RiskIQ partners with DataComm360 to accelerate a... » London: RiskIQ has announced that it has selected DataComm360 to be their distributor in the Middle ... Flexera Software launches AdminStudio Suite 2016... » Maidenhead, U.K.: Flexera Software has announced the latest release of AdminStudio Suite, the indust... ARMED FORCES DAY CELEBRATED ACROSS THE COUNTRY » Celebrations are underway today to mark the eighth annual Armed Forces Day, honouring the work and d... Wireless security skills need to prepare for the I... » The proliferation of new Wireless communication technologies within consumer electronics and smart d... Opengear achieves Cisco Compatibility Certificatio... » Sandy, Utah: Opengear has announced that its Resilience Gateway has successfully achieved Cisco comp... Brexit: “The vote in favor of Brexit has been a re... » Executive director of War on Want, Hilary is author of the book The Poverty of Capitalism: Economic ... OF FOOLS OF THE MIDDLE BELT, ONE NORTH AND PASTO... » PART ONE Protesters against cultural imperialism in Nigeria. A treatise on pastoral jihadism, is... Databarracks recognised for second consecutiv... » London-based provider Databarracks has been recognised in Gartner’s June 2016 Magic Quadrant for Dis... INSURERS OFFER BETTER DEAL FOR ARMED FORCES PERS... » Armed Forces personnel posted overseas will from today (Saturday 25 June) be able to keep their moto... Qognify wins Government Security News’ 2016 Airpor... » Qognify, formerly NICE Security has announced that it has been awarded three Government Security New...

CLICK HERE TO

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to Vigilance Weekly

Information Security Header

Following on from the DDos attacks on US Banks, Imperva have posted up an interesting blog which shows the origins of these attacks which have stemmed from malware being planted into webservers.

 

Please see link below:

http://blog.imperva.com/2013/03/itsoknoproblemo-eyes-wide-shut.html

Itsoknoproblemo, Eyes wide shut.

In January, Incapsula released analysis showing how infected webservers were being used in order to elevate broader attacks, such as DDoS campaigns, which we have recently witnessed targeting the banking industry.

Today, ThreatPost released an article discussing the recent rise of DDoS against US Banks. Some banks were reported to suffer service disruption ( via sitedown). This follows a warning issued by the Qassam Cyber Fighters hacktivist group, claiming it will disrupt US Banks operations as part of “Operation Ababil.”

Denial of Service (DoS) attacks are technical attacks that are focused on consuming the resources of a server/service, which prevents it from serving more legitimate users of that specific service. This is done either by consuming the available network bandwidth, or in the application age, by consuming the actual application resources. These attacks usually require many machines addressing the service in the same time to generate the load.

The Web Threat Angle

In the industrialized hacking age, where Hactivism has become talk of the day, hackers build botnets in order to coordinate such an attack from many computers. One of the easiest ways to build a botnet is through “Waterhole” websites, which are popular websites infected with malware that infect the host, which becomes a zombie in the botnet, waiting for instructions to generate targeted traffic upon demand. The recent NBC malware infection attack is a great example of the use of Waterhole websites to infect the masses

Now we are seeing itsoknoproblemo, which is one of the tools most used in the recent DDoS attacks against the US Banking industry, some peaking at 70 Gbps.

This tool is distributed mostly via a Remote File Inclusion (RFI) attack, creating a drive-by download vector for users that hit the infected web pages, and then become zombies. An RFI attack allows you to plant/redirect users to malicious code just by going on the website.

What does this teach us?

There are two problems that need to be dealt with here. One is the problem that the banks now deal with: the DDoS attacks themselves. The other is the infection vector of the malware via webservers.

 

The RFI vulnerability is the starting point that allows hackers to build the bot-net that eventually generates the DDoS attack.

 

Since alongside spear-phishing, it enables one of the biggest ways for hackers to send malware and DDoS-specific malware to users.

 

Interestingly enough, companies protected by Web Application Firewalls are capable of protecting themselves against RFI attacks and from the follow-up of distributing malware. And even though they do not suffer from the DDoS attack itself, the malware distribution creates the reputation damage that companies fear