Tag Archives: dos attacks

Irish lottery site and ticket machines hit by DDoS attack

Ireland’s National Lottery website and ticket machines were knocked offline after a distributed denial of service (DDoS) attack on Wednesday. Customers trying to buy tickets for the €12m (£9m) draw found themselves unable to do so for nearly two hours. The jackpot was the largest in 18 months. Premier Lotteries Ireland (PLI), the operator, has said the incident is under investigation. During a DDoS attack, a website or online service’s capacity to handle internet traffic is overloaded – usually by automated programs set to flood the site with requests. The attack began at 11:21 GMT on Wednesday and lasted for about two hours. Retail systems were brought back online by 12:45 GMT and the website by 13:25 GMT. “They said you couldn’t buy tickets from the ticket machines, which is really interesting, it’s not just the website – it would be quite interesting to understand why that happened,” said John Graham-Cumming at DDoS-protection company Cloudflare. ‘Under investigation’ “This incident is still under investigation,” a spokeswoman said. “However, we can confirm that at no point was the National Lottery gaming system or player data affected.” Given the large jackpot involved, the lottery was experiencing high demand for tickets on Wednesday lunchtime. The impact of the attack may well have been heightened by this, according to Igal Zeifman, senior digital strategist at cybersecurity company Imperva. “As a rule, record-setting prizes and jackpots result in traffic spikes on lottery sites, and it is very common for DDoS attackers to strike during such predictable peak traffic times, especially when going after big targets,” he said. Source: http://www.bbc.com/news/technology-35373890

See the original post:
Irish lottery site and ticket machines hit by DDoS attack

Lotto ticket machines, website working after DDoS attack

The National Lottery website and ticket machines were targeted by a cyber-attack to disrupt its operations. A  DDoS (Distributed Denial of Service) attack floods the communications system with traffic affecting all communications connectivity. “Indications are that this morning’s technical issues were as a result of a DDoS attack affecting our communications networks,” a statement from the Lottery said. “The issues were resolved by the National Lottery’s DDoS protection systems, limiting disruption and restoring all operations within two hours. “This incident is still under investigation. However, we can confirm that at no point was the National Lottery gaming system or player data affected,” the statement added. Tonight’s jackpot is heading for €12 million. RGDATA, the representative association for the independent retail grocery sector, said the National Lottery made it aware of the problem this morning. Last February, the National Lottery was forced to postpone its draw for 24 hours after a technical problem stopped ticket machines working. Source: http://www.rte.ie/news/2016/0120/761563-national-lottery/

Read More:
Lotto ticket machines, website working after DDoS attack

DDoS Attack Hits Kickass Torrents, DNS Servers Crippled

Site goes down for most of the day on January 16 Kickass Torrents, the Internet’s biggest torrent portal has suffered downtime yesterday after an unknown attacker has pummeled the site with a DDoS attack. According to a statement given by the site’s administrators to TorrentFreak, a blog dedicated to piracy news, the attack was aimed at the website’s DNS servers. Because of this, both the main domain and the plethora of official site proxies were down as well. The brunt of the attack was registered yesterday, January 16, and had the site taken offline for almost all day. Previously, during the week, the site was also hit by smaller DDoS attacks. Everything seems to be up and running now, but expect future attacks as well. The attack fits the pattern of a DDoS extortion campaign, when small attacks are launched at first, and then a bigger one to force victims into paying the DDoS ransom. Earlier this week, Europol announced the capture of the famed DD4BC DDoS extortion group in Bosnia and Herzegovina. DD4BC is the first group known to launch DDoS attacks and then ask for payments in Bitcoin. The group’s actions have been copied by many other DDoSing outfits, and most DDoS attacks nowadays are launched for this reason. Kickass Torrents is one of Alexa’s top 100 sites on the Internet, meaning it’s an attractive target for DDoSing groups, thanks to its huge advertising revenue. Source: http://news.softpedia.com/news/ddos-attack-hits-kickass-torrents-dns-servers-crippled-499019.shtml

