2017’s 5 Most Dangerous DDoS Attacks & How to Mitigate Them (Part1)

By Carl Herberger


Throughout the history of mankind, whether in warfare or crime, the advantage has swung between offense and defense, with new technologies and innovative tactics displacing old doctrines and plans. For example, the defensive advantage of the Greek phalanx was eventually outmaneuvered by the Roman legion. Later, improvements in fortifications and armor led to castles and ironclad knights, until the invention of gunpowder made them obsolete. In the 20th century, fixed fortifications and trenches were rendered outdated by highly mobile armored forces. In all these examples, the common denominator is that one side’s tactical advantage spawned new ways of thinking among its opponents, eventually degrading that advantage or reversing it completely.

Enter the digital age, where lines of code and terabytes of information determine who has the tactical advantage. Of late, the pendulum has swung in favor of cyber-attacks. Rate-based technologies, once considered adequate to handle the most advanced distributed denial-of-service (DDoS) threats, have fallen obsolete as tech-savvy adversaries move beyond the static concepts of most conservative corporate budgets and know how to overcome name-brand mitigation technologies. These ultra-adaptive hackers have given rise to the top five nastiest attack techniques in 2017.

ATTACK TYPE #1:  Advanced Persistent DoS (APDoS):


Wikipedia defines APDoS as:


“…a clear and emerging threat needing specialized monitoring and incident response services and the defensive capabilities of specialized DDoS mitigation service providers. This type of attack involves massive network layer DDoS attacks through to focused application layer (HTTP) floods, followed by repeated (at varying intervals) SQLI and XSS attacks. Typically, the perpetrators can simultaneously use between 2 to 5 attack vectors involving up to several tens of millions of requests per second, often accompanied by large SYN floods that can not only attack the victim but also any service provider implementing any sort of managed DDoS mitigation capability. These attacks can persist for several weeks.”


It becomes clear that APDoS requires an array of technologies to stop the network floods, HTTP application-level DDoS and encrypted threats. Moreover, Radware is witnessing these attack techniques manifest into SMTP attacks (a relatively new vector) and secure-SMTP such as TLS over SMTP.


APDoS attacks assume many forms, but typically attackers will switch tactically between several targets to create a diversion to fool mitigation tools, all the while eventually concentrating the main thrust of the attack onto a single victim. To successfully mitigate these threats, organizations must understand the threat and make certain it has certain protections in place (e.g. high caliber detection and mitigation). To start, characterize APDoS threats into the following classes:


 “Advanced reconnaissance (pre-attack OSINT and extensive decoyed scanning crafted to evade detection over long periods)


Tactical execution (attack with a primary and secondary victims but focus is on primary)


Explicit motivation (a calculated end game/goal target)


Large computing capacity (access to substantial computer power and network bandwidth resources)


Simultaneous multi-threaded ISO layer attacks (sophisticated tools operating at layers 3 through 7)


Persistence over extended periods (utilizing all the above into a concerted, well managed attack across a range of targets)”


The task is daunting and real. As the next generation of DDoS threats emerge, organizations must be diligent and proactive. Companies must rise above the normal corporate culture of security controls and become obsessive about removing risks and compulsive about action. After all, these organizations may literally be holding life and death decisions in their hands – and this makes their actions rather profound and very unique.


ATTACK TYPE #2: DNS Water Torture Attack


A DNS NXDOMAIN flood attack, which is also known as a water torture attack, targets an organization’s DNS servers. This type of attack involves a flood of maliciously crafted, DNS lookup requests. Intermediate resolvers also experience delays and timeouts while waiting for the end target’s authoritative name server to respond to the requests. These requests consume network, bandwidth and storage resources. They can also tie up network connections, causing timeouts.


By understanding the threat, an organization can comprehend two of the largest problems in solving this attack vector:


First: The attacker is coming from a known legitimate source and can’t realistically be blocked while still maintain healthy DNS resolution operations over the long term


Second: The attacker source is actually also querying legitimate requests at the same time illegitimate requests are being sent.


To counter this resource-draining threat, organizations should monitor their recursive DNS servers, keeping a keen eye for anomalous behavior such as spikes in the number of unique sub-domains being queried or spikes in the number of timeouts or delayed responses from a given name server.


