US-CERT: Anonymous DDoS Activity
US-CERT has received information from multiple sources about coordinated distributed denial-of-service (DDoS) attacks with targets that included U.S. government agency and entertainment industry websites. The loosely affiliated collective "Anonymous" allegedly promoted the attacks in response to the shutdown of the file hosting site MegaUpload and in protest of proposed U.S. legislation concerning online trafficking in copyrighted intellectual property and counterfeit goods (Stop Online Piracy Act, or SOPA, and Preventing Real Online Threats to Economic Creativity and Theft of Intellectual Property Act, or PIPA).
"hxxp://3g.bamatea.com/loic.html"
"hxxp://anonymouse.org/cgi-bin/anon-www.cgi/""hxxp://chatimpacto.org/Loic/"
"hxxp://cybercrime.hostzi.com/Ym90bmV0/loic/"
"hxxp://event.seeho.co.kr/loic.html"
"hxxp://pastehtml.com/view/bl3weewxq.html"
"hxxp://pastehtml.com/view/bl7qhhp5c.html"
"hxxp://pastehtml.com/view/blafp1ly1.html"
"hxxp://pastehtml.com/view/blakyjwbi.html"
"hxxp://pastehtml.com/view/blal5t64j.html"
"hxxp://pastehtml.com/view/blaoyp0qs.html"
"hxxp://www.lcnongjipeijian.com/loic.html"
"hxxp://www.rotterproxy.info/browse.php/704521df/ccc21Oi8/vY3liZXJ/jcmltZS5/ob3N0emk/uY29tL1l/tOTBibVY/wL2xvaWM/v/b5/fnorefer"
"hxxp://www.tandycollection.co.kr/loic.html"
"hxxp://www.zgon.cn/loic.html"
"hxxp://zgon.cn/loic.html"
"hxxp://www.turbytoy.com.ar/admin/archivos/hive.html"3g[.]bamatea[.]com A 218[.]5[.]113[.]218
cybercrime[.]hostzi[.]com A 31[.]170[.]161[.]36
event[.]seeho[.]co[.]kr A 210[.]207[.]87[.]195
chatimpacto[.]org A 66[.]96[.]160[.]151
anonymouse[.]org A 193[.]200[.]150[.]125
pastehtml[.]com A 88[.]90[.]29[.]58
lcnongjipeijian[.]com A 49[.]247[.]252[.]105
www[.]rotterproxy[.]info A 208[.]94[.]245[.]131
www[.]tandycollection[.]co[.]kr A 121[.]254[.]168[.]87
www[.]zgon[.]cn A 59[.]54[.]54[.]204
www[.]turbytoy[.]com[.]ar A 190[.]228[.]29[.]84GET /?id=1327014189930&msg=%C2%A1%C2%A1NO%20NOS%20GUSTA%20LA%20msg=%C2%A1%C2%A1NO%20NOS%20GUSTA%20LA%20
msg=:)
msg=:D
msg=Somos%20Legion!!!
msg=Somos%20legi%C3%B3n!
msg=Stop%20S.O.P.A%20:)%20%E2%99%AB%E2%99%AB HTTP/1.1" 200 99406 "http://pastehtml.com/view/bl7qhhp5c.html"
msg=We%20Are%20Legion!
msg=gh
msg=open%20megaupload
msg=que%20sepan%20los%20nacidos%20y%20los%20que%20van%20a%20nacer%20que%20nacimos%20para%20vencer%20y%20no%20para%20ser%20vencidos
msg=stop%20SOPA!!
msg=We%20are%20Anonymous.%20We%20are%20Legion.%20We%20do%20not%20forgive.%20We%20do%20not%20forget.%20Expect%20us!66:6c:6f:6f:64:00:00:00:00:00:00:00:00:00 | flood.........
- Develop a checklist or Standard Operating Procedure (SOP) to follow in the event of a DDoS attack. One critical point in a checklist or SOP is to have contact information for your ISP and hosting providers. Identify who should be contacted during a DDoS, what processes should be followed, what information is needed, and what actions will be taken during the attack with each entity.
- The ISP or hosting provider may provide DDoS mitigation services. Ensure your staff is aware of the provisions of your service level agreement (SLA).
- Maintain contact information for firewall teams, IDS teams, and network teams and ensure that it is current and readily available.
- Identify critical services that must be maintained during an attack as well as their priority. Services should be prioritized beforehand to identify what resources can be turned off or blocked as needed to limit the effects of the attack. Also, ensure that critical systems have sufficient capacity to withstand a DDoS attack.
- Have current network diagrams, IT infrastructure details, and asset inventories. This will assist in determining actions and priorities as the attack progresses.