Read More:
DDoS Attack Hits Kickass Torrents, DNS Servers Crippled

A DDoS Learning Curve for Universities, Government & Enterprises

Distributed Denial of Service attacks are easy, cheap and too often, effective. But they’re not unstoppable. There’s no getting around it — DDoS attacks are growing in frequency, size, severity, sophistication, and even persistence each year. These tenacious, effective attacks can last anywhere from hours to months. They can be launched from botnets, use multiple protocols, and even disguise themselves with SSL encryption. Protecting yourself against DDoS isn’t a matter of stopping one attack but a multitude, sometimes all at once. Even worse, IT departments may not realize an attack is underway, thinking a failing server or application is responsible. Rutgers University, for example, recently fell prey to its sixth known DDoS attack in a single year — and Rutgers is not an outlier. Thousands of DDoS attacks hit universities, enterprises, government organizations, and banks every day—some successful, some not. One thing is for sure: no one is safe, and attacks will continue because DDoS attacks are easy, cheap and, too often, effective. But they’re not unstoppable. Universities and other organizations can take steps to prepare for and minimize the effect of even the most sophisticated assaults: Step 1. Have a good monitoring system in place Security teams have many ways to get insight into their network, including flow sampling, in-path detection and mirrored data packets. Here’s a brief breakdown of the pluses and minuses: Flow sampling: The router samples packets and exports datagrams on them. While scalable, this method leaves out large quantities of information because it only samples one packet out of thousands. This allows some “slow and low” attacks to fly under the detection radar, or take a long time to trigger an alert. In-path detection:  A high-performance DDoS mitigation device continuously processes all incoming traffic and possibly outgoing traffic. The device can take immediate action with sub-second mitigation times. One concern is ensuring the mitigation solution can scale with the uplink capacity during multi-vector attacks. Mirrored data packets: Full detail for analysis is provided, while not necessarily in the path of traffic. This method can be a challenge to set up, but allows for fast detection of anomalies in traffic and is a centralized place for analysis and mitigation. Step 2. Keep an eye on performance metrics and scalability When it comes to DDoS, everything happens on a large scale: the number of attacking computers, the bandwidth they consume and the connections they generate. To fight back, organizations need a combination of high-performance, purpose-built hardware that can mitigate common, yet large-scale attacks effectively, and intelligent software that can inspect traffic at the highest packet rates. For instance, an effective combination might include leveraging dedicated network traffic processors (e.g. FPGAs) to handle the common network-layer attack in combination with powerful, multi-core CPUs to mitigate more complex application-layer attacks. What’s key here is to ensure there is enough processing headroom to prepare networks for future generations of DDoS attacks. Step 3. Invest in a security awareness program Mitigation of next-generation DDoS attacks starts with training — especially to recognize normal network behavior and spot anomalies. For instance, companies that have started their migration to IPv6 must have security specialists in place that know IPv6 well enough to recognize attacks when they happen, and then to know how to use available tools to properly fight them off. Proper training allows organizations to be proactive versus reactive. Security policies take time to devise, so universities and other organizations shouldn’t wait for the IT support staff to raise a red flag before they decide to take action. Source: http://www.darkreading.com/attacks-breaches/a-ddos-learning-curve-for-universities-government-and-enterprises-/a/d-id/1323879

Continue Reading:
A DDoS Learning Curve for Universities, Government & Enterprises

DDoS attack on Pakistan Government Websites on Live Radio

Dozens of government websites in Pakistan have been targeted by hackers, including one military site that was taken down during a live radio interview with one of the group’s members. The organization responsible, known as New World Hackers, performed a distributed denial of service (DDoS) attack on Pakistan’s Frontier Constabulary website during an appearance on the AnonUK Radio Show on Sunday, following a weekend of sustained attacks on government sites. Dozens of government websites in Pakistan have been targeted by hackers, including one military site that was taken down during a live radio interview with one of the group’s members. The organization responsible, known as New World Hackers, performed a distributed denial of service (DDoS) attack on Pakistan’s Frontier Constabulary website during an appearance on the AnonUK Radio Show on Sunday, following a weekend of sustained attacks on government sites. “It’s not that the Indian hackers want to attack Pakistani sites, there is a war between them and the Pakistani hackers,” the New World Hackers member says. “We upgraded the capabilities of the Indian hackers. “The Pakistani hackers always wish to fuck with India. The Indian hackers are actually the good guys.” Pakistan’s Frontier Constabulary did not respond to a request for comment. Source: http://www.newsweek.com/hackers-take-down-pakistan-government-websites-live-radio-413888