Any DNS attack mitigation tool must meet unique challenges. Beyond a limited set of vendors, there is no real automated solution to mitigate this threat, as the tool must contain the following attributes:


Mitigation tools must have deep knowledge of DNS traffic behavior – The tool must understand DNS traffic and “learn” or establish baseline behaviors continuously to immediately identify abnormal DNS traffic. Moreover, the tool or technique must analyze every field in DNS traffic to identify abnormal packets and to create real time signatures.


Mitigating high rate of DNS packets – The tool must be able to challenge large amounts of DNS queries per second and to process up to – often in larger circuits – 10- 35 million packets per second of attack traffic. The attack traffic does not affect legitimate traffic while under attack.


Mitigation accuracy – With unique DNS challenges and accurate analyzing of DNS traffic behavior, an organization must be able to accurately distinguish between legitimate DNS traffic and attack-based DNS traffic to minimize false positives. This enables the service provider to continue and serve its legitimate users even under severe attack.


Provide best quality of experience even under attack – Obviously the idea of operating a service is that you must have an architecture that can guarantee minimum latency to all processed traffic, and especially to the legitimate traffic. This guarantees a best quality of experience to legitimate internet users even under attack.


Source:  radwareblog 


Up to 44 million UK consumers may have had their identity put at risk after Equifax hack



By now, you’ve no doubt read the news stories about the massive data breach at credit-reporting service Equifax which has put 143 million US customers at risk of identity theft.

Hackers stole personally identifiable data including social security numbers, dates of birth, addresses, and driving license information – alongside (in the case of some 209,000 consumers) credit card information.

But you would be wrong to think that it is only consumers in the United States who are at risk because of the breach.

Equifax has admitted that it also “identified unauthorized access to limited personal information for certain UK and Canadian residents.”

What Equifax doesn’t say in its advisory is just how many UK and Canadian citizens might be at risk, but a report from The Telegraph puts the number of potential British victims at 44 million.

Considering that the estimated population of the UK (including children who I would argue are less likely to be being having their credit rating checked) is about 65 million, that’s a frankly catastrophic figure.

And don’t imagine for a second that because you may have never heard of Equifax, or done no business with them, that you have somehow escaped from being affected by this breach. Many companies in the UK use Equifax’s credit-cehcking services when deciding if they want to take you on as a customer or not.

In short, you may never have had any direct dealings with Equifax, but they may still have had your personal data – and it may now be in the hands of hackers.

Things only get worse when you recognise just what it means to have key personal data such as names, dates of birth, and social security numbers (although these aren’t used in the UK) are exposed.

If, say, your password is exposed through a website breach you can always change your password. But try changing your date of birth, or your name… you’re stuck with them for life.

Identity thieves can use personal information such as dates of birth, names, addresses and social security numbers to fraudulently open accounts, take out loans and credit cards, or even buy a house… all without you knowing, and yet it’s you ultimately which might find yourself with a damaged credit rating as a result.

It’s no wonder, as The Telegraph quotes, that the likes of BT are keeping a close eye on the developing story:


“We are aware of the developing story and are monitoring the situation closely. Like many companies in the UK, BT uses Equifax services. We are working on establishing whether this breach has any impact on those services.”




In many ways I’m reminded of how T-Mobile’s CEO was unable to disguise his anger when Experian, a company tasked with credit-checking the phone company’s users, suffered its own data breach exposing social security numbers and other personal information two years ago.

You can’t help but feel some sympathy for the companies which placed their trust in Equifax, believing that the firm would take proper care of consumers’ information.

But most of all I feel sorry for the many millions of consumers who are currently utterly oblivious that their identities are at risk, and the potential problems they might face in the future.


Source:Hotforsecurity


Unpatched D-Link Router Vulnerabilities Disclosed

A researcher has disclosed the details of several unpatched vulnerabilities affecting D-Link DIR-850L routers and mydlink cloud services.

Researcher Pierre Kim has decided to make his findings public without giving D-Link time to release fixes due to the way the company handled patching and coordination for previously reported vulnerabilities.

“Their previous lack of consideration about security made me publish this research without coordinated disclosure,” Kim explained.

The expert discovered in mid-June that both revisions A and B of the DIR-850L firmware lack proper protection. The former allows an attacker to easily forge a firmware image, while the latter is protected with a hardcoded password.

