.com INR-2

Thursday, June 23, 2011

WordPress hit by 'extremely large' DDoS attack

Blog host WordPress.com was the target of a distributed denial-of-service (DDoS) attack earlier today described by the company as the largest in its history.

As a result, a number of blogs--including those that are a part of WordPress' VIP service--suffered connectivity issues. That includes the Financial Post, the National Post, TechCrunch, along with the service's nearly 18 million hosted blogs.

According to a post by Automattic employee Sara Rosso on the company's VIP Lobby (which had been down at the time of the attacks, though was archived by Graham Cluley over at Naked Security), the size of the attack reached "multiple Gigabits per second and tens of millions of packets per second." Rosso had also said putting a stop to the attack was "proving rather difficult."

Rosso had also said the company would be handling its VIP sites ahead of general users.

Denial-of-service attacks are designed to overwhelm Web sites with requests, effectively shutting them down. The ones that are distributed present a much larger challenge to combat, since they can come from a wider variety of networks and hosts.

Update at 10:35 a.m. PT: In an e-mail to CNET, WordPress founder Matt Mullenweg said the attack had affected three of the company's data centers, and was the largest its seen in the company's six-year history. Mullenweg also said that the attack "may have been politically motivated against one of our non-English blogs," but that that detail had not been confirmed. Full e-mail below:

There's an ongoing DDoS attack that was large enough to impact all three of our data centers in Chicago, San Antonio, and Dallas--it's currently been neutralized but it's possible it could flare up again later, which we're taking proactive steps to implement.

This is the largest and most sustained attack we've seen in our six-year history. We suspect it may have been politically motivated against one of our non-English blogs but we're still investigating and have no definitive evidence yet.

The company has also posted a notice on its product uptime status blog:









Anonymous Denies Hacking Sony, Stealing Credit Cards

The hacking group Anonymous has denied responsibility for the attack on Sony's networks, claiming that it has "never...engaged in credit card theft."

Computerworld— The hacking group Anonymous has denied responsibility for the attack on Sony's networks, claiming that it has "never...engaged in credit card theft."
In a long statement posted to the Daily KOS site, the group said others were trying to frame it for the hack of Sony's PlayStation and Online Entertainment networks.
"Whoever broke into Sony's servers to steal the credit card info and left a document blaming Anonymous clearly wanted Anonymous to be blamed for the most significant digital theft in history," said Anonymous. "No one who is actually associated with our movement would do something that would prompt a massive law enforcement response."
Although Sony declined to testify yesterday before a House subcommittee investigating data breaches, in its written response Tuesday to questions ( download PDF ) the company said Anonymous was at least partially responsible for the hacks because it had conducted denial-of-service (DoS) attacks against Sony in the weeks prior to the credit card hack.
"Whether those who participated in the in the denial of services attacks were conspirators or whether they were simply duped into providing cover for a very clever thief, we may never know," said Sony. "In any case, those who participated in the denial of service attacks should understand that -- whether they knew it or not -- they were aiding in a well planned, well executed, large-scale that that left not only Sony a victim, but also Sony's many customers around the world."
Sony also said the credit card hackers had left a file named "Anonymous" on one of its servers. The file contained the words "We are legion," a trademark phrase of the group.
"Anonymous has never been known to have engaged in credit card theft," the group countered Wednesday.
Tuesday's accusations that Anonymous may have been involved was a reversal for Sony.
In a Tokyo press conference Monday, Kaz Hirai, CEO of Sony's games subsidiary, said the company had not found find any link between Anonymous and the newest attacks.
Anonymous had denied responsibility for the Sony network breaches before. On April 22, it issued a statement titled, "For Once We Didn't Do It" that argued "Sony is taking advantage of Anonymous' previous ill-will toward the company to distract users from the fact that the [PlayStation Network] outage is actually an internal problem with the company's servers."
The group had taken credit for the DoS attacks against Sony two weeks before the April breach. Those attacks were launched as a protest of Sony's legal pursuit of George Hotz, who had hacked the PlayStation 3 to run Linux OS.


Hotz, who settled with Sony, has also said he had nothing to do with the network attacks.
"I'm not crazy, and would prefer to not have the FBI knocking on my door," Hotz said in an April 28 blog post . "Hacking into someone else's server and stealing databases of user info is not cool. You make the hacking community look bad, even if it is aimed at douches like Sony."
But Hotz also said Sony had essentially reaped the whirlwind.
"The fault lies with the executives who declared a war on hackers, laughed at the idea of people penetrating the fortress that once was Sony, whined incessantly about piracy, and kept hiring more lawyers when they really needed to hire good security experts," said Hotz. "Alienating the hacker community is not a good idea."
It would obviously be in Anonymous' interest to deny responsibility for the credit card theft. Sony contacted the Federal Bureau of Investigation (FBI) three days after it discovered the intrusion, and five days later met with the agency to provide details of the attack.
The FBI, along with law enforcement authorities in other countries, have been pursuing Anonymous since last year, when the group targeted a large number of Web sites -- including those for Amazon, PayPal, MasterCard and Visa -- for withdrawing services from Wikileaks , the document leaking organization that began publishing U.S. diplomatic cables in November 2010.
In December 2010 and January 2011, the FBI seized hardware from several U.S. Internet service providers, then executed dozens of search warrants in its search for Anonymous.
Sony took its PlayStation Network offline on April 20. As of today, that network, as well as the Online Entertainment network, was not operational.
The company told Congress on Tuesday that it had not identified the people who broke into its servers and lifted the personal information -- and possibly credit card numbers, as well -- of millions of customers.

Internet hit by wave of Fake PC 'defrag' tools

A spate of scareware apps that trick users into buying useless hard disk repair tools appears to be part of a concerted campaign to push fake 'defrag' software, a security company has said.
The Internet abounds with Windows utilities, usually free, some not very good. Users have an unquenchable appetite for them.
According to a GFI-Sunbelt Security blog, a new type of bogus disk software has suddenly become very common on the back of this, with a clutch of convincing examples appearing in recent weeks.
Users encountering new examples HDDRepair, HDDRescue and HDDPlus should ignore them. They are bogus applications that claim to defragment a user's hard disk even though such a requirement is barely needed given that Windows does a lot of this work behind the scenes anyway.
The apps will, however, claim that a user's hard disk is riddled with problems, as will the slightly older examples UltraDefragger, ScanDisk, Defrag Express and WinHDD. Sorting out the non-existent issue can cost anything from $20 and up.
Such apps have been around for some time in fact but have simply been less documented compared to the fake antivirus programs that have caused chaos on the Internet in the last two years.
The phenomenon of fake software is now deeply entrenched on the Internet and criminals have even taken to aping the way security companies are creating all-purpose security programs. Fake apps adopting this verisimilitude tactic include PCoptomizer, PCprotection Center and Privacy Corrector.
A quick trawl of Google reveals that all of the above scareware examples are easy to encounter. So how does a user tell the real and useful from the fake and expensive?
Depending on the type of app, it is sometimes easier to consult lists of real apps that worry about working out which ones aren't genuine.
As the author points out, the overworked Virus Total is one site that allows files and URLs to be checked against known rogue lists, while certification company ICSA Labs publishes a separate, more high-level list of known vendors. These are not perfect warning systems however. Rogue URLs change constantly and might not be spotted by Virus Total, for instance.