Black Lotus delivers award winning DDoS protection ranging from full network defense to website and server protection, 24/7/365. Learn more by visiting http://www.blacklotus.net or call (866) 477-5554.

Browsing "Older Posts"

Browsing Category "Articles"
According to a study reported by Computer Weekly, the threat of distributed denial of service (DDoS) is growing. Specifically, between Q4 2013 and Q1 2014, the average bandwidth peak of volumetric attacks was 114% higher. The results of the report agree in spirit with the findings of Black Lotus’s Q1 2014 Threat Report.

In some cases, standard infection methods were sidelined in favor of reflection attacks, a subcategory of denial of service called distributed reflection denial of service (DrDoS). Malicious parties are able to generate more damaging campaigns by using reflection. As a result, those behind many of the first quarter’s most powerful DDoS attacks – including the #1 hit – used reflection rather than standard botnet infection tactics.

DrDoS involves sending spoofed requests to vulnerable servers around the world, which in turn send an amplified response back to the spoofed source, easily knocking it offline or even saturating upstream carrier networks. This increasingly popular reflection tactic takes advantage of bugs in Internet protocols to perform profoundly devastating damage.

Three protocols that have been widely used for these types of attacks are Domain Name System (DNS), Character Generator (CHARGEN), and Network Time Protocol (NTP). All of those protocols are forms of User Datagram Protocol (UDP), the design of which makes it easy to trick servers into responding to the victim rather than the attacker who originated the malicious requests.

Amplification attacks are gaining traction because the strength of the attack is boosted: data can be delivered to a target at a high volume, an amplification factor as high as x400, while the device or devices used in the effort do not have to generate the same amount of information. This means that an attacker with 100 Mbps of bandwidth could generate an attack as large as 40 Gbps.

Amplification and reflection techniques themselves had an average bandwidth increase of 39% vs. Q4 2013. The first quarter also logged the highest volume DDoS incident ever.

Core projections and statistics  from our first quarter threat report


As stated above, the findings of our Q1 2014 Threat Report – along with the projections for the near future based on the report’s findings – present a similarly challenging DDoS landscape for the Internet community. Exploits of the NTP protocol that became widespread in the first two months of the year have been thwarted by a broad and coordinated security response. However, we project that within the next 12 to 18 months, reflection attacks will become increasingly massive, with DrDoS threats potentially exceeding 800 Gbps in volume.

Within the first three months of 2014, the Black Lotus network mitigated the highest volume attack that has ever been perpetrated. That attack crescendoed on February 10, measuring 421 Gbps and 122 Mpps (millions of packets per second) at its height. The bit volume from the previous day, February 9, was similarly grandiose but did not quite match the massive scale of February 10.

Although these huge attacks will remain a significant concern just due to their horrific scope, they are many times larger than the typical DDoS assault. Our analysis found that the average bit volume and packet volume for the first quarter were 2.7 Gbps and 1.8 Mpps, respectively.

By comparison, the largest DrDoS attack observed in Q1 2014 was 156 times larger than average, which was derived from a sizable sample pool: 462,621 attacks, equivalent to 5140 attacks per day, 214 per hour, or 4 per minute.

Attacks of less than 3 Gbps might appear unintimidating to large enterprises; however, organizations that have smaller networks and/or may not have the capital to overprovision are often threatened by assaults of that scope.

The size of the average attack is similar to what our network experienced during the last quarter of 2013. Based on the 6-month period as a whole, the data suggests that a company’s DDoS mitigation protections should be established at a bare minimum of 5 Gbps.

Many service providers defend their networks up to 10 Gbps. As we know from this quarter, that level will protect against attacks of the average size but not against the many high-octane barrages that networks are experiencing more commonly worldwide.

The attacks on February 9 and 10 – with the latter achieving the strongest bit level as mentioned above – targeted a weakness in NTP daemons, as addressed by Black Lotus in our January 8 Threat Advisory. So that Black Lotus customers would be safeguarded against this form of attack, NTP defenses were implemented for all clients, regardless of subscription level.

As Vann Abernethy mentions in a piece for Wired, security organizations have estimated that there have been as many as 400,000 NTP servers that are susceptible to exploitation in the commission of DrDoS attacks. As many as 1000 of those servers could amplify data as much as 700 times, an amplification factor many times greater than the domain name system (DNS) DrDoS which targeted anti-spam organization Spamhaus.