Taken from:
DDoS attack on Pakistan Government Websites on Live Radio

Minnesota Courts Website Target Of DDoS Attacks

A week after the Minnesota courts website was completely shut down for 10 days in December, we’re finally finding out why. The Minnesota Judicial Branch says its website was the target of two distributed-denial-of-service (DDoS) attacks. In a DDoS attack, a website or server is overwhelmed with network traffic until it can no longer function for legitimate users. The MJB says the attacks in December left their site unusable to members of the public for several hours, and was eventually completely shut down from Dec. 21 to 31 in order to install additional safeguards. Officials say no personal data was breached as a result of the attack — DDoS attacks are typically used to sabotage a website or server , rather than steal information. Authorities say initial forensics show the attacks were primarily launched from servers in Asia and Canada, and international authorities are investigating. Source: http://minnesota.cbslocal.com/2016/01/08/minnesota-courts-website-target-of-ddos-attacks/

Visit link:
Minnesota Courts Website Target Of DDoS Attacks

DDoS attack on BBC may have been biggest in history

Last week’s distributed denial of service attack against the BBC website may have been the largest in history. A group calling itself New World Hacking said that the attack reached 602Gbps. If accurate, that would put it at almost twice the size of the previous record of 334Gbps, recorded by Arbor Networks last year. “Some of this information still needs to be confirmed,” said Paul Nicholson, director of product marketing at A10 Networks, a security vendor that helps protect companies against DDoS attacks. “If it’s proven, it would be the largest attack on record. But it depends on whether it’s actually confirmed, because it’s still a relatively recent attack.” According to Nicholson, it sometimes happens that people who step forward and take credit for attacks turn out to be exaggerating. New World Hacking also said that the attack, which came on New Year’s Eve, was “only a test.” “We didn’t exactly plan to take it down for multiple hours,” the group told the BBC. New World Hacking also hit Donald Trump’s campaign website the same day, and said its main focus was to take down ISIS-affiliated websites. It’s common for hackers to go after high-profile media websites, but attacks against political websites are increasingly likely to be in the spotlight this year because of the U.S. election cycle, according to Raytheon|Websense CEO John McCormack. “The U.S. elections cycle will drive significant themed attacks,” he said. “This is just the beginning and it will get worse — and more personal — as candidates see their campaign apps hacked, Twitter feeds hijacked, and voters are targeted with very specific phishing attacks based on public data such as voter registration, Facebook and LinkedIn.” One possible reason to conduct a DDoS attack against a high-profile target such as the BBC or Donald Trump is marketing, said A10 Networks’ Nicholson. It seems that New World Hacking may be affiliated with an online DDoS tool called BangStresser, which delivers attacks as a service. Last year, a similar group, the Lizard Squad, conducted a marketing campaign for their DDoS service, the Lizard Stressor. “There are a lot of parallels here,” said A10 Networks’ product marketing manager Rene Paap. These services typically leverage botnets or use stolen payment cards to rent cloud-based servers, he said. Typically, the rented servers are used to run command and control servers. What’s unusual about New World Hacking is that they’re claiming to be using Amazon servers to generate actual attack bandwidth. “That is something new,” said Paap. “But it hasn’t been confirmed or denied yet.” Not all DDoS attack services are illegal, said Nicholson. “Some are offered as useful services to websites, to see if they can handle the load,” he said. Others fall squarely into the gray area, allowing cyber-terrorists, extortionists and digital vandals to launch attacks for a few hundred dollars each. “Some of them are quite inexpensive and configurable,” Nicholson said. “for example, you can have different attacks at different times, so that it’s harder to defend against them.” To protect themselves, Nicholson recommends that companies deploy a combination of on-premises and cloud-based solutions to handle attacks of varying types and sizes. “You need to be able to detect what’s going on, that there’s actually an attack,” he said. “And once you detect an attack, you need to be able to mitigate it as long as possible.” According to security vendor Netcraft, service to the BBC network was restored by using the Akamai content delivery network. Akamai declined to comment about this particular case. “As policy, the company isn’t commenting on specific situations,” said a spokesperson. Source: http://www.csoonline.com/article/3020292/cyber-attacks-espionage/ddos-attack-on-bbc-may-have-been-biggest-in-history.html