He also found several cross-site scripting (XSS) vulnerabilities that can be exploited to steal authentication cookies from logged-in users. Hackers could also exploit various flaws to change a router’s DNS settings and forward the victim’s traffic to a malicious server, cause some services to enter a denial-of-service (DoS) condition, and execute arbitrary commands as root via the DHCP client.

Vulnerabilities identified by Kim in the mydlink cloud service, which allows users to access their D-Link devices from anywhere over the Internet, can be exploited by an unauthenticated hacker to remotely associate a targeted device with their own mydlink account, obtain device passwords -- which are in many cases stored or transmitted in clear text -- and take complete control of the router.

Kim believes the vulnerabilities related to the cloud service could also affect other D-Link products, including network-attached storage (NAS) devices and cameras. The expert has published detailed technical information for each of the security holes he found.

Securityweek has reached out to D-Link for comment and will update this article if the company responds.

D-Link recently patched three vulnerabilities found in DIR-850L routers by Kim and two other researchers as part of a hacking competition called Hack2Win. The flaws disclosed this week by the expert were not submitted to the contest, which only covered revision A of the router firmware.


Source:  security week 


Researchers discover Remote Code Execution vulnerability in Apache Struts 2

Security researchers just detected yet another major vulnerability in Apache Struts 2[1]. The detected security flaw allows hackers to perform a remote code execution[2], which is probably the most dangerous vulnerability that can be detected in software.

Apache Struts 2 is an open-source framework designed to develop web applications using Java programming languages. The framework is extremely popular, which means that many apps created using it are vulnerable.

According to researchers from lgtm (they were the ones who discovered the vulnerability), all Struts versions starting from 2008 contain this security flaw. The same can be said about every web application that uses Apache Strut 2 framework’s REST plugin.

The code of this vulnerability is CVE-2017-9805[3]. According to the researchers who made the discovery, it gives an attacker a possibility to execute any code on the target server remotely. The criminal simply needs to send a criminal XML code in a particular form to enable the vulnerability on the destination server.

The only condition is that the server has to run an app created using Apache Struts framework and REST plugin. The plugin uses XStream for deserialization and doesn’t use any kind of filtering, which can possibly lead to Remote Code Execution when deserializing malicious XML scripts.

As a result, the hacker might get full access to the server and infiltrate other computers on the same network.

Apache Struts vulnerabilities can be used to infect servers with ransomware

Vulnerabilities in Apache Struts 2 is something that excites cyber criminals. In the past, flaws in this popular web application framework were exploited by Cerber virus’ distributors, allowing to inject the malicious virus to servers and encrypt all files on them.

Cerber developers were quick to exploit the CVE-2017-5638 vulnerability in Apache Struts to deliver ransomware to servers. They started operating soon after the release of patch and proof-of-concept exploit. Researchers noticed first attacks at the end of March 2017.

The criminals reportedly leveraged the vulnerability to execute shell commands on the target servers. Besides, they ran BITSAdmin and several other command-line utilities. As a result, Cerber ransomware was downloaded and executed on target systems.

Beware that Arena and Lukitus viruses are on a rise nowadays, so their distributors might attempt to leverage the vulnerability, says NoVirus.uk experts.

Upgrade to the new version to secure your system

Researchers who discovered the flaw immediatelly reached out to the Apache Software Foundation and reported the issue. Shortly after, the company released 2.5.13 version of Apache Struts that contains a patch for the described Remote Code Execution vulnerability.

The only solution to the specified problem is to upgrade to Apache Struts version 2.5.13. There is no workaround available, so rush to upgrade their AS2 installations.

Source:  2-spyware 


Cyber security expert issues bizarre warning that sex robots could be easily hacked and made to KILL their owners

Elon Musk has previously claimed that artificial intelligence could take over the planet, and he's not the only one concerned about the dangers of killer tech.


Last month, tech billionaire Elon Musk claimed that artificial intelligence could take over the planet, and he’s not the only one concerned about the dangers of killer tech.

With sex robots becoming increasingly popular and sophisticated, Cyber security lecturer Dr Nick Patterson revealed that the lifelike dolls could end up going all Terminator on us.


However, in the case of sex robots, the danger isn’t that the love dolls will end up developing minds of their own, Westworld-style.


