Online Services

Category: Security

  • Surviving Electmageddon: Protecting against a wave of DNS outages

    Two weeks ago, DNS provider Dyn was attacked in a very large DDoS attack. IoT devices were used to send an overwhelming amount of traffic to Dyn’s resolvers which resulted in Dyn effectively being taken offline for hours. This took out Netflix, Paypal, Github, Twitter and many other name brand services.

    The Dyn attack may have been retribution against a researcher from Dyn who collaborated with Brian Krebs – both of whom have been working to expose DDoS-for-hire and DDoS protection rackets. We think this explanation is more likely than it being a ‘state sponsored attack’.

    The Dyn attack was the result of Internet of Things or IoT devices being infected with a botnet. At the time about 500,000 devices were infected and only 10% of them were used in the Dyn attack. The source code for the Mirai botnet that was used in the Dyn attack was released some time before the attack on Dyn and this allowed any attacker to build their own botnet and launch a large DDoS attack on any target.

    Earlier this year, Russian hackers, codenamed ‘Fancy bear’ and ‘Cozy bear’ hacked into the Democratic National Committee which resulted in email leaks. This may have been an attempt to disrupt or influence the US election.

    The US election is on November 8th, less than 1 week from now. Some candidates may benefit if fear, uncertainty and doubt are cast on the election itself or the results. Launching a massive DDoS style attack on DNS providers on November 8th would achieve that objective. It would take many services off-line, including news, exit poll results, official candidate websites, official announcement sources and services we rely on like banking.

    We think that certain nation states may have reason to create this kind of disruption. We also think that malicious individuals with their own agenda may also try to create disruptions on November 8th. The Dyn attack demonstrated that by leveraging IoT devices and the Mirai source code, massive outages can be created by individuals or state actors.

    In light of the above facts and the climate we find ourselves in, we would like to make a recommendation to owners of mission critical websites to help them weather the storm that may arrive on November 8th. We are suggesting a change in DNS configuration that is technically complex and also increases operating costs. We recommend this change for business or mission critical websites who have a technical staff they can call on to help them implement this.

    We recommend that websites set up a secondary DNS provider via a different DNS vendor. By doing this, if your first DNS vendor is attacked, the second one will answer any requests for your domains IP address and your website or service will continue functioning as per normal.

    To do this, you need to have a primary DNS provider that allows “zone transfers”. That means that the primary provider must give you the ability to authorize another DNS provider to copy or replicate all your DNS records from time to time.

    The vendor you choose as a secondary DNS provider must have the ability to act as a secondary where another vendor is the primary. That means it must be able to do zone transfers from your primary DNS provider to replicate your DNS records.

    Wordfence is moving to this configuration over the next few days and we’re implementing it with our current DNS provider, DNSMadeEasy as primary and with Verizon’s Edgecast DNS service as the secondary. We have verified that they can work with this configuration and they will give us the performance our customers expect.

    The diagram below gives you a general idea of how a secondary DNS server keeps your website online if your primary DNS provider is attacked. Customers can’t lookup your website IP address and, rather than your website appearing offline, they are able to resolve your site IP with the secondary DNS server and connect to your website. DNS is more complex than the diagram indicates, but this gives you a general idea of how failover works from primary to secondary during a DDoS attack.

    Using a secondary DNS provider

     

    Finding a cost effective DNS provider that can act as secondary DNS to your primary provider can be a challenge. You may also have to switch primary DNS providers if your primary does not allow zone transfers to a secondary DNS provider. For example, Cloudflare does not appear to allow secondary DNS servers because they don’t allow zone transfers.

    We did an audit of the top 10,000 websites (Source: Alexa), and out of 1832 domains that use Cloudflare, only 3 have secondary DNS configured on another vendor. We think these three are using something other than the standard zone transfer to secondary configuration because Cloudflare technically doesn’t support doing that.

    Using a single DNS provider if you operate a mission critical website creates a single point of failure. As recent history has shown, this can leave you offline during a large DDoS attack. As the old Latin saying goes, if you wish for peace, prepare for war. We recommend mission critical websites make appropriate preparations in case we see a repeat of October 21st – and let’s all hope that November 8th comes and goes peacefully.

    The post Surviving Electmageddon: Protecting against a wave of DNS outages appeared first on Wordfence.

  • Learning From Buggy WordPress Wp-login Malware

    Learning From Buggy WordPress Wp-login Malware

    Learning From Buggy WordPress Wp-login Malware

    When a site gets hacked, the attack doesn’t end with the malicious payload or spam content. Hackers know that most website administrators will clean up the infection and look no further. Many go on to patch vulnerable software, change their passwords, and perform other post-hack steps. All of this is good, but hackers who follow through the sustainment phase of the attack also leave behind ways to easily reinfect the site.

    After breaking into a website, hackers want to make sure they still have access if the original security hole is closed.

    Continue reading Learning From Buggy WordPress Wp-login Malware at Sucuri Blog.

  • Malicious WordPress Subdirectory Installs For SEO Spam

    Malicious WordPress Subdirectory Installs For SEO Spam

    Malicious WordPress Subdirectory Installs For SEO Spam

    Remediating over 500 infected sites per day, we see attacks executed at varying levels of complexity. The tactics attackers use to compromise a site provide insight into their motives.

    Some write elegant code and cover their trails carefully, while others create simple attacks that can be applied broadly but aren’t well concealed.

    Spammers never cease in their quest to make use of resources of hacked sites, especially in black hat SEO schemes.

    Continue reading Malicious WordPress Subdirectory Installs For SEO Spam at Sucuri Blog.

  • DynDNS is currently being DDoS’d – May affect your site

    DNS provider DynDNS, also known as Dyn.com is currently being attacked using a very aggressive DDoS attack. If you use them for your website DNS you probably have experienced outages today.

    You can get status updates from DynDNS themselves here and also on Twitter.

    This attack affects any website or online service that uses Dyn.com for DNS resolution. So far this attack has affected:

    • Paypal
    • Netflix
    • Github
    • Twitter
    • Esty
    • Soundcloud
    • Spotify
    • Amazon
    • Heroku
    • Pagerduty
    • Shopify

    And many other large well known brands.

    This attack may affect your website shopping cart checkout if you use a service provider who has been affected by the attack. It may also affect other features or services you provide to customers that rely on being able to contact a site affected by the attack.

    The attack appears to be an attack on Dyn’s infrastructure according to their technical updates. They are working continuously to mitigate the attack. You can watch BGP routes change as Dyn tries to mitigate the attack.

    Last Friday the source code for the Mirai malware that infects a very large (greater than 1 million) Internet of Things botnet was released to the general public. According to Brian Krebs this “virtually guarantees that the Internet will soon be flooded with attacks from many new botnets powered by insecure routers, IP cameras, digital video recorders and other easily hackable devices”. This large scale attack today may be related to the Mirai source code release.

    DownDetector is showing many major brands are having trouble today. Click on a logo for connectivity details.

    If you are affected by this attack, you should consider setting up another DNS provider as your secondary DNS or temporarily moving all DNS to another provider. This appears to be what Amazon has done to mitigate the attack. You will need to exactly duplicate your DNS configuration on the new provider before making it the authoritative DNS for your domain and this may take some time. The transfer may take up to 48 hours, by which time this may all be over.

    The post DynDNS is currently being DDoS’d – May affect your site appeared first on Wordfence.