 

The changing landscape


NTP reflection attacks have received significant attention during the first quarter because the bit volume was so massive. However, the majority of severe attacks –  primarily HTTP GET and SYN floods – targeted servers and applications. In other words, traditional, tried-and-true methods are still incredibly popular, despite the new threat of NTP amplification. For further analysis, see our Q1 2014 Threat Report.

By Kent Roberts


Study: DDoS Attacks Growing Stronger in 2014

By Unknown → Wednesday, June 11, 2014

Some of the largest, well-known, and important DDoS attacks ever carried out


Although distributed denial of service (DDoS) attacks happen all the time, we tend to only hear about the absolute largest ones. These attacks receive mainstream, global press attention either because the sites they have targeted are incredibly massive and have a large cultural footprint, because of the sheer amount of data transmitted in the attack, or a combination of the two. DDoS attacks have been not only growing in rate of occurrence, but also in sophistication and size, so this list is unfortunately bound to look different a year from now (or possibly even a week from now). But let’s take a look at a handful of the most notable attacks in recent memory, which are important either because of their size or the visibility/cultural importance of the target.

Spamhaus vs. Cyber Bunker (“Operation Stophaus”)

Known by many as “The DDoS Attack That Almost Broke The Internet”, the attack that took down Spamhaus in Spring of 2013 was truly massive. Spamhaus is an email filtering company that as its name might suggest, stops SPAM email from ever entering millions of inboxes around the world. They keep track of where these SPAM messages originate from and noticed that many were coming from a Dutch hosting company called Cyber Bunker. When Spamhaus inquired to Cyber Bunker about the SPAM and other baddies that were seemingly originating from them, they responded bombastically and claimed they were an independent nation that isn’t under the jurisdiction of Spamhaus or anyone else. Spamhaus acted accordingly and essentially worked with Cyber Bunker’s providers to sever their connections. Cyber Bunker responded by launching a huge DDoS attack, that at its peak, was funneling 300 Gbps to Spamhaus’ site. One of the largest DDoS attacks on record prior to the Spamhaus attack was around 100 gigabytes per second, to put it into perspective.

The Church of Scientology vs. Anonymous

The DDoS that was launched and carried out against the Church of Scientology’s website pales in comparison to the Spamhaus attack, but it’s important for putting the hacktivist collective known as Anonymous on the map and ensconcing them in the cultural lexicon. Anonymous stated through their website that they are opposed to the principles of the Scientology religion, and would act accordingly to expel it “…from the Internet and systematically dismantle the Church of Scientology in its present form.” The attack, carried out in January of 2008, seems almost infantile compared to the Spamhaus attack – at its peak, Anonymous was funneling 220 Mbps  at the main Scientology website. Although it was enough to knock the site out and render it inaccessible, it is less than 1,000 times as powerful as the Spamhaus attack. However, outside of tech circles, few people have ever heard of Spamhaus, let alone Cyber Bunker – the Church of Scientology, however, is incredibly controversial and well-known in mainstream circles. This attack received plenty of news coverage, and gave Anonymous global brand recognition. With their signature Guy Fawkes masks and relatively large amount of members, Anonymous quickly rose the ranks of the most notable hacking groups and are arguably the most influential hacktivist collective in history.

Mafiaboy vs. Yahoo, CNN, Dell, Amazon, E-Trade, et al

This series of attacks put the term “DDoS” on the radar for many people, as they occurred in 2000 and showed how potentially damaging they can be. A young hacker from Canada, who went by the online alias “Mafiaboy”, successfully took down Yahoo (at the time the 2nd largest site on the Internet and the world’s most popular search engine), Amazon, Dell, E-Trade, and several other high-profile and highly-trafficked sites using a simple yet effective DDoS method. Even for sites of these magnitudes, they were particularly vulnerable to DDoS attacks, in part due to the fact that the attacks themselves were relatively unknown outside of the techiest of spheres. And as if the sites under attack didn’t have enough egg on their collective faces already for leaving a huge security loophole open on their sites, it was made worse by the fact that Mafiaboy (birth name Michael Calce) was only fifteen years old at the time he carried out the attacks. The amount of damage that a single teenage hacker could reap brought worldwide attention to the concept of DDoS attacks, and caused many sites and hosting providers to immediately implement safeguards to prevent against them. As with anything, attacks and the attackers have grown more sophisticated since Mafiaboy’s exploits, but the relative ease at which a high school freshman could take down the 2nd largest website in the world brought some much needed awareness to DDoS attacks.

