a DNS server with as much as 100 times as much data . When the attackers have faked the source address for those incoming requests, the responses can overwhelm the victims’ servers — and possibly spill over and clog other parts of the Net. DNS servers are critical to the Internet as they translate alphanumeric-based Web addresses like “www.google.com” into the numeric IP addresses that computers can understand. The Spamhaus attacks reportedly utilized more than 30,000 unique DNS resolvers. There are efforts, such as the Open DNS Resolver Project, to convince DNS administrators to implement source address validation, among other actions, to eliminate open DNS resolvers as a Net-wide weakness. There are also calls for IT departments and individual PC owners to make a greater effort to scan their computers for signs of malware that could be hijacking their machines into becoming part of a botnet. Additionally, the Electronic Frontier Foundation and others have offered tips to small businesses on how to cope with DDoS attacks, if their sites become one of the direct or indirect targets. For DDoS protection click here . http://www.cio-today.com/story.xhtml?story_id=0020002HERPO&page=2

More:
Lessons Learned in Historic DDoS Attack on Spamhaus

How you may have inadvertently participated in recent DDoS attacks

The botnets driving the recent distributed denial of service attacks are powered by millions of infected computers. Their coordinated flood of requests overwhelms the Internet’s DNS servers, slowing them down and even knocking the servers offline. The long-term solution for site operators and visitors alike may rely on reluctant ISPs working together. The risk that an Internet-connected computer is infected with malware will never be reducible to zero. It’s just the nature of software that errors happen. Where there are software-design errors, there are people who will exploit those errors to their advantage. The best PC users can hope for is to minimize the chances of an infection and to mitigate the damage a piece of malware can inflict — whether it intends to steal a user’s sensitive data or to commandeer the machine as part of a cyber attack on servers thousands of miles away. Last week, Internet users were caught in the crossfire of an online battle. On one side were spammers and other nefarious types who send malware via e-mail. On the other was the spam-fighting organization Spamhaus. As Don Reisinger reported last Wednesday, several European sites experienced significant slow-downs as a result of the attack, which may have also involved criminal gangs in Russia and Eastern Europe. In a post last Friday, Declan McCullagh explained that the technology to defeat such attacks has been known for more than a decade, although implementing the technology Internet-wide is difficult and, practically speaking, may be impossible. So where does that leave your average, everyday Internet user? Our ability to prevent our machines from being hijacked by malware will always be limited by our innate susceptibility. We’re simply too likely to be tricked into opening a file or Web page we shouldn’t. PC infection rates hold steady despite the prevalence of free antivirus software. Even the best security programs fail to spot some malware, as test results by A-V Comparatives indicate (PDF). For example, in tests conducted in August 2011, Microsoft Security Essentials was rated as Advanced (the second-highest scoring level) with a detection rate of 92.1 percent and “very few” false positives. Since we’ll never eliminate PC infections, the best defense against botnets is not at the source but rather at the point of entry to the ISP’s network. In July of last year the Internet Engineering Task Force released a draft of the Recommendations for the Remediation of Bots in ISP Networks that points out the challenges presented by bot detection and removal. Unfortunately, detecting and removing botnets isn’t much easier for ISPs. When ISPs scan their customers’ computers, the PC may perceive the scan as an attack and generate a security alert. Many people are concerned about the privacy implications of ISPs scanning the content of their customers’ machines. Then there’s the basic reluctance of ISPs to share data and work together in general. Much of the IETF’s suggested remediation comes down to educating users about the need to scan their PCs for infections and remove those they discover. While most virus infections make their presence known by slowing down the system and otherwise causing problems, the stealth nature of many bots means users may not be aware of them at all. If the bot is designed not to steal the user’s data but only to participate in a DDoS attack, users may feel no need to detect and delete the bot. One of the IETF report’s suggestions is that ISPs share “selective” data with third parties, including competitors, to facilitate traffic analysis. In March of last year the Communications Security, Reliability and Interoperability Council released its voluntary Anti-Bot Code of Conduct for ISPs (PDF). In addition to being voluntary, three of the four recommendations in the “ABCs for ISPs” rely on end users: Educate end-users of the threat posed by bots and of actions end-users can take to help prevent bot infections; Detect bot activities or obtain information, including from credible third parties, on bot infections among their end-user base; Notify end-users of suspected bot infections or help enable end-users to determine if they are potentially infected by bots; and Provide information and resources, directly or by reference to other sources, to end-users to assist them in remediating bot infections. A paper titled “Modeling Internet-Scale Policies for Cleaning up Malware” (PDF) written by Lawrence Berkeley National Laboratory’s Stephen Hofmeyr and others suggests that having large ISPs working together to analyze traffic at points of entry to their network is more effective than bot detection on end-user machines. But that doesn’t get us off the hook entirely. If every Windows PC were scanned for