Monthly Archives: September 2015

Mobile advertising DDoS JavaScript drip serves site with 4.5 billion hits

CloudFlare has turned up an unusual form of denial-of-service attack: mobile advertisements that are pumping out around 275,000 HTTP requests per second.…

More:
Mobile advertising DDoS JavaScript drip serves site with 4.5 billion hits

Mobile advertising DDoS JavaScript drip serves site with 4.5bn hits

Once-theoretical attack vector appears fully-formed on CloudFlare’s doorstep CloudFlare has turned up an unusual form of denial-of-service attack: mobile advertisements that are pumping out around 275,000 HTTP requests per second.…

Continue reading here:
Mobile advertising DDoS JavaScript drip serves site with 4.5bn hits

Hackers Used Imgur to Launch DDoS Attacks on 4chan

A Reddit user has uncovered a covert method of carrying DDoS attacks on 4chan’s infrastructure using images hosted on Imgur, via Reddit. According to Reddit user rt4nyp, who discovered the vulnerability, every time an Imgur image was loaded on the /r/4chan sub-reddit, over 500 other images were also loaded in the background, images hosted on 4chan’s CDN. Since traffic on 4chan is quite huge as is, getting some extra connections from Reddit pushed 4chan’s servers over the edge, crashing them several times during the day. Additionally, 8chan, a smaller 4chan spin-off, was also affected and suffered some downtime as well. Malicious code was being loaded with Imgur images Reddit user rt4ny was alerted that something was amiss when he noticed that Imgur images on Reddit were loaded as inlined base64 data. Taking a closer look at the base64 code, he observed that a small piece of JavaScript code was added at the end, which had no business being there. This code secretly stored the “axni” variable in the browser’s localStorage, which was set to load another JavaScript file from “4cdns.org/pm.js.” This is not 4chan’s official CDN, but a domain registered to closely resemble the real deal, which was taken down in the meantime. When refreshing the original image that loaded the “axni” variable, the malicious code would not be loaded again, a measure taken to avoid detection. Additionally, also to avoid detection, the JS file stored on “4cdns.org/pm.js” could not be loaded directly in the browser. Loading 500+ 4chan images inside a hidden iframe Analyzing the pm.js file, rt4ny found that it loaded an iframe outside the user’s view with the help of some clever CSS off-screen positioning tricks, inside which the hundreds of 4chan images were being loaded, along with a 142 KB SWF file. Imgur was contacted about this issue, and fixed it on the same day. “Yesterday a vulnerability was discovered that made it possible to inject malicious code into an image link on Imgur,” said the Imgur team. “From our team’s analysis, it appears the exploit was targeted specifically to users of 4chan and 8chan via images shared to a specific sub-reddit on Reddit.com using Imgur’s image hosting and sharing tools.” It’s a sad day for humanity when we see hackers combine the three best sites on the Internet to find cat GIFs into such wicked and immoral ways. Source: http://news.softpedia.com/news/hackers-used-imgur-to-launch-ddos-attacks-on-4chan-492433.shtml

See the original post:
Hackers Used Imgur to Launch DDoS Attacks on 4chan

The rise of repeated "low and slow" DDoS attacks

There's been a significant change in the nature of DDoS attacks that is leaving businesses exposed to data breaches and malware. Recent research from Neustar shines a light on the changing tactics …

See the original post:
The rise of repeated "low and slow" DDoS attacks

Aggressive tactics from DD4BC extortionist group revealed

Akamai shared details of an increase in DDoS attacks from the Bitcoin extortionist group DD4BC, based on observation of attack traffic targeted at customers from September 2014 through August 2015. …

Continued here:
Aggressive tactics from DD4BC extortionist group revealed

3l33t haxxors don’t need no botnet, they just pinch passwords

Crooks can thrive by ‘living off the land’ rather than forging elaborate schemes Half of all breaches Dell’s SecureWorks outfit has responded to over the last year have been a result of attackers using legitimate admin tools and stolen credentials.…

Link:
3l33t haxxors don’t need no botnet, they just pinch passwords

Bored Brazilian skiddie claims DDoS against Essex Police

‘I will do 19 years’ attacker says in garbled English – perhaps accidentally right A teenager from Brazil has claimed responsibility for a distributed denial of service (DDoS) attack on Essex Police’s website, following a similar attack on another force earlier this week.…

See the article here:
Bored Brazilian skiddie claims DDoS against Essex Police

NBN vaults Australia into global top-10 … DDoS attack sources

Or not, if you look at the numbers Australia has won the dubious honour of being named in the global top-10 DDoS sources, and in its quarterly State of the Internet report, Akamai reckons our tiny number of high-speed fibre broadband users are the cause.…

Visit link:
NBN vaults Australia into global top-10 … DDoS attack sources