North Korea vs. The United States and South Korea 

Although this last example is not a specific, singular incident of a DDoS attack, it’s important to include as it shows how governments of nations at odds can employ DDoS as an effective and reliable agent in waging cyber warfare. South Korean websites, in both the mostly in the government sector, have experienced several large and sophisticated DDoS attacks, dating back to as early as 2009 and still occurring today. The first attack that garnered attention in 2009 affected mostly government sites, including many South Korean military sites. Interestingly enough, several prominent U.S. sites – including The White House, the Department of Defense, and The New York Stock Exchange – were affected as well. Officials and cyber security experts soon learned that the attacks in the U.S. and South Korea were related, and not long after that were able to determine that the attacks originated from a diplomatic enemy that the U.S. and South Korea both share – North Korea. In a country with arguably the most restricted access to the Internet, where only a handful of select individuals have access to a (state-run) Internet at dial-up speeds and 3G mobile internet is forbidden, it’s worth noting that they are employing DDoS attacks and other methods of cyber warfare. They have grown increasingly effective at mounting DDoS attacks as well - South Korean officials have gone on record saying that North Korea ranks behind only the United States and Russia in their ability to carry out DDoS attacks.

Derptrolling Attacks of 2014

From January 2 to January 6, 2014, Black Lotus collected data on the highly publicized @DerpTrolling (via Twitter) attacks against online gaming targets which included Xbox Live, EA, League of Legends, and Blizzard. The attacks claimed by the @DerpTrolling collective caused outages to major gaming networks such as Xbox Live, EA, League of Legends, and Blizzard, and were the result of the CVE-2013-5211 attack vector. Black Lotus measured the @DerpTrolling botnet at a maximum capability of approximately 28 Gbps. The attacker was likely seeking soft targets in an attempt to trigger IP address null routes by the carrier of each respective target. This would have the effect of rendering the target inoperable without the attacker having to exhaust any additional DrDoS resources. More detailed information can be found in a recent Black Lotus Threat Report here: http://www.blacklotus.net/pdf/Black-Lotus-Threat-Advisory-NTP-Reflection-Attacks-Jan-8-2014.pdf



The Largest DDoS Attacks on Record

By Unknown → Thursday, May 29, 2014

What to look for when evaluating your DDoS protection solution


As we’ve covered before in previous blog posts, and as you probably can surmise yourself given the seemingly daily news reports of new and bigger Distributed Denial of Service (DDoS) attacks, your site cannot afford to forgo DDoS protection services. Given the relative ease at which a handful of users or sometimes a single person can grind your site and your entire online business to a screeching halt, DDoS mitigation should be viewed as an essential component to your website and online presence.

As with anything, shopping around can drastically improve your results when arriving at a DDoS protection provider. But for many individuals and business professionals, it can be a bit overwhelming when beginning your search. By its very nature, DDoS is a very technical aspect of the Internet and comes with a lot of jargon and heady vocabulary that can be confusing to the average user. Don’t let that stop you from pursuing proper DDoS protection – we’re here to let you know what you should be looking for and explaining these metrics in layman’s terms so you’ll have a proper grasp on the basics of DDoS and how to properly safeguard against it.

First of all, we’ll briefly define a DDoS attack (although we won’t go into too much detail, since you can read an entire blog entry devoted to this topic here). A DDoS attack is when a large amount of computers, typically controlled by only a handful of actual human beings, all bombard your website with traffic – so much traffic that your bandwidth is quickly depleted and your site is rendered inaccessible. Some site owners assume that simply purchasing more bandwidth would help to prevent against DDoS attacks, but even the world’s biggest sites with astronomically high bandwidth capabilities can be taken down with DDoS, as the number of computers the attackers can control via botnets and malware Trojans can be in the millions.

