Posts Tagged ‘data security’

A Few Points on Yesterday’s Big DDos Attack

Saturday, October 22nd, 2016

If you had trouble getting to a various websites yesterday it was probably fallout from a huge distributed Denial-of-Service (DDoS) attack:

Criminals this morning massively attacked Dyn, a company that provides core Internet services for Twitter, SoundCloud, Spotify, Reddit and a host of other sites, causing outages and slowness for many of Dyn’s customers.

In a statement, Dyn said that this morning, October 21, Dyn received a global distributed denial of service (DDoS) attack on its DNS infrastructure on the east coast starting at around 7:10 a.m. ET (11:10 UTC).

More coverage of the attack here. “At the peak of the attack, average DNS connect times for 2,000 websites monitored by Dynatrace went to about 16 seconds from 500 milliseconds normally.”

Internet-of-Things-enabled devices appear to be at the heart of the DDoS attack:

According to Dan Drew, the chief security officer at Level 3 Communications, the attack is at least in part being mounted from a “botnet” of Internet-of-Things (IoT) devices.

Drew explained the attack in a Periscope briefing this afternoon. “We’re seeing attacks coming from a number of different locations,” Drew said. “An Internet of Things botnet called Mirai that we identified is also involved in the attack.”

The botnet, made up of devices like home Wi-Fi routers and Internet protocol video cameras, is sending massive numbers of requests to Dyn’s DNS service. Those requests look legitimate, so it’s difficult for Dyn’s systems to screen them out from normal domain name lookup requests.

Earlier this month, the code for the Marai botnet was released publicly. It may have been used in the massive DDoS attack against security reporter Brian Krebs. Marai and another IoT botnet called Bashlight exploit a common vulnerability in BusyBox, a pared-down version of the Linux operating system used in embedded devices. Marai and Bashlight have recently been responsible for attacks of massive scale, including the attack on Krebs, which at one point reached a traffic volume of 620 gigabits per second.

Matthew Prince, co-founder and CEO of the content delivery and DDoS protection service provider CloudFlare, said that the attack being used against Dyn is an increasingly common one. The attacks append random strings of text to the front of domain names, making them appear like new, legitimate requests for the addresses of systems with a domain. Caching the results to speed up responses is impossible.

At least some commenters have pointed to a possible connection between DDoS attacks and web services firm BackConnect Inc.:

The latest comes the day after Doug Madory, director of Internet Analysis at Dyn, gave a presentation at an industry conference about research he had done on questionable practices at BackConnect Inc., a firm that offers web services, including helping clients manage DDoS attacks. According to Madory, BackConnect had regularly spoofed Internet addresses through a technique known as a BGP hijack, an aggressive tactic that pushes the bounds of industry.

Madory’s research was conducted with Brian Krebs, a well-known writer on computer-security issues. Krebs also published an article based on the research last month. Within hours, his website was hit by a “extremely large and unusual” DDoS attack, he wrote.

Perhaps someone with more computer security knowledge than I (Dwight? Borepatch?) might comment on how best to defend from these attacks in the future. Spin up big on-demand cloud clustered DNS VMs when a DDoS attack is detected?

DNC Data Breach: Less Security Concern, More Clinton Dirty Tricks

Friday, December 18th, 2015

I included the DNC data breach story in my LinkSwarm roundup, but the more I look at it, the less the story seems like “data breach by Bernie Sanders team” and more like “dirty tricks by Hillary Clinton’s team.”

Here’s a description by Slashdot poster Chris Johnson that states the case:

NGP-VAN, the company that stores this data, which is run by an old Clinton hand who worked for them in 1992, the company paid $34,000 by Ready For Hillary, was repeatedly dropping their firewall between the two major Dem campaigns, Clinton and Sanders.

A guy who’s now fired from the Sanders team observed this. They complained once and were given assurances by the company that it was a mistake and wouldn’t happen again. Then it happened again. The guy decided to gauge how deeply the Clinton campaign was able to read into the Sanders campaign, by experimenting to see how much of the Clinton data he could get. That’s a bad call but by information security standards it’s not unthinkable: it’d be called a white hat intrusion, seeing how much of the firewall was down by probing the other side and assuming your own data was revealed exactly the same way. It does matter, but you still have to fire the guy.

One thing we can be sure of is, anything open to ‘stealing’ on the Clinton side was just as open on the Sanders side, literally. It’s the same system and the same firewall, and if the firewall keeps mysteriously going down for no good reason you have to wonder what’s up and more relevantly what’s being made available to those on the other side of the firewall, which might explain why the firewall’s going down like that.

The Sanders people did NOT throw a fit the first time this happened. But this time, the Sanders guy got caught crossing the nonexistent firewall. We have no information at all on whether anybody from the Clinton side was doing the same thing. During that time there WAS NO firewall and the guy wasn’t hacking, he was browsing, as anybody on either side could have done during those windows.

I think that’s accurate so far. The behavior of the firewall is important, whether or not it’s suspicious as a planned exploit of the Sanders data run by Clinton people who are at the DNC and at NGP-VAN.

In response to the Sanders guy browsing over and seeing data (how do they know? Because HE TOLD THEM. The Sanders team were the ones reporting this, that’s part of the story), the DNC suspended access by the Sanders campaign to THEIR OWN DATA at a crucial time. In order to get access back, at least as of this morning, the requirement is for the Sanders campaign to prove it has destroyed all data that it didn’t necessarily even download (remember, Sanders guy claims he was exploring the Clinton system because it would mirror the vulnerability of the Sanders system, and he’s not IN the Clinton system to go and browse the Sanders side to see how much is revealed, but he was IN the Sanders side and could look at the Clinton side and reasonably conclude that his own side was equally compromised)

And social media is blowing the hell up, not unreasonably, because it’s a goddamn hatchet job combined with a kneecapping to yank access by the Bernie campaign to its OWN DATA because a guy from the Bernie campaign passively browsed through a firewall he didn’t himself disable, a firewall run by a company controlled by Clinton partisans which had been going down already for reasons unknown.

This seems consistent with the facts, consistent with the DNC being “all in” on the Hillary coronation, and consistent with the Sanders campaign suing the DNC for access to their own freaking data.

Says the Sanders campaign:

by their action, the leadership of the Democratic National Committee is now actively attempting to undermine our campaign. This is unacceptable. Individual leaders of the DNC can support Hillary Clinton in any way they want, but they are not going to sabotage our campaign – one of the strongest grassroots campaigns in modern history.

We are announcing today that if the DNC continues to hold our data hostage, and continues to try to attack the heart and soul of our campaign, we will be in federal court this afternoon seeking an immediate injunction.

What is required here is a full and independent audit of the DNC’s handling of this data and its security from the beginning of this campaign to the present, including the incident in October that we alerted them to.

The incident is also consistent with Hillary’s own repeated Nixonian dishonesty. It’s not enough that she has the weakest slate of primary challengers for a non-incumbent since Nelson Rockefeller decided to bow out and let Nixon have the GOP nomination in 1960. Hillary is so used to winning through lies and dirty tricks she does it even when she doesn’t need to. It’s simply who she is.