Showing posts with label DDoS Attacks. Show all posts
Showing posts with label DDoS Attacks. Show all posts

Sunday, April 29, 2012

Accidentally invented - Dos attack using Google Spreadsheets

Panos Ipeirotis, a computer scientists working at New York University,attack on his Amazon web service using Google Spreadsheets and Panos Ipeirotis checked his Amazon Web Services bill last week - its was $1,177.76 !

He had accidentally invented a brand new type of internet attack, thanks to an idiosyncrasy in the online spreadsheets Google runs on its Google Docs service, and he had inadvertently trained this attack on himself. He calls it a Denial of Money attack, and he says others could be susceptible too.

On his personal blog Ipeirotis explained that it all started when he saw that Amazon Web Services was charging him with ten times the usual amount because of large amounts of outgoing traffic.


As part of an experiment in how to use crowdsourcing to generate descriptions of images, he had posted thumbnails of 25,000 pictures into a Google document, and then he invited people to describe the images. The problem was that these thumbnails linked back to original images stored on Amazon’s S3 storage service, and apparently, Google’s servers went slightly bonkers. “Google just very aggressively grabbed the images from Amazon again and again and again,” he says.

After analyzing traffic logs he was able to determine that every hour a total of 250 gigabytes of traffic was sent out because of Google’s Feedfetcher, the mechanism that allows the search engine to grab RSS or Atom feeds when users add them to Reader or the main page.

After speaking with Google representatives, Ipeirotis believes that the company is trying to balance user privacy with a desire to present fresh content. It seems that Google doesn’t want to store the information on its own servers so it uses Feedfetcher to retrieve it every time, thus generating large amounts of traffic.

Google becomes such a powerful weapon due to a series of perfectly legitimate design decisions,” Ipeirotis wrote in a blog posting on the issue.


Source: THN

Monday, April 9, 2012

Downing Street website also taken down by Anonymous

The Anonymous collective has vowed to target British Government sites every week, bringing them offline by overloading them with traffic.
So-called “hacktivists” were able to launch their cyber attack on Saturday night despite announcing it days in advance, raising questions about the effectiveness of Whitehall internet security.

The British branch of Anonymous – a loose global collective of computer hackers who often target law-enforcement websites – first advertised “#OpTrialAtHome” last Monday.
undefined
The Anonymous hacking network uses as a logo the mask from the comic V For Vendetta
A poster featured the photos of three British citizens who have been sent to the US to face trial – Gary McKinnon, Richard O’Dwyer and Christopher Tappin – together with the slogan “Fight extradition”.

It included the address of the Home Office website and the direction to “charge ya lazers” on Saturday at 9pm GMT.

Supporters would understand this to be an order to join in a “distributed denial-of-service attack” on the website, in which thousands of computers are used to send a flood of requests to visit the victim’s homepage, causing its servers to buckle under the demand.

At the appointed hour, Anonymous Twitter feeds ordered followers to “fire your Laz0rs”, and soon reported “Tango Down” as the target was hit.
Screenshots showed that the Home Office website was inaccessible from 9pm and service was reportedly patchy until Sunday morning.
A Home Office spokesman said: “The Home Office website was the subject of on online protest last night.

“This is a public-facing website and no sensitive information is held on it. There is no indication that the site was hacked and other Home Office systems were not affected.

“Measures put in place to protect the website meant that members of the public were unable to access the site intermittently.

“We will continue to monitor the situation and take measures accordingly.”

The activists also brought down the Downing Street website at about 10.30pm, but a spokesman for the Prime Minister said it only lasted for a “couple of minutes” and there was no suggestion of it being hacked into. The Ministry of Justice denied the hackers’ claims that its website had also been taken offline.

Anonymous explained on Twitter: “It’s a digital protest which is different [from] hacking. UK want their government to listen. We can do it as long as it takes.

“Selling your citizens to foreigners is not acceptable! We are Anonymous, we do not forget, we do not forgive.”
Another message from the group said: “EXPECT a DDOS (Distributed Denial of Service) every Saturday on the UK Government sites.”

Source: Telegraph

Tuesday, March 6, 2012

How to make a DDoS Attack?

Hi all my visitors. Today I am going to tell you about "How to make a DDoS attack from your Computer?"

Process-1
LOIC [Low Orbit Ion Canon]

First of all please Download LOIC [Low Orbit Ion Canon] from here. You will get the all instruction about how to download?
LOIC Interface
Secondly, You should have to uninstall your all kind of Anti-virus what ever you installed in before!

Thirdly,

1. Insert the website address or URL of the website you want to attack via DDoS.
2. Click on "Lock On" Button.
3. Port will be better if you keep it default "80".
4. In this section you can use "HTTP" or "TCP" one of this 2 Methods.
5. If you Select "HTTP" method then insert "1000" in the "Threads" & if you select "TCP" method then insert "10000" in the "Threads" area.
6. Now Press on Highlighted Blue IMMA CHRAGIN button in the Upper right Corner.