So if more bandwidth isn’t the answer, what is? There are several key elements that you must weigh when choosing your DDoS protection. First how quickly your protection provider can give you emergency assistance in case of a DDoS attack. As there is no way to 100% prevent against DDoS attacks, emergency protection is one of the most important elements to consider, as you’ll want to have a way to quickly bring your site or sites back up to full strength in the event of an attack. Make sure the provider you choose not only offers a variety of packages based on size of potential attacks, but also one that has real life human beings standing by on call 24 hours a day, 7 days a week, 365 days a year. DDoS attacks can and do happen at any time, any day of the year, and the last thing you’d want to deal with when experiencing an attack is long wait times or having to interact with automated operators.

Secondly, look closely at what type of protection packages are offered. These will typically be broken down by a bit or packet rate threshold – the more gigabits per second of protection a package offers, the more secure your site will be against potential DDoS attacks. Keep in mind that while it is true that the higher the protection rate the more safe your site will be, you may not need the absolute largest type of protection, depending on your business. One of the biggest DDoS attacks on record occurred last year against the email-filtering company Spamhaus, which was under attack at a rate of approximately 300 gigabits per second – the previous record was around 100 gigabits per second, and a typical large-scale DDoS attack (one against a large enough company or entity to get attention) usually runs in the 50 gigabits per second range. Lately, attacks have become even larger with Black Lotus mitigating NTP protocol distributed reflection denial of service (DrDoS) attacks peaking at 421 Gbps in February 2014, possibly a world record! While it’s true that it’s better to be safe than sorry, if you run a local specialty soap shop in a small rural town, you may not need a package that safeguards against the largest scales of DDoS attacks.

Thirdly, consider a DDoS protection service that offers a seamless transition to integrating its protection into your current hosting situation, regardless of your provider. As we know, every minute that your website is down is potentially lost revenue, so choosing a solution that quickly and easily can be implemented with no migration time or costs is huge. There are many different options when it comes to working with your current web hosting provider – evaluate your options based on cost and ease of transition. Look for solutions that can work seamlessly with your site, regardless of your hosting provider and regardless of your location anywhere on the globe.

Fourthly, detailed reports are crucial as they can tell you not only where any potential attacks are coming from, but what methods in which they are being carried out. Some DDoS protection providers offer real-time analysis and reporting, meaning that at any time (whether you’re currently under attack or not), you can log in and see precise and accurate data regarding your traffic and its origins. Depending on your technical expertise, find a provider that will not only include reports when you need them, but also will provide the proper context as to what the data and numbers mean.

And finally, all DDoS protection essentially boils down to filtering your inbound web traffic through high capacity “scrubbers” as they are known. A typical DDoS mitigation service will filter all inbound traffic to your website through their system of scrubbers first. Using complex algorithms, the scrubbers determine which traffic is organic and clean, and which (if any) is resulting from DDoS style attacks. What you want to see here is not only the size and capabilities of the actual scrubbers, but also some flexibility in how they operate. Having the scrubbers be scalable to your site and operation is crucial, as is the ability to select how and when this traffic is filtered. If you are a service provider with your own BGP network, look into network wide protection which can be deployed by GRE tunnel or physical cross connection, allowing  you to essentially sell DDoS protection as part of your customer packages.

There are a handful of industry leaders in the DDoS mitigation space – by comparing packages, flexibility, support, and cost against your business and website’s needs, you will hopefully find the perfect protection package and provider that’s right for you.



.

What Your DDoS Protection Solution Absolutely Must Provide

By Unknown → Thursday, May 22, 2014
The effect of the Heartbleed Bug was, to put it lightly, widespread. In fact, Security Affairs calls it “probably the most serious menace to the modern Internet.” Heartbleed is a loophole in OpenSSL that enables an intruder to see as much as 64 kB of unencrypted data that has been transferred by users into systems including Facebook and Google.

Any organization using OpenSSL may have been impacted by the bug. What’s most devastating about Heartbleed is that the vulnerability – discovered by Google’s Neel Mehta — has existed for two years. Mashable released a list of major sites that require password changes by all users to secure their accounts – critically important now that the bug is common knowledge.

NTP & DrDoS


Many users and IT security professionals are interested in the broad ramifications of Heartbleed. Specifically, worry is rising that the bug could be used to facilitate DDoS (distributed denial of service) attacks. By spoofing a request to a server that is not properly secured, hackers are able to direct a large amount of data at their target.