Instead, the risk is that hackers could breach the realistic robots‘ inner defences and catch out their owners with their pants down.


Dr Patterson told Star Online that hacking into many modern-day robots, including sexbots, would be a piece of cake compared to more sophisticated gadgets like mobiles and computers.


The tech expert, from Deakin University, Australia, said: “Hackers can hack into a robot or a robotic device and have full control of the connections, arms, legs and other attached tools like in some cases knives or welding devices.


“Once a robot is hacked, the hacker has full control and can issue instructions to the robot.”


The warning may sound a little far fetched, but the robots run using an operating system just like a phone or PC.


And as with all devices, if that system is ever connected to the internet, then it becomes possible for hackers to break in to it.


The cyber defence guru added: “The last thing you want is for a hacker to have control over one of these robots.


“Once hacked they could absolutely be used to perform physical actions for an advantageous scenario or to cause damage.”


Previously, the Sun Online exclusively revealed that the sexbots could actually end up SAVING people’s lives, according to one of the companies behind the AI-lovers.


We also exclusively told how wars of the future could be fought with man-made robotic viruses which turn people into zombies.


Source:  The Sun Uk 


Smartphones Under Fire: Why We Need to Keep Our Android Devices Safe

If there’s one thing we know about cybercrimnals it’s that where there’s people and money, they will surely follow. With an estimated 1.4 billion Android devices in use today, it’s not hard to see why they might have your smartphone in their sights.

Attacks on Android devices made up 81 percent of mobile attacks last year, as infections reached an all-time-high of 1.35 percent of all devices in October, according to Nokia. Why should we care? Because increasingly we live our digital lives through our mobile devices. If they get hit by the bad guys, it could end up costing us dear.

With smartphone attacks surging 400 percent in 2016, there’s no time to lose.

Android threats are growing

Traditionally, it’s always been fairly easy for developers to upload their apps to Google’s official Play store or the numerous third-party app marketplaces around the world. However, this openness can be problematic for security. Although Google is getting better at vetting apps for potentially malicious content, and removing those that sneak through as soon as it is informed, there’s still a risk that what you choose and install could have malware on it.

Most recently, researchers discovered over 1000 apps infected with SonicSpy, Android malware designed to hijack an infected device to spy on its user, or else make calls and send texts to premium rate numbers. At least three versions found their way onto Google Play. Other examples of recent Android malware include GhostCRL, which allows hackers to remotely control a device; and MilkyDoor, which had up to a million installs on Google Play.

Patching – installing the latest security updates – is one of the easiest things you can do to a PC or mobile device to lower your chances of getting infected by malware. But with the open Android ecosystem there can be issues with patches produced by Google not being implemented by the individual device makers and carriers. Google claimed in its latest Android Security Year in Reviewreport that just half of all Android devices were patched in 2016. Although an improvement on previous years, this figure is way lower than it needs to be.  In fact, less than 3 percent of users are running the latest, most secure OS version.


What’s at stake?

There could be a high price to pay. Hackers know we do everything from check our emails and social media pages, buy goods, watch videos, text our friends and do online banking on our smartphones. That makes the mobile device a prime target for malware and social engineering scams designed to steal or trick us into handing over our log-ins and financial information.

To part us from our hard-earned cash, hackers have developed a range of tools and tactics including banking Trojans, ransomware, spyware, phishing, and premium rate SMS malware.

Threats can come from a variety of places. It might be that unsecured public Wi-Fi hotspot you’ve just logged onto. Or that app you’ve just installed that isn’t what it seemed. It could be hidden in an email attachment or a link in an unsolicited SMS, IM, or social media post. It might even be lurking in a malicious advert on an otherwise legitimate-looking website.

What’s more, if you use the same device to connect to the corporate network at work, you’ll risk spreading any malware infection to the workplace.

Consider too, that many types of undesirable processes on your mobile device can go unnoticed. Big attacks, like ransomware and malware, are obvious, but apps and websites that leak private data, or track more than you want them to, are much more common. Undesirable behaviors, and their negative side-effects, can be so insidious you might never notice them.

