Barret Lyon on DDoS and how to use Squid to Stop it.

Barrett Lyon

In the world of Information Security, especially DDoS, Barrett Lyon is no stranger. Barrett was one of the co-founders of Prolexic (a company that specializes in DDoS Protection).  Barrett recently launched a new venture, called 3Crowd.

What intrigued me – is how I could possibly overlook a post by Barrett on his blog regarding DDoS. Albeit, he writes a lot of stuff concerning security, this mini-tutorial is worth looking into.

The latter is okay, but the Squid Proxy tutorial is something worthy for newbies to look into. How a Squid Proxy can really deflate a lot of the attack traffic, not to mention that most providers such as Prolexic, Gigenet, Staminus, etc. use SNORT and FreeBSD based boxes running PF (Packet Filter). A FreeBSD Box running PF can scale quite well and is very good an thwarting traffic. A lot of new small service providers are propping up – using a distributed FBSD setup, they are able to break up the incoming traffic and filter it – to quite a significant extent, and then parsing the traffic onto a secure (read: optimized for Anti-DDoS efforts) squid box and it deflate the incoming DDoS attack to a very large extent.

However, as with everything else in life, no one will provide you with the complete recipe that works for DDoS protection.

Tags: , , , , , , , , , , , , , , , , , , , ,

How to DDoS: Botnet SDK Available on Twitter.

BitDefender is reporting that a social network Twitter is now being used to control botnets and in fact the SDK (Software Development Kit) for do it yourself Botnets is now available.

More of this can be read at Help Net Security.

Tags: , , , , , , ,

New DoS attack uses Web Servers as Zombies.

A new type of bot being operated out there on the Internet, now interestingly enough is using Web Servers for initiating a DoS (Denial of Service) attack, as opposed to home or business PCs.

The notion is that since web servers have high-speed connectivity to the Internet vs. your average home PC, better to compromise a single web server for a DoS attack rather than 50 PCs.

More can be read on this here on CNet: New DoS attack uses Web Servers as Zombies

Tags: , , ,

2 Australian Atheist Websites get DDoS

Two major Australian atheist website get DDoS. Read more about it here.

Tags:

JustBet.com website under attack.

JustBet.com website is under attack. Read more about this here.

Tags: , ,

Sedo: .de brings in .dos!

Sedo, the domain name auctioneer said, that it was not the intense bidding activity for the one, two and three character .de names that bought its website down,  but in fact a denial of service attack. Read more about it here.

Tags: , , ,

DoS Attacks Grow – Costs Drop!

As with everything else in life, the number of attacks, in this case, DoS attacks have grown, whilst the cost of actually doing a DoS attack has dropped. Read more on this here.

Tags: ,

BitBucket DDoS Attack – What Went Wrong?

The Register has a well-written article on the post-DDoS scenario and analysis of what happened at BitBucket. BitBucket as you may know was a customer on  the Amazon EC2 Cloud and it got DDoS’d big time. This article clearly spells out that it was actually Amazon that was at fault, by exposing their internal storage network to the outside world to be DDoS.

Read the complete article here.

Tags: , , , ,

Zeus Bot Tracker.

Here is perhaps one of the most professional tracking websites that I have seen for a Bot. Abuse.ch is a website that tracks the ZeuS hosts around the world. More at https://zeustracker.abuse.ch/index.php

Tags: , , ,

Malware Economy Thriving. Buy a DDoS bot today!

Malware economy is thriving – especially in this downturn economy. You can even buy your own bot from $100, to $ 3,500.

Bots that can be used for stealing passwords, spamware, adware, ddos attacks, etc. are now available for sale if you know where to look.

Read more here.

Tags: , , , , ,