Hackers seed Amazon cloud with potent denial-of-service bots

  • 28 July 2014
  • 1 reply
  • 2 views

Userlevel 7
Badge +54
Considering the size of Amazon this is potentially disastrous for companies which use it's services.
 

Bug in open-source analytics app may have compromised other services too.

by Dan Goodin - July 28 2014
 
http://cdn.arstechnica.net/wp-content/uploads/2014/07/cloud-seeding-640x320.jpg DooFiAttackers have figured out a new way to get Amazon's cloud service to wage potent denial-of-service attacks on third-party websites—by exploiting security vulnerabilities in an open source search and analytics application known as Elasticsearch.
The power of Backdoor.Linux.Ganiw.a was documented earlier this month by researchers from antivirus provider Kaspersky Lab. Among other things, the trojan employs DNS amplification, a technique that vastly increases the volume of junk traffic being directed at a victim by abusing poorly secured domain name system servers. By sending DNS queries that are malformed to appear as if they came from the victim domain, DNS amplification can boost attack volume by 10-fold or more. The technique can be especially hard to block when distributed among thousands or hundreds of thousands of compromised computers.
 
Full Article
 
Just over a month ago another instance of this happened Code Spaces gets hacked, shuts it's doors

1 reply

Userlevel 7
Attackers are exploiting a vulnerability in distributed search engine software Elasticsearch to install DDoS malware on Amazon and possibly other cloud servers. Last week security researchers from Kaspersky Lab found new variants of Mayday, a Trojan program for Linux that's used to launch distributed denial-of-service (DDoS) attacks. The malware supports several DDoS techniques, including DNS amplification. One of the new Mayday variants was found running on compromised Amazon EC2 server instances, but this is not the only platform being misused, said Kaspersky Lab researcher Kurt Baumgartne
 
By Slashdot / http://it.slashdot.org/story/14/07/28/1444241/attackers-install-ddos-bots-on-amazon-cloud

Reply