Flood started.


PC Users Keep your LOIC application running and keep visiting this site by clearing your browser catch everytime
before you visit.
Process-2

TEV DoS



TEV DoS users start DoS by inserting IP=[Of the website URL] Port= 80

Process-3
Normal Computer User

People who are unable to Run LOIC, Go this way:

Go to START => RUN => cmd => & Type "ping URL -t" Paste Website URL in the URL section and keep -t Without Quote. Press enter. Keep Doing It Until The Site Is Down.


Ask me If you fall in any kind of problem related this. Ask me here!

Copyright: Admin

Saturday, February 18, 2012

Anonymous Hackers Develop WebLOIC DDOS Tool for Android Mobiles

These Days Anonymous Hacker Group using a new tool WebLOIC. This tool is even easier to use than LOIC DDOS tool, requiring no download, it sends requests using Javascript in the user's browser. Just like LOIC, it is a quick path to prison, sending thousands of requests from your IP address to the target, accompanied by a slogan.

Anonymous+Hackers+Develop+WebLOIC+DDOS+Tool+for+Android+Mobiles

Recently Hackers Release and New Interface of WebLOIC, ie. for Android Mobile in the form of an Application named “LOIC para Android by Alfred”. They Spread this tool via Anonymous social network accounts to execute the new attack in Various Anonymous operations against Argentinian government - such as #opargentina #iberoamerica.

When Attacker will click "Fire", a JavaScript will sends 1,000 HTTP requests with the message “We are LEGION!” that perform DoS attacks of Given Target URL.


Source: The Hacker News

Wednesday, September 14, 2011

Download LOIC (Low Orbit Ion Cannon)

LOIC (Low Orbit Ion Cannon) is an open source network stress testing application, written in C#. A JavaScript version has also been created enabling a DoS from a web browser. LOIC was initially developed by Praetox Technologies, but later it was released into the public domain.


Aaha! Wait a little bit!

Have you downloaded and installed Microsoft .NET Framework 4 Client Profile? Without it you can't run this LOIC Software.


Use:

LOIC performs a denial-of-service (DoS) attack (or when used by multiple individuals, a DDoS attack) on a target site by flooding the server with TCP packets or UDP packets with the intention of disrupting the service of a particular host. People have used LOIC to join voluntary botnets.

Notable Uses:

LOIC was utilized by Project Chanology, an offshoot of the Anonymous group, to attack Scientology websites, then by Anonymous itself to successfully attack the Recording Industry Association of America's website in October 2010, and again during Operation Payback in December 2010 to attack the websites of companies and organizations that opposed WikiLeaks. LOIC was utilized by many attackers, despite the fact that a network firewall could easily filter out network traffic it generates, thus rendering it only partly effective. More than 30,000 downloads of the tool were reported to have occurred between 8 and 10 December 2010. If an attack is not routed through an anonymization network such as Tor, traceable IP address records can be logged by its recipient. This can be used to identify the individual user conducting DDoS attacks from logs kept by their ISPs. On January 27, 2011, five people were arrested in the UK in connection with the Operation Payback attacks, while in June 2011 a further three LOIC users were arrested in Spain for their involvement in the web attacks. On 14 June 2011, it was reported that Turkish police arrested 32 individuals who allegedly attacked government websites in protest against the introduction of state level web filtering. The individuals are thought to be members of Anonymous that used the LOIC tool in their protest.

Source: Desk & Wikipedia

Friday, September 2, 2011

Hackers can use Google+ servers to make DDos attack on ANY website!

A new security hole has been discovered on the Google+ servers that would allow potential hackers to make DDos using Google’s Bandwidth. Google+ has been under testing for quite sometime now and a tester at an Italian Security firm has reported that the Google+ servers can be used to make DDos requests to other websites. The original sighting of this reports can be seen at IHTeam Security Blog by Simone Quatrini. He demonstrates how users can make use of Google’s server to act as a proxy and fetch content of any desired website. It is also noted that Google’s servers are more anonymous than other servers. Here is the video for the news :  



To Download the DDoS Source Code  Here

Source: Link

Thursday, July 7, 2011

Anonymous Attacks Turkish Websites Again

Hacker group Anonymous said late Wednesday that its Antisec movement hacked and defaced Turkish government websites, in protest against new Internet filtering rules that come into force in the country in August.



The group said it released data from about 100 websites in Turkey, and put up its logo and message on some 74 websites, criticizing what it described as greater control over the Internet in Turkey, including blocks on thousands of websites and blogs.

The hacks released are part of a "Turkish Takedown Thursday" action planned by the group. Its Antisec program, started in June with the now disbanded hacker group LulzSec, targets governments, law enforcement, and corporations.