Staying safe

One of the reasons mobile threats are so insidious is that we tend to spend less time when we’re on the move considering our actions. When we’re browsing, getting email, using social networks, or texting on our smartphones we’re usually distracted and in a hurry. That makes it easier for the bad guys to trick us into a misplaced click. So, what can we do to stay safe on our mobile devices?

Here’s a few ideas on where to start:

Only use the official Google Play store to download apps

Always ensure your device’s OS is on the latest version

Don’t reveal any sensitive info via things like online banking or checking emails when logged in on public Wi-Fi

Don’t click on links or open attachments in unsolicited emails, social media posts, IMs, SMS messages

Set a screen lock so no one can access the device if it’s lost or stolen

Download security software from a reputable provider to the device. Trend Micro Mobile Security for Android safeguards against malicious apps, fraudulent websites, data theft, unsecured Wi-Fi, dangerous links, and device loss.

With the right tools to hand and a clear head, we can all benefit from the freedom and fun our smartphones provide whilst protecting our digital lives from online threats

By Michael Miley
Source:  Trendmicro 


Protect Your Privacy with Webcam Protection - Bitdefender







Today’s smart home is defined by the number of smart and internet-connected devices that work either together or individually to allow users to remotely control or automate various features for efficiency or convenience. The number of IoT devices per household has increased significantly over the past couple of years, reaching an estimated 11 smart devices/accessories per home, according to a Bitdefender survey*.


With the proliferation of smart things, security concerns have risen as security researchers have often found IoT devices lacking in even basic security to protect user privacy and data. The number of smart devices per households has reached 11 in the United States and Germany, 10 in France, and 9 in the UK.

Since in the United States most smart device users are concerned that their identity can be stolen (58%), that sensitive information can be obtained (56%) and that the devices can be infected with viruses (55%), 7 out of 10 users have at least one camera connected to the Internet.


Internet connected cameras have often been found vulnerable and remotely controllable by attackers. Since they usually share a network with other household internet-connected devices, they can be used as gateways to launch attacks on other network devices or even compromise the entire home network.


However, these are not the only devices sporting a camera that can be used to spy on users. The top 3 US smart devices with a camera that’s connected to the Internet are smartphone (51%), laptops with windows (27%), and tablets (25%), yet only 3 out of 10 users of smart devices are concerned that someone could gain access to the devices’ camera and that they can be recorded without their knowledge.

Smart TVs are also web-camera-enabled and 6 out of 10 Smart TV users don’t have a security solution for this device. What’s more, 35 percent of the Smart TV users installed additional software/ apps on the Smart TV, 30 percent of which installed apps from other places / stores / websites than official ones. The same study concluded that half of smart TV owners have never changed the password on their device and 55 percent of respondents also said they did not perform a firmware update on their device.


Remembering that not only smartphones and laptops have web cameras that are connected to the internet, users also have to be wary of their privacy when other IoT devices sport such features. Smart TVs and IP cameras are often poorly secured, have default passwords, or are never updated with the latest firmware, making them viable targets for cybercriminals.


From a laptop or smart phone perspective, making sure that only legitimate applications have access to the device’s web camera is vital, as rogue software may try to spy on you. Cybercriminals will often use such private footage to extort favors – financial or otherwise – from their victims, threatening public shaming if their demands are not meant.


Something as innocent as a web camera can be used by cybercriminals against you, and it’s up to you to make sure that any web-camera-enabled device in your household is protected, so that your private life remains private.


Bitdefender’s Webcam Protection feature identifies if your PC’s or laptop’s camera is misused or abused by illegitimate applications and will protect users from cybercriminals and cyber-stalkers trying to invade their privacy.


For those that don’t have the new Bitdefender 2018, but still want to protect their privacy, unplugging the camera or manually shutting it down is always an option, provided it’s an external webcam. Physically covering the lens with tape or a specially designed webcam cover will keep Peeping Toms away, but that doesn’t mean they can’t eavesdrop.


*Note: The study consisted of a survey performed by iSense Solutions at Bitdefender’s request during April 2017, and it’s based on based on 1000 interviews. The sample used in this report is representative for the Smart device users, with WI-FI connection in USA (at age, gender and region level), 18+ y.o.. Error degree is +/-3. 1% at a confidence interval of 95%.





Source:  hotforsecueity by Bitdefender 


Intel Tiger Lake CPUs to come with Anti-Malware Protection

Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...