View article:
DDoS attack on BBC may have been biggest in history

Linode Resets Customer Passwords After Breach, DDoS Attack

Cloud-based webhost Linode absorbed another body blow on Tuesday when it said it was resetting customer passwords after a suspected breach. The development compounded the company’s existing woes as it continues to battle a distributed denial-of-service attack that began on Christmas. A Linode representative said late Tuesday its executives were unavailable for comment and that an investigation was ongoing. The password breach was announced after the company said three accounts were accessed without permission and it discovered two Linode.com user credentials on an “external machine.” “This implies user credentials could have been read from our database, either offline or on, at some point,” Linode said in an advisory to customers. “The user table contains usernames, email addresses, securely hashed passwords and encrypted two-factor seeds. The resetting of your password will invalidate the old credentials.” Linode said it notified the customers whose credentials were found on outside machines and said there was no evidence of further intrusion into host or virtual machines. Linode markets its services toward developers and offers quick, scalable solid state driver server deployments. As of this morning, portions of the Linode website were still inaccessible, and the company said it has not been able to determine whether the DDoS attack and the password breach are related attacks. In the past, experts have warned that criminals will use easy-to-mount DDoS attacks against a target in order to distract IT and security staff away from the real target. “The entire Linode team has been working around the clock to address both this issue and the ongoing DDoS attacks. We’ve retained a well-known third-party security firm to aid in our investigation. Multiple Federal law enforcement authorities are also investigating and have cases open for both issues. When the thorough investigation is complete, we will share an update on the findings,” Linode said. “You may be wondering if the same person or group is behind these malicious acts. We are wondering the same thing. At this point we have no information about who is behind either issue. We have not been contacted by anyone taking accountability or making demands. The acts may be related and they may not be.” Linode was relatively quiet about the DDoS attack until a New Year’s Eve blogpost from network engineer Alex Forster. Forster said that a criminal gang was using a botnet to fire bad traffic at Linode’s authoritative nameservers causing DNS outages. All public-facing websites and web and application servers were also targeted, taking down Linode Manager. The attackers also sent traffic at Linode’s colocation provider’s upstream routers and its internal network infrastructure causing packet loss. In all, Forster said there were more than 30 attacks carried out in the week between Christmas and New Year’s Eve. Source: https://threatpost.com/linode-resets-customer-passwords-after-breach-ddos-attack/115790/#sthash.PPbMALPg.dpuf

View post:
Linode Resets Customer Passwords After Breach, DDoS Attack

Bitcoin exchange BTCC stands firm against DDoS ransom hacker and wins

Bitcoin exchange BTCC Technology Ltd. had an interesting time over the new year when it was targeted by a Bitcoin-for-DDoS (Distributed Denial of Service) attack, but in a great story we don’t see often enough, the company held steady and won, complete with a hilarious ending. The company first came under DDoS attack on December 31 when they received an email from an unknown source demanding they pay 1 Bitcoin ($430) in ransom or the attacks would escalate. Having ignored the demand, on New Years Day BTCC was targeted with a 10 Gbps DDoS attack, the strength of which was not expected by the company’s DDoS mitigation service. According to a post on Reddit, the DDoS protection provider said something along the lines of “This thing is huge! You guys aren’t paying us enough for this!” so BTCC paid them more, and the site stayed up. Naturally, as these things go, the second attack was followed by a new ransom demand by the hacker, who was now asking for a payment of 10 Bitcoin ($4300) to prevent a further attack. Instead of paying, BTCC just battened down the hatches waiting for the next attack. Another, more intense DDoS attack of several hours then followed, causing BTCC’s servers to experience some performance issues, including a partial loss of functionality. BTCC still refused to pay the ransom and instead upgraded their servers to cope even better with the increasing attacks. Another ransom email demand was received, with demand for  payment of 30 Bitcoins ($12924) with the hacker adding ““We will keep these attacks up until you pay!…. You had better pay up before you go bankrupt! Mwa ha ha!” BTCC once again ignored the demand, and the attacks recommenced, complete with more demands for Bitcoin. At this point BTCC had ramped up their mitigation efforts so much that no matter how much traffic the hacker sent it didn’t affect their service at all, to the point that the company stopped noticing many of the attacks as they usually failed to disrupt their networks for more than a few minutes after the upgrades they rolled out. Winning Around this point, despite his or hers best efforts and multiple demands, the hacker gave up trying to take the site down, but not before sending one last, hilarious plea to BTCC. “Hey, guys, look, I’m really a nice person. I don’t want to put you all out of business. What do you say we just make it 0.5 BTC and call it even?” This email was, like those before it, ignored by BTCC, which resulted in one final email from the now disgruntled, losing hacker: “Do you even speak English?” and that was that. Although DDoS attacks are serious business and not every company has the capacity to put into place defensive measures, sometimes a story just makes you want to smile. BTCC 1 vs hacker 0. Source: http://siliconangle.com/blog/2016/01/06/great-story-bitcoin-exchange-btcc-stands-firm-against-ddos-ransom-hacker-and-wins/