For example, a bug discovered in the network time protocol (NTP) daemon in early 2012 instructed the server to send hundreds of times the data to a fraudulent IP address which served as the recipient of the brute-force attack. Site security tool and content delivery network (CDN) powerhouse CloudFlare reported the largest distributed denial of service pummeling ever recorded in February – which at its peak hit 400 gigabytes per second (Gbps).

The attack directed toward CloudFlare is considered a subcategory of DoS called distributed reflection denial of service (DrDoS). NTP, domain name service (DNS), and any other tools based on uniform datagram protocol (UDP) are vulnerable to these reflection barrages if they meet the following criteria:

  • public facing (as opposed to outward facing or intranet/internal);
  • one or more of its default commands sends a sizable packet in response to a small request;
  • isn’t outfitted with monitoring capabilities to filter out unwanted traffic.

Understanding Heartbleed & Reverse Heartbleed


Heartbleed is the household name for CVE-2014-0160, its designation within the Common Vulnerabilities and Exposures catalog. It exploits the code of the incredibly popular open source security certificate software OpenSSL (version 1.0.1 without the patch provided in 1.0.1g) so that 64 kB of data held in memory on a server is obtained through a dysfunction in the TLS/DTLS (transport layer security/datagram transport layer security) heartbeat.

By spoofing a HeartbeatRequest so that it seems larger than it actually is, the server essentially is stumped by the situation. Rather than failing to deliver the amount of data ordered by the fraudulent HeartbeatRequest, the server meets the needs of the spoof by drawing on random data that exists in its memory. Our founder, Jeffrey A. Lyon, referred to this process in Network World as “the digital equivalent of short-changing a cashier.”

The data retrieved could include such information as passwords, allowing malicious parties to access user accounts. Private SSL keys could be obtained as well. Note that private keys were initially not considered vulnerable but that their exposure was since confirmed by numerous parties.

To thicken the plot, security industry publication SC Magazine reports that another rendition of Heartbleed has been discovered. In Reverse Heartbleed (also exploiting CVE-2014-0160), rather than a client device stealing information from a server, a server steals information from a client device. Login credentials and other sensitive data can be taken from PCs and smartphones. These client machines use OpenSSL to encrypt communication in some browsers and other applications that run within the local system.

Use of Heartbleed for DDoS


Because this process creates a larger response than the size of the request – as enabled via spoofing – it makes sense that amplification could occur, which in turn could be used by DrDoS instigators. Matthew Prince, founder of CloudFlare (a huge name in the security industry, as mentioned above), tweeted the below note, for example.


Prince’s comment was a bit oversimplistic and hasty, though, as is often true of tweets.

One major argument criticizing the possibility of a Heartbleed DDoS – offered by various security professionals – is that TLS only operates through stateful transport control protocol (TCP). The stateful nature of the interaction describes a communication agreement between client and server: a session must be enacted before the server could inundate any machine with data.

That line of thinking, unfortunately, is only half true. Note the type of TLS mentioned in passing above: datagram transport layer security (DTLS). DTLS is architected to perform identically to TLS through UDP instances, including VPNs (virtual private networks). The good news is that there is a standardized defense for distributed denial of service via DTLS – RFC4347, which was released by the Internet Engineering Task Force (IETF) in April 2006.

Because UDP is stateless, a session cannot occur through it with DTLS. Instead, the service has to make sure the request is legitimate by responding to ClientHello with HelloVerifyRequest and a cookie. The cookie must then be sent back to the server in a new ClientHello in order for the client to receive ServerHello. This form of validation makes malicious activity much less possible.

Response to Heartbleed & shifting focus back to NTP


Regardless of the distributed denial of service implications of Heartbleed – which are minimal compared to other threats – this vulnerability should be remediated immediately by system administrators:

  • All OpenSSL instances should be updated;
  • All passwords that may have been stolen should be changed; and
  • Passwords should continue to be modified on a regular basis.
  • SSL certificates that may have been stolen should be revoked (via the certificate authority, which is typically the brand of the certificate).

The real concern with DDoS right now is DrDoS utilizing NTP, along with the standard methods used by attackers in previous years (which are rising again now that many vulnerable NTP daemons have been patched). Our Q1 2014 Threat Report details attacks for the first three months of the year.


