Showing posts with label dos. Show all posts
Showing posts with label dos. Show all posts

Saturday, 8 August 2009

DoS/DDoS news resources

Considering the hype about DoS and DDoS in the last days as consequence of attacks to Twitter, Facebook and LiveJournal I decided to include some of my information sources in this blog. I did some redesign of the right bar. I included some DoS and DDoS news, they are a set of news manually selected by me. I take the news from different sources and I apply some basic filtering and data-mining I come with them. They can be also accessed here if you want to include them in your RSS reader.

"Security news from Twitter" are posts about DoS/DDoS attacks collected from twitter. This is a little bit noisy with around 30-50 posts per day. Some of the posts are repeated or uninterested (from my perspective) but it works as a source for my tools that extract some information for them. The raw feeds are here and here.

Finally I included some general IT security news from twittsecurity. Twittsecurity is a bot that shares security news in Twitter. It searches and selects IT security news using a hybrid method (automatic and human assisted). Feel free to follow it.

Monday, 16 March 2009

The BBC, the botnet and other DDoS attacks


No doubt that the most commented DDoS news of the week were related to the botnet that the BBC hired. In fact it was the staff of one of its programs called Click. The program's goal was to demonstrate how easy it is to hire a botnet to perform criminal activities. The botnet was used to send SPAM to a especially set account and to launch a DDoS attack to security company website's specifically set for this purpose. Although the ethics of the action has been critiqued, the fact is that they have demonstrated how easy and cheap it is to hire such services.

In other news, Jose Nazario of Arbor Networks in hiss presentation at SOURCE Boston commented about the new "trends" in cyber crime. Nazario said that cyber criminals are not just selling kits for running malicious software on unprotected computers. Now they sell services for script-kiddies and criminals who are just not good enough to use the malware by themselves. The audio of the presentation here.

The DDoS attack to the torrent site Mininova continued during this week. Here you can see some trends in traffic that the attacks have generated.

Sunday, 8 March 2009

DDoS in March

To the surprise of some, the Pirate Bay website was under a DDoS attack earlier this week. Still no news about the intellectual authors. The site is stable for now.

According to an analysis of the anti-virus firm Sophos, the worm Confiker could start a DDoS attack to some sites, including Soutwest Airlines. The collateral damage would be a DoS due to the spread of the worm. The note on TechRepublic.

And the torrent's site Minova has been attacked by a DDoS. According to TorrentFreak the attack has reached the 2 Gbps peak. It seems to come from bot networks that appear to be in Germany and Argentina.

Tuesday, 10 February 2009

Feed Analysis

Well, this is post is more a plead for help than a real post.

I need to analyse a RSS feed that I have been generating by searching for twitts related to DoS and DDoS attacks. In order to do it soon and with not so much effort I would like to avoid programming something (may be using feed parser or XML_RSS). What I would like to do is:

  1. Get the average post per day, week and month
  2. Get the average for a specific week and month
  3. Get the all items for a specific date
  4. If possible, to graph the number of items by day, week and month

If somebody knows a webservice to do that, please let me know to my e-mail, by a comment here or just send me a twitt. I would really appreciate!

Wednesday, 10 December 2008

Le Monde (the translated version here) reports that the web site of the French Embassy  in China has been inaccessible for a few days. The cause is an apparently DDoS. The attack seems to be a consequence of the political tensions between China and France as result of the meeting of the french president Sarkozy with the Dalai Lama in Poland.


This is another case of the infamous cyber-war.

 

Tuesday, 4 November 2008

New DoS and DDoS coming?


  The SANS Internet Storm Center reports that some worms exploiting the new Microsoft RPC vulnerability (MS08-067) are been seen on the wild. As I wrote before (here for the automatic translation by Google) this is critical vulnerability from the same family that brought us worms as Blaster

Fortunately as mentioned by Steve Gibson in Security Now the Internet has changed a lot from those past experiences. Today most Windows XP (with SP2) and Windows Vista hosts have the firewall on by default that minimizes the risk of infection. However many Windows 2000, 98 and 95 computers, most of them forgotten in some computer room are still in a high risk. I wonder if this will be another endemic disease that will be living in the Internet as their cousins.

Here there is the report from F-Secure for the interested people. And, wait for at least some minor disruptions generated by compromised machines.

Wednesday, 4 June 2008

DoS video with captions

Well, I started to play with the new YouTube feature to add captions to your video. I think that my video of the DoS attack simulation is better explained with captions. This is the same video that I have used in some of my research work and paper presentations.

I do not why but the embedded video did not show the captions, so the link is here.

Friday, 30 May 2008

Revision 3 Under DDoS by ... MediaDefender

This has been around the twitter world and it is funny and serious. Some days ago Revision 3, a new media company that distribute their content via Internet was under a DDoS attack. They just released in their blog that the attack came by no other than MediaDefender. MediaDefender is a dark company paid by content distributors in order to disrupt, hack and to do other non ethical activities with the flag of "Anti-piracy". It results that Revision 3 uses bittorrent, a very common P2P tool to distribute ITS OWN content.

Many questions raise with these actions. What was Mediadefense doing against Revision3? Are legal their actions? What are the MediaDefender's criteria to "disrupt" torrent sources?

I honestly hope that Revision 3 take some legal action against this attack. I think that is enough with the danger that website owners face today with attacks from botnets, it is not good to add more attack sources such as this type of companies.