Link:
Bitcoin exchange BTCC stands firm against DDoS ransom hacker and wins

DDoS gang takes down BBC websites, Donald Trump’s campaign site over holiday weekend

A group of computer criminals used two separate distributed denial-of-service (DDoS) attacks to bring down all of the BBC’s websites and Donald Trump’s main campaign site over this past holiday weekend. The story begins on New Year’s Eve, when all BBC sites, including its iPlayer service, went dark for three hours. At the time, the UK-based news organization reported that the outage was the result of a “technical issue”. It later stated that a group calling themselves the “New World Hackers” had claimed credit for launching a DDoS attack against the broadcaster, as a “test of its capabilities” Since then, one of the group’s members who identified himself as “Ownz” took the opportunity to send a screenshot to ZDNet of the web interface that was used to attack the BBC. If the screenshot is legitimate, the group allegedly employed their own tool called BangStresser to launch an attack of up to 602 Gbps – a volume of traffic that well-surpasses the largest attack on record at 334 Gbps, as documented by Arbor Networks in the middle of year. Not untypically, BangStresser is itself protected from DDoS attacks by CloudFlare – one of the popular DDoS mitigation services often deployed by websites keen to protect themselves from attackers. The attack apparently made use of two Amazon Web Services servers, but managed to skirt around the company’s automated misuse detection systems as Ownz explained in an interview with ZDNet : “We have our ways of bypassing Amazon. The best way to describe it is we tap into a few administrative services that Amazon is use to using. The [sic] simply set our bandwidth limit as unlimited and program our own scripts to hide it.” No other information has yet been provided about the attack. But whatever else transpired, the group was sufficiently pleased that they decided to use BangStresser to launch a DDoS against Donald Trump’s official campaign website, donaldjtrump.com, just a few days later. According to Softpedia , Trump’s website went down immediately on Saturday, January 2 and remained dark for several hours until DDoS mitigation solutions were put in place. The attacks, however, remained ongoing throughout the day against mail.trump.com domain, the Trump Organization’s Webmail service. Trump’s camp has yet to officially address the incident. A statement posted on Saturday by Trump’s campaign advisers (and redistributed via HackRead ) attributed the downage to “an unusually high volume of traffic” only. On Monday, Real Forums sat down with members of the group to inquire about their New Year’s exploits. Here’s what they had to say: “Our reasons behind the BBC attack was just a test of our capabilities. Although, the Trump site was the target. He can be very racist. We didn’t mean to cause as much damage as we did to BBC, but for Trump, Yes.” The group goes on to state that it plans to launch additional DDoS attacks against Trump and other large organizations like the BBC . The group also specifically mentions ISIS and the Ku Klux Klan as future targets. We’re not a week into 2016, and we’ve already witnessed DDoS attacks that have succeeded in taking down the websites of major news organizations and U.S. political candidates. It just goes to show that while malware is on the rise, DDoS attacks are not going anywhere in the New Year. As we all get back to work, we should therefore take the time to make sure our enterprises have the necessary DDoS mitigation technologies in place. Source: https://www.grahamcluley.com/2016/01/ddos-gang-takes-bbc-websites-donald-trumps-campaign-site-holiday-weekend/

Continue reading here:
DDoS gang takes down BBC websites, Donald Trump’s campaign site over holiday weekend