Heartbleed & DDoS: Is There a Connection?

By Unknown → Tuesday, May 6, 2014

By Jerry Whitehead III, re-posted by Jeffrey Lyon


Detailed information and data regarding one of the most popular and devastating forms of DDoS attacks

They say that records are meant to be broken, and in the case of sizing up Distributed Denial of Service (DDoS) attacks, that has never been truer over the past few months. DDoS attacks are measured in terms of how much data per second is being directed at the target site (with the eventual hope of overloading it and rendering it offline). In their infancy and the early days of the web, attacks were measured in megabits, then gradually and in 2000 we saw our first ever 1 Gbps attack. And they have grown steadily since, culminating with the attack on Spamhaus in March 2013, which saw peaks of over 300 Gbps and was large enough to reportedly actually slow down the entire Internet in parts of Europe.

The Spamhaus DDoS attack reigned as king for nearly a year, before reports in the early part of 2014 had various attacks topping the scale at 421 Gbps. How were hackers able to increase the size and severity of their DDoS attacks in less than a year? The answer lies in relfection style DDoS attacks or DrDoS (Distributed reflection Denial of Service) attacks.

Reflection attacks are particularly devastating due to the limited manpower required to launch a massive attack. As the name might suggest, a single attacker is able to direct requests through a particular type of server, which then reflects the response back to a particular target. Depending on the size of the request versus the size of the response, traffic can quickly become tapped out (the higher the ratio of response to request, the quicker and easier it is for hackers to carry out the attack).

One particularly dangerous form of DrDoS attack utilizes the Network Time Protocol (NTP) service.

NTP is used by millions of computers in an effort to synchronize time to Coordinated Universal Time (UTC), the official time standard used by the world to regulate clocks. When a computer connects to the Internet, it will synchronize with a particular NTP server, typically by sending a small packet of data. The return data is the correct UTC time, and the computer’s date and time is correctly synchronized.

There is a different kind of data request that can be sent to an NTP server, however, known as a “monlist” command. This type of ping sent to an NTP server will result in a detailed list of the last 600 or so computers and devices that synchronized to that particular NTP server. As you can imagine, the size of the response is MUCH bigger than the size of the request, making this type of exploit ideal for attackers. They carry it out by sending forged (or “spoofed”) requests to an NTP server with the IP address of their desired target. The server then replies back to the fake request and sends the much larger response back to the target. With the tools available to today’s DrDoS attackers, sending millions of these requests is a breeze, and before too long the intended target’s network is overloaded and knocked offline.

We have covered this type of attack extensively in our recent Threat Reports, which are available for download at our website. As we mentioned, the ratio of amplification is a key factor when attackers decide which method they will use to attempt to take down a site. We have found that some of these particular type of NTP DrDoS attack have an amplification ratio of several hundred, meaning for every byte of information that is sent to the NTP server, it replies with several hundred bytes of information. Multiple sources spoofing constant NTP requests are how these attackers are regularly and easily approaching the 300-400 Gbps scope of attacks.

We have found that at one point there were over 400,000 NTP servers worldwide that are vulnerable to this “monlist” type of attack. Once this exploit was communicated throughout the DDoS circles in the early part of 2014, it was open season. Black Lotus reported an alarming 87% increase in the frequency of attacks during January 2014, and that was due in large part to the proliferation of NTP attacks. NTP attacks were also by far the most common types of attacks during January, constituting approximately 40% (4,877 of 12,108 total) severe attacks.

NTP DrDoS attacks are also responsible for the largest DDoS attacks on record. On February 9 and 10 of 2014, we observed NTP attacks taking advantage of the “monlist” query peaking at 421 gigabytes per second, which is believed to still be the highest of all time.

What can you do to protect your website or network from these styles of attacks? Black Lotus recommends the following steps be taken to improve your own network and the overall safety and stability of the web.

- Make sure your NTP server is running version NTP-4.2.7p26 or later, as anything older than this (which has not been patched) is likely participating in these DrDoS attacks. To find out which version your server is running, head to http://www.openntpproject.org/ and enter in your IP address (or range of addresses).