- Understand your current environment and have a baseline of daily network traffic volume, type, and performance. This will allow staff to better identify the type of attack, the point of attack, and the attack vector used. Also, identify any existing bottlenecks and remediation actions if required.
- Harden the configuration settings of your network, operating systems, and applications by disabling services and applications not required for a system to perform its intended function.
- Implement a bogon block list at the network boundary.
- Employ service screening on edge routers wherever possible in order to decrease the load on stateful security devices such as firewalls.
- Separate or compartmentalize critical services:
- Separate public and private services
- Separate intranet, extranet, and internet services
- Create single purpose servers for each service such as HTTP, FTP, and DNS
- Review the US-CERT Cyber Security Tip Understanding Denial-of-Service Attacks.
- Cyber Security Tip ST04-015 - <http://www.us-cert.gov/cas/tips/ST04-015.html>
- Anonymous's response to the seizure of MegaUpload according to CNN - <http://money.cnn.com/2012/01/19/technology/megaupload_shutdown/index.htm>
- The Internet Strikes Back #OpMegaupload - <http://anonops.blogspot.com/2012/01/internet-strikes-back-opmegaupload.html>
- Twitter Post from the author of the JavaScript based LOIC code - <http://www.twitter.com/#!/mendes_rs>
- Anonymous Operations tweets on Twitter - <http://twitter.com/#!/anonops>
- @Megaupload Tweets on Twitter - <http://twitter.com/#!/search?q=%2523Megaupload>
- LOIC DDoS Analysis and Detection - <http://blog.spiderlabs.com/2011/01/loic-ddos-analysis-and-detection.html>
- Impact of Operation Payback according to CNN - <http://money.cnn.com/2010/12/08/news/companies/mastercard_wiki/index.htm>
- OperationPayback messages on YouTube - <http://www.youtube.com/results?search_query=operationpayback>
- The Bogon Reference - Team Cymru - <http://www.team-cymru.org/Services/Bogons/>
Troj/Loic-A (http://nakedsecurity.sophos.com/tag/loic/)
andTroj/Refref-A (http://nakedsecurity.sophos.com/2011/11/11/anonymo
us-and-lulzsec-trawl-google-code-search-for-securi ...) These latest pages we detect as Troj/DDoS-AN (http://nakedsecurity.sophos.com/2012/01/20/anonymous-opmegaupload-ddos-attack/). This means we have blocked access to the pages themselves - we'll also be getting feedback on these pages, which will lead to them being blocked on URL alone, but the main thing is that we're blocking the code itself.By Sophos
Tweet
Memorial
Knowledge is suppressed because of its power to change.
Online since 30-jan-2010
Security tips #1
Donate
Donate & Help us out. Server(
cost money.
Security tips #2
Avoiding Social Engineering and Phishing Attacks
Dealing with Cyberbullies
Preventing and Responding to Identity Theft
Recognizing and Avoiding Spyware
Recovering from Viruses, Worms, and Trojan Horses
Understanding Denial-of-Service Attacks
Understanding Hidden Threats: Corrupted SoftwareFiles
Understanding Hidden Threats: Rootkits and Botnets
Who's new
- ciberprov
- michael.nguyen
- mornjinfeng
- aniketdaptardar
- hadriker
- Alanw
Security vids #1
Team Cymru Research NFP is a specialized Internet security research firm and 501(c)3 non-profit dedicated to making the Internet more secure. Team Cymru helps organizations identify and eradicate problems in their networks, providing insight that improves lives.
Team Cymru the video series 1 to 10
Team Cymru the video series 11 to 20
Team Cymru the video series 21 to 30
Team Cymru the video series 31 to 40
Team Cymru the video series 41 to 50
Team Cymru the video series 51 to 60
Who's online
Security vids #2
The Center for Education and Research in Information Assurance and Security (CERIAS) is currently viewed as one of the world’s leading centers for research and education in areas of information security that are crucial to the protection of critical computing and communication infrastructure.
CERIAS is unique among such national centers in its multidisciplinary approach to the problems, ranging from purely technical issues (e.g., intrusion detection, network security, etc) to ethical, legal, educational, communicational, linguistic, and economic issues, and the subtle interactions and dependencies among them.
CERIAS Security: Attribute-Based Access Control
CERIAS Security: Information Flow Analysis in Security Enhanced Linux
CERIAS Security: Towards Mining Syslog Data
Weapons of Mass Disruption Gallery Launch: Reitinger Remarks
Weapons of Mass Disruption: Mike McConnell on The Nightmare Scenario










Comments
Post new comment