Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

In one of the biggest findings of the year after a series of disclosures since last 8 months it is now clear beyond doubt that the famous content framework "Joomla" is in the eye of the storm from attackers with malicious intents. The modus operandi is pretty clear with running exploitation campaigns which comprises a large numbers of servers, or Software-as-a-Service (SaaS) providers, which is being used to push malware and phishing campaigns as well as to serve as zombies in distributed denial of service (DDoS) botnets.

Vulnerabilities in web applications hosted by Software-as-a-Service providers continue to provide ammunition for criminal entrepreneurs. Now they are preying on a vulnerable Joomla plugin for which they have invented a new DDoS attack and DDoS-for-hire tools, said Stuart Scholly, senior vice president and general manager in the Security Business Unit at Akamai, in a statement.  This is one more web application vulnerability in a sea of vulnerabilities  with no end in sight. Enterprises need to have a DDoS protection plan in place to mitigate denial of service traffic from the millions of cloud-based SaaS servers that can be used for DDoS. reads the report.

The Attacks

In a joint investigation exercise between PhishLabs R.A.I.D (Research, Analysis & Intelligence Division) & Akamai Technologies Prolexic Security Engineering and Response Team (PLXsert), the PLXsert experts examined the traffic signature(digital footprints) from Joomla distributions in DDoS attacks. The attack campaigns in close observation reveals that the traffic signature match the sites well known for nefarious activities involving services such a DDoS-for-Hire

"Another trait in these signatures is the lack of a User-Agent HTTP header in a majority of the requests. However some boxes that use the PHP curl request include a User-Agent string that contains the PHP version used by the curl_exec() request.", says report.

The Vulnerability

A serious Google Maps vulnerability was discovered which allows the attackers to turn the Joomla servers integrated with Google Maps plugins into a hacking tool for DDoS attacks. What makes these joomla reflection DDoS attacks exponentially successful is the aspect of it being low cost & easy to run.Yes, luck can sometimes rub the shoulder of billion dollar companies the wrong way with easy & economical campaigns. The observation of traffic indicates a similarity with attacks which use tools specifically designed to corrupt XML and Open Redirect functions, which in return produce a reflected response. This reflection technique takes the advantage of IP or application vulnerability which easily gives access to DDoS attackers to directly reflect malicious traffic to a 3rd party device or a server. Many experts at PLXsert believe that reflection techniques are very commonly used for DDoS attacks and Google Maps vulnerability makes it simple for attackers to get it act as a proxy.

Technical Details

DAVOSET tool which is used to make Joomla reflection attacks more efficient contains a default list of servers which comes in handy for exploiting the Google Maps vulnerability of the plugins which convert them into DDoS reflector machines.

Google Maps Vulnerability

Google Maps Vulnerability Google Maps Vulnerability

UFONet is the other tool which is generally used to automate reflection attacks as it is simple to run Joomla Reflection DDoS attacks with it.

Google Maps Vulnerability

"After Effects" (The Damage)

Akamai researchers and experts have examined various Joomla sites attacked by hackers since September last year with close to 1.5lakh vulnerable sites which could be used as a Joomla Reflector with attacks still continuing in early 2015 with the primary source of traffic of attacks is from Germany(31.8%) with US coming close(22.1) followed by Poland(17.9).

Google Maps Vulnerability

DDoS Mitigation

PLXsert has identified the following three DDoS mitigation procedures that can help mitigate this attack vector. These recommendations are by no means exhaustive and should not be taken as a sole means of DDoS protection.

  • Block HTTP GET /1.0 request traffic if support for legacy clients is not needed.
  • Block HTTP requests with a PHP-based User-Agent string if they are not needed.
  • Use the three Snort rules provided in Figure 10. The signature can be adapted to other mitigation techniques in order to detect or block these DDoS attacks.

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.