malware once a month, there would be far fewer bots available for the next DDoS attack. Since CNET readers tend to be more tech-savvy than average, I suggest a computer-adoption program: everyone scan two or three PCs they suspect aren’t regularly maintained by their owners (such as relatives) on a pro bono basis. Here are three steps you can take to minimize the possibility that a Windows PC will be drafted into a botnet army. Don’t use a Windows administrator account The vast majority of malware targets Windows systems. In large part it’s simply due to numbers: there are so many more installations of Windows than any other operating system that leveraging Windows maximizes a piece of malware’s effectiveness. Many people have no choice but to use Windows, most likely because their employer requires it. For many others, using an OS other than Windows is impractical. But very few people need to use a Windows administrator account on a daily basis. In the past two years I’ve used only a standard Windows account on my everyday PC, with one or two exceptions. In fact, I often forget the account lacks administrator privileges until a software installation or update requires that I enter an administrator password. Using a standard account doesn’t make your PC malware-proof, but doing so certainly adds a level of protection. Set your software to update automatically Not many years ago, experts advised PC users to wait a day or two before applying patches for Windows, media players, and other applications to ensure the patches didn’t cause more problems than they prevented. Now the risk posed by unpatched software is far greater than any potential glitches resulting from the update. In May 2011 I compared three free scanners that spot outdated, insecure software. My favorite of the three at the time was CNET’s own TechTracker for its simplicity, but now I rely on Secunia’s Personal Software Inspector, which tracks your past updates and provides an overall System Score. The default setting in Windows Update is to download and install updates automatically. Also selected by default are the options to receive recommended updates as well as those labeled important, and to update other Microsoft products automatically. Use a second anti-malware program to scan the system Since no security program detects every potential threat, it makes sense to have a second malware scanner installed for the occasional manual system scan. My two favorite manual virus-scanning programs are Malwarebytes Anti-Malware and Microsoft’s Malicious Software Removal Tool, both of which are free. I wasn’t particularly surprised when Malwarebytes found three instances of the PUP.FaceThemes virus in Registry keys of my everyday Windows 7 PC (shown below), but I didn’t expect the program to detect four different viruses in old Windows system folders on a test system with a default configuration of Windows 7 Pro (as shown on the screen at the top of this post). An unexpected benefit of the malware removal was a reduction in boot time for the Windows 7 machine from more than two minutes to just over one minute. Help for site operators who come under attack DDoS attacks are motivated primarily by financial gain, such as the incident last December that emptied a Bank of the West online account of $900,000, as Brian Krebs reported. The attacks may also be an attempt to exact revenge, which many analysts believe was implicated in last week’s DDoS onslaught against Spamhaus. The government of Iran was blamed for a recent series of DDoS attacks against U.S. banks, as the New York Times reported last January. Increasingly, botnets are being directed by political activists against their opposition, such as the wave of hacktivist attacks against banks reported by Tracy Kitten on the BankInfoSecurity.com site. While large sites such as Google and Microsoft have the resources to absorb DDoS attacks without a hiccup, independent site operators are much more vulnerable. The Electronic Frontier Foundation offers a guide for small site owners to help them cope with DDoS attacks and other threats. The Keep Your Site Alive program covers aspects to consider when choosing a Web host, backup alternatives, and site mirroring. The increasing impact of DDoS attacks is one of the topics of the 2013 Global Threat Intelligence Report released by security firm Solutionary. Downloading the report requires registration, but if you’re in a hurry, Bill Brenner offers a synopsis of the report on CSO’s Salted Hash blog. As Brenner reports, two trends identified by Solutionary are that malware is increasingly adept at avoiding detection, and Java is the favorite target of malware exploit kits, supplanting Adobe PDFs at the top of the list. The DNS server ‘vulnerability’ behind the DDoS attacks The innate openness of the Internet makes DDoS attacks possible. DNS software vendor JH Software explains how DNS’s recursion setting allows a flood of botnet requests to swamp a DNS server. CloudShield Technologies’ Patrick Lynch looks at the “open resolvers” problem from an enterprise and ISP perspective. Paul Vixie looks at the dangers of blocking DNS on the Internet Systems Consortium site. Vixie contrasts blocking with the Secure DNS proposal for proving a site’s authenticity or inauthenticity. Finally, if you’ve got two-and-a-half hours to kill, watch the interesting panel discussion held in New York City last December entitled Mitigating DDoS Attacks: Best Practices for an Evolving Threat Landscape. The panel was moderated by Public Interest Registry CEO Brian Cute and included executives from Verisign, Google, and Symantec. I was struck by one recurring theme among the panel participants: we need to educate end users, but it’s really not their fault, and also not entirely their problem. To me, it sounded more than a little bit like ISPs passing the buck. For DDoS protection click here . Source: http://howto.cnet.com/8301-11310_39-57577349-285/how-you-may-have-inadvertently-participated-in-recent-ddos-attacks/

Link:
How you may have inadvertently participated in recent DDoS attacks