- If you find any out of date NTP daemons on your network, upgrade them immediately to the most current versions

- Be sure to implement BCP38 on your network, which is a way to safeguard against spoofed IPs and make sure that any request incoming to your network, be it an NTP “getlist” ping or otherwise, is genuine

- Make sure you are implementing access control lists or some sort of policy to block NTP traffic at your network’s edge, which will essentially require customers to use a specific, company-provided NTP daemon for NTP synchronization

Network Time Protocol DrDoS Attacks

By Unknown → Friday, April 11, 2014
Earlier this week US-CERT released details of a vulnerability (CVE-2014-0160), which exists in OpenSSL, a software package used by many web servers such as Apache and nginx to provide encryption for HTTPS connections. OpenSSL versions in the 1.0.1 series prior to 1.0.1g with the RFC6520 TLS heartbeat extension enabled are susceptible, accounting for an estimated 500,000 servers worldwide. To mitigate this threat server administrators must upgrade to OpenSSL 1.0.1g or recompile existing 1.0.1 implementations with the -DOPENSSL_NO_HEARTBEATS flag.

By exploiting this vulnerability an intruder is able to view up to 64kb of data in memory, potentially revealing the site's SSL private key and other confidential information such as login names and passwords. This vulnerability is particularly dangerous as it has existed for the past 2 years and it is almost certain that those with nefarious intentions have been exploiting the vulnerability for quite some time. This means that all login names, passwords, and SSL keys on affected systems must be considered compromised.

A hacker with a stolen SSL key is particularly dangerous. This makes it possible for the hacker to poison DNS cache and create a seemingly perfect clone of the site for which the SSL key was created. Visitors will believe that they are visiting the real site and will see the SSL padlock as expected with zero indication that the visitor has been redirected to a malicious copy of the site, almost certainly resulting in theft of the visitors private information such as login credentials, identifying information, financial data, and so forth.

Black Lotus recommends that system administrators take the following course of action:

- Ensure that web servers are not running a vulnerable OpenSSL implementation.
- In the event that the server was ever running a vulnerable OpenSSL implementation, contact the SSL certificate authority for any keys which may have been compromised and request revocation of the certificate. A new SSL certificate based on a new CSR will be required.
- To be certain, test your site using this tool.- Regardless of the outcome of the aforementioned test, change all passwords, continue to do so frequently and do not use common passwords across multiple sites.

Black Lotus is proactively responding to this threat by testing internal systems and those of managed clients. We have confirmed that no Black Lotus systems have been impacted by this vulnerability and no confidential information such as customer login credentials have been compromised. Regardless, we encourage customers to use the aforementioned tool to test for this vulnerability. In the event that a web server is deemed vulnerable it is important to inspect not only the origin web server but also any proxy, such as a DDoS protection service, that may be handling traffic for the site as an OpenSSL implementation on either could result in a leak.

If you have any concerns about the security of your Black Lotus server or DDoS protection service please contact support@blacklotus.net for immediate remediation assistance.

Defending your site against the Heartbleed vulnerability

By Unknown → Wednesday, April 9, 2014

By Jerry Whitehead III, re-posted by Jeffrey Lyon


How the popular form of cyber-attack has grown since its infancy

Few would have thought that the actions of a young aspiring computer enthusiast (15 years old, to be exact) working predominately alone from Canada would forever change the face of cyber security as we know it. And although that may sound hyperbolic, it’s absolutely true – a young hacker named name Michael Calce (better known by his online alias of Mafiaboy) single-handedly took down some of the largest websites in the world using Distributed Denial of Service (DDoS) attacks. His exploits put DDoS attacks on the international stage and gave the term meaning to the public at large.

But that’s not to say that Mafiaboy’s attacks were the beginning of DDoS –they were simply relegated to the extremely computer savvy circles and unknown to most people on the planet. Let’s take a look back at the history of Denial of Service type attacks and how they have evolved from their earliest stages into the behemoths they have become today.

Most DDoS attacks prior to around 2000 weren’t event DDoS attacks at all – they were Denial of Service (DoS) attacks, meaning that the traffic sent to try and overload a site or network originated from a single source. The “Distributed” in DDoS attacks means that the traffic is being sent from many different sources, making DDoS attacks much more dangerous and difficult to trace.