Turks took to the streets in May to protest against the new filtering scheme, which plans to introduce four levels of filtering - family, children, domestic, or standard - for Internet users by August 22. While protestors describe the rules as mandatory, the government has said they are optional filters for the protection of families.

Anonymous last month launched DDoS (distributed denial of service) attacks on some Turkish government websites in protest against the proposed filtering rules. Among the sites that were attacked were that of the Internet regulator, Telekomünikasyon İletişim Başkanlıgı. This site was not affected on Wednesday.

Turkey responded last month by arresting 32 persons said to be involved in the attacks on the government sites.

Earlier this week, police arrested 15 people in Italy for their alleged involvement in Anonymous attacks, according to reports.

Source: AnonOps




Saturday, June 11, 2011

Operation Turkey: Anonymous fights Internet censorship with DDoS success




Today, Thursday, the international Internet hactivist collective known as Anonymous launched a successful DDoS attack against the Turkish government, taking down several official government websites, including http://tib.gov.tr/ and www.­sgk.­gov.­tr.

Anonymous is protesting Internet censorship in Turkey. The Turkish government plans to implement a filter on Internet browsing on Aug. 22 under the pretense of protecting the youth from "harmful elements on the web." Critics argue that the filter will lead to wide-spread censorship.

The current Anonymous cyber attacks against the Turkish government consist of DDoS (distributed denial of service) attacks using a coordinated network of Low Orbit Ion Canons (LOICs). Such attacks are an orchestrated attempt to make a computer resource unavailable to its intended user.
The following is an excerpt from a video statement released Monday by those claiming to represent the nebulous collective known as Anonymous:

To the citizens of Turkey.
We are Anonymous.

Over the last few years, we have witnessed the censorship taken by the Turkish government, such as blocking YouTube, Rapidshare, Fileserve and thousands of other websites. Most recently, the government banned access to Google services.

These acts of censorship are inexcusable. The internet is a platform for freedom, a place where anyone and everyone can come together, discuss topics, and share information, without the fear of government interference.

We, Anonymous, will not stand by and let this go unnoticed. We will fight with the Turkish people against their government's rain of censorship.

Citizens of Turkey, Anonymous now fights with you.

Turkish Government,

Expect us.


While the Information and Communication Technologies Authority (BTK) of Turkey claims the proposed system of Internet filters is harmless, and will simply offer users more options, Anonymous and other concerned observers fear a much more draconian effect.
Last May tens of thousands Turkish citizens protested in Istanbul against the proposed Internet censorship. Anonymous and other critics worry the filtering system would make it possible to keep records of people's Internet activity and may be used as a means to prevent or halt possible political protest or dissidence.

Source: AnonOps


Monday, March 7, 2011

WordPress.com DDoS Attacks Primarily From China


undefined

After recovering from the largest Distributed Denial of Service attack in the service’s history (“multiple Gigabits per second and tens of millions of packets per second”) yesterday morning, blog host WordPress.com was attacked again very early this morning, finally stabilizing its service at 11:15 UTC (around 3:15 am PST).
WordPress.com serves 18 million sites, many of them news sites like our own,  which lead someto conjecture that the attacks had come from the Middle East, a region experiencing its own Internet issues at the moment. Not so says Automattic founder Matt Mullenweg, who tells me that 98% of the attacks over the past two days originated in China with a small percentage coming from Japan and Korea.
According to Mullenweg one of the targeted sites was a Chinese-language site operating on WordPress.com which also appears to be blocked on Baidu, China’s major search engine. WordPress.com doesn’t know exactly why the site was targeted and won’t release the name until it does. Based on the extent of the attacks Mullenweg tells me that they appear to be politically motivated.
“WordPress.com was hit with a another wave of attacks today (the fourth in two days) that caused issues again. This time we were able to recover more quickly, and also determined one of the targets to be a Chinese-language site which appears to be also blocked on Baidu. The vast majority of the attacks were coming from China (98%) with a little bit of Japan and Korea mixed in.”
While Mullenweg tells me that DDoS attacks are fairly common at WordPress.com but its the strength of its infrastructure (distributed across three data centers in three cities) usually prevents anyone from noticing. The recent attacks have impacted not just WordPress.com sites, other servers in the same part of the network causing the outages. WordPress.com is collaborating with upstream providers to shift the attacks.
Says Mullenweg, “Right now there are huge asymmetric risks on the internet because any bad actor, for a few tens of thousands of dollars, has the online equivalent of a dirty nuke and can bring even the largest sites to their knees and silence millions of voices.”
WordPress.com isn’t the only one suffering from recent DDoS attacks, a slew of South Korean sites also took a hit during the same time period.
Update: Mullenweg tells me that after closer scrutiny the attacks don’t seem to be politically motivated, “it doesn’t look like attacks were politically motivated, likely more business-oriented given the targeted site, though we still haven’t heard back from the owner.”

Source: TechCrunch