- 14 May 2010 10:29
Imperva discovers more dangerous DDoS attack threat
SYDNEY, May 14. Imperva, the data security leader, has uncovered a new DDoS attack that appears to be more powerful, more efficient and less traceable than traditional methods.
The new threat was identified by Imperva's lab, the Application Defense Center (ADC). Already the new attack mode has compromised hundreds of web servers by turning them into bots. Unlike typical DDoS attacks that capitalise on bot-infected PCs by using the servers as the attack platforms, the hackers have created a much stronger force. Below are details of the discovery:
What it is: A new type of DDoS attack that has currently infected hundreds of web servers. Unlike traditional DDoS methods that capitalise on bot-infected PCs, the attackers have turned the web servers themselves into payload-throwing bots
How it works: Rather than use the server as a means of distributing DoS malware to PCs, attackers infect the servers themselves with a malicious DoS application. Then, using a simple software program with a dashboard and control panel, the hackers configure the IP, port and duration of an attack. The simply insert a URL they wish to attack, click and go.
Imperva was able to acquire the source code of this application - which consisted of just 90 lines of PHP code - and has screenshots . We've also witnessed an attack as it was taking place and can describe what we saw and what we learned.
Why Imperva believes this is unique:
* Although servers are typically harder to compromise than PCs, by capitalising on their greater horsepower, the hackers create a much more efficient and powerful DDoS tool using servers as the attack platform. Attack volumes are multiplied by the numbers of exploited web servers.
* By using web servers, the attackers are less detectable. Tracebacks typically lead to a lone server at a random hosting company.
About Imperva Imperva, the Data Security leader, enables a complete security lifecycle for business databases and the applications that use them. Over 4,500 of the world’s leading enterprises, government organizations, and managed service providers rely on Imperva to prevent sensitive data theft, protect against data breaches, secure applications, and ensure data confidentiality. The award-winning Imperva SecureSphere is the only solution that delivers full activity monitoring from the database to the accountable application user and is recognised for its overall ease of management and deployment. For more information, visit www.imperva.com.
Media queries Grenadine Lau Imperva Phone: +65.6749 4482 Mobile: +65.9666 1886 Email: Grenadine.Lau@Imperva.com
David Frost PR Deadlines Pty Ltd, for Imperva Phone: +61.2.4341 5021 Mobile: +61 (0) 408 408 210 Email: davidf@prdeadlines.com.au
Chapter 3: Managing VoIP Performance, Availability, and Security
When adding network features to support a secure VoIP network environment, the challenge is to achieve balance of informed technology choices with intelligent resource procurement and allocation. Chapter 2 identified several critical voice performance requirements—the most obvious being throughput, delay, and jitter.
FeedDemon
FeedDemon is an easy-to-use RSS reader for Windows which will keep you informed with the latest news and information. The Google Reader Synchronization allows you ...
Top Ten Considerations when Deploying IT Operations Management in the Cloud
IT organisations must be able to quickly deliver and securely manage new business and IT services at fraction of the cost. This means that every IT organisation must reconsider how they approach IT operations and business service management. As a result, many IT organisations are looking to the cloud for its promised benefits of reducing total cost of ownership, requiring less technical skill set and very fast time to value.
- FTMicrosoft Systems Engineer - Microsoft - IIS 6/7 - Active Directory - ScriptingNSW
- FTMicrosoft Systems Engineer - Microsoft - IIS 6/7 - Active Directory - ScriptingNSW
- FTSenior .Net Developer - Mobility/Portal SolutionsNSW
- FTMobile Portal Architect - .Net TechnologiesNSW
- FTWindows Systems Engineer - Server 2003/2008 - VMWare - IIS 6/7NSW
- FTIIS Engineer - Microsoft - IIS 6/7 - Active Directory - ScriptingNSW
- FTProduct Manager / Application StrategistNSW
- FTWindows Server Systems Engineer - Server 2003/2008 - VMWare - SCCMNSW
- CCDB2 / DBA Technical Consultant - Finance company - Melbourne CBD - DB2VIC
- FTProduct Manager / Application StrategistNSW
- FTProduct Manager / Application StrategistNSW
- FTIntegration Engineer - Trading systems - UNIX/ScriptingNSW
- FTProduct Manager / Application StrategistNSW
- FTMicrosoft Systems Engineer - Microsoft - IIS 6/7 - Active Directory - ScriptingNSW
- CCData Migration AnalystNSW
- FTMicrosoft Systems Engineer - Microsoft - IIS 6/7 - Active DirectoryNSW
- FTSupport Consultant - Global Vendor - $55-75,000NSW
- CCDigital Business Analyst - Agile/ScrumNSW
- FTVM Systems Engineer - Microsoft - VMWare - IIS 6/7 - Active DirectoryNSW
- FTIIS Engineer - Microsoft - IIS 6/7 - Active Directory - ScriptingNSW
- FTSoftware Engineer - Java/LinuxNSW
- FTMobile Data Terminal EngineerNSW
- FTUser Experience & Support Service - French or German SpeakersNSW
- FTFlash / ActionScript DeveloperNSW
- FTSenior C# ASP.Net DeveloperNSW