One of the first and most simple DoS attacks leveraged the Internet Control Message Protocol (ICMP) ping flooding. ICMP is one of the basic principles of the Internet Protocol Suite, which is essentially the rules and guidelines that dictates how the Internet works. It uses small bits of data, known as packets, to send messages across the network about basic operations (such as a new computer joining a network). As far back as 1989, nefarious computer experts soon realized that if they could access a site’s network (which was much easier back then), they could take advantage of the ICMP and send numerous packets to the host using the flood option of pinging packets, which sends packet after packet without waiting for a response from the target. The inbound packets would take up precious bandwidth, and it was made worse of the host responded with outgoing packets, which would take up even more bandwidth.

One of the first DoS attacks to have the “Distributed” put in front of it came in September of 1996, when New York City Internet Service Provider (ISP) Panix.com was attacked. The hackers used the SYN flood method to completely overwhelm Panix’s web, mail, and news servers. SYN stands for SYNCHRONIZE and is an important part of how users connect to websites – the user sends a SYNCHRONIZE request, which is then responded to with a SYN-ACK, or SYNCHRONIZE-ACKNOWLEDGE request from the host. The user then will reply with an ACKNOWLEDGE message and the connection is established. During a SYN flood attack, malicious users overwhelm the server with SYN requests, but never respond with the SYN-ACK message. The server will wait for some time for the SYN-ACK message, during which time legitimate users are also requesting connections. Before too long, the connections become maxed out and service to real users is denied. During the Panix.com attack, hackers were sending approximately 150 SYN requests per second and were using spoofed Internet Protocol (IP) addresses, making them appear as they were coming from everywhere and therefore, impossible to block.

Although DoS attacks started to shift into DDoS, they were still mostly relegated to the most educated among computer hackers. That changed in 1997 when Trinoo (or Trin00) was released – the first downloadable program designed specifically to implement DDoS attacks. Trinoo allowed a single hacker to infect numerous computers which could later be used at his or her disposal. Once access to a network was gained, Trinoo automatically compiled a list of vulnerable machines on the network. The hacker then had to make a few clicks and all infected computers would flood a single host (or website) with User Datagram Protocol (UDP) packets, which is a similar method to the ICMP attack listed above, but is less straightforward and requires the host to send a response packet, which takes up even more bandwidth.

Following in Trinoo’s footsteps, the Low Orbit Ion Cannon (LOIC) is a program/tool designed specifically for coordinated DDoS attacks. The LOIC has been used in some of the most high-profile DDoS attacks on record, including: taking down the Church of Scientology site and affiliate sites (known as Operation Chanology, named after popular message board 4chan); taking down the Recording Industry Association of America (RIAA); taking down the sites of any high-profile entities that opposed WikiLeaks and Julian Assange’s beliefs (known as Operation Payback); and taking down several government sites (US Department of Justice, US Copyright Office, the FBI) after shutting down popular file sharing site MegaUpload (known as Operation Megaupload).

While the methods of DDoS have changed slightly, they are all based on basic rules of the Internet Protocol Suite that can be exploited – all types of DoS and DDoS attacks are essentially maxing out the capacity of a given site or network, which knocks it offline and denies service to everyone. What has continued to change, even on a seemingly weekly basis, are the size and scope of these DDoS attacks. For example, let’s take a look at the Panix.com attack, which knocked out the largest NYC-based ISP for days. Those SYN packets (which at the attack’s peak, were being sent about 150 times per second) are only 60 bytes in size. That means the Panix.com attack was sending data at a rate of 9,000 bytes (or 9 kilobytes) per second, per attacker. That quickly was dwarfed in size by multiple megabyte per second attacks, and by 2000, the world saw its first ever gigabyte per second DDoS attack.

That exponential growth in DDoS attack size should be alarming…especially considering that in early 2014, DDoS attacks were regularly breaking the 200 Gbps size, peaking at a whopping 400 Gbps in several attacks. So while the methodology might not be being radically altered, the magnitude of the attacks most certainly is. Businesses and networks are constantly adding bandwidth to not only facilitate legitimate users, but also to make their sites harder to knock offline via DDoS attacks. But with attacks exceeding 400 Gbps, bandwidth is going to give out at some point – dedicated DDoS protection is the only way to truly safeguard against these new, massive attacks.

The Evolving Face of DDoS Attacks

By Unknown → Tuesday, April 8, 2014