Eagle Eye Networks

DDOS Cyber Attacks Update

September 29, 2016 Eagle Eye Networks

cyber blog- ddos-attacks

Last week hackers forced Brian Krebs to take down his security journalism site because of a large scale Denial of Service Attack – likely one of the largest ever seen.

Krebs on his website KrebsOnSecurity.com has a long history of exposing DDOS cyber criminals. This was one of the biggest attacks in the history of the Internet.

Estimates go as high as 1.5 million devices begin used to make this attack. The attack had a tremendous amount of power behind it.

According to Level 3, the largest part of the Botnet used for the attack was made mostly of internet-connected cameras and DVR’s made by DAHUA Technology, a Chinese manufacturer, with a subsidiary in California. The hackers found a vulnerability which affects most of DAHUA’s cameras that allow anyone to take control of the devices by entering an extra-long overflowing password. The botnet also includes other devices like home routers and Linux computers.

Malware was then installed on the devices to make them part of the attack botnet. Similar botnets have been used both DDOS attacks and ransomware attacks.

The hackers used a malware dubbed “MIRAI”. MIRAI source code was initially released in 2015 and is widely available. It is written in C and designed to be very portable to different platforms.

Expect to see more attacks, problems, and issues of this ilk in the future. This botnet is really large and will likely play a role in the future. If you have a camera or a DVR that has been connected to the internet, you should either dispose of it or make sure it is not infected. It is not enough to put it behind a firewall once its infected.

Further Reading:
https://www.wired.com/2016/10/internet-outage-ddos-dns-dyn/
https://blog.level3.com/security/attack-of-things

Tags

Other posts that might interest you

loading

Are You Afraid of Your DVR?

You should be if it's connected to the internet. It could be the doorway for hackers to access your entire network. Once a DVR is compromised, it can be used…

October 31, 2016 Eagle Eye Networks

Cloudflare Security Bug

Eagle Eye Networks does not use Cloudflare - a website performance enhancement service. There was a relatively severe security issue detected by Tavis Ormandy at Project Zero in the Cloudflare…

February 27, 2017 Eagle Eye Networks

Devil’s Ivy Update

In July 2017, cyber security researchers discovered a serious flaw, which they named “Devil’s Ivy”, that exists in nearly all cameras supporting the popular ONVIF specification. The flaw allows hackers…

August 8, 2017 Eagle Eye Networks