2 weeks ago
2 weeks ago
3 weeks ago
Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.
We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.
In one of the biggest findings of the year after a series of disclosures since last 8 months it is now clear beyond doubt that the famous content framework "Joomla" is in the eye of the storm from attackers with malicious intents. The modus operandi is pretty clear with running exploitation campaigns which comprises a large numbers of servers, or Software-as-a-Service (SaaS) providers, which is being used to push malware and phishing campaigns as well as to serve as zombies in distributed denial of service (DDoS) botnets.
Vulnerabilities in web applications hosted by Software-as-a-Service providers continue to provide ammunition for criminal entrepreneurs. Now they are preying on a vulnerable Joomla plugin for which they have invented a new DDoS attack and DDoS-for-hire tools, said Stuart Scholly, senior vice president and general manager in the Security Business Unit at Akamai, in a statement. This is one more web application vulnerability in a sea of vulnerabilities with no end in sight. Enterprises need to have a DDoS protection plan in place to mitigate denial of service traffic from the millions of cloud-based SaaS servers that can be used for DDoS. reads the report.
In a joint investigation exercise between PhishLabs R.A.I.D (Research, Analysis & Intelligence Division) & Akamai Technologies Prolexic Security Engineering and Response Team (PLXsert), the PLXsert experts examined the traffic signature(digital footprints) from Joomla distributions in DDoS attacks. The attack campaigns in close observation reveals that the traffic signature match the sites well known for nefarious activities involving services such a DDoS-for-Hire
"Another trait in these signatures is the lack of a User-Agent HTTP header in a majority of the requests. However some boxes that use the PHP curl request include a User-Agent string that contains the PHP version used by the curl_exec() request.", says report.
A serious Google Maps vulnerability was discovered which allows the attackers to turn the Joomla servers integrated with Google Maps plugins into a hacking tool for DDoS attacks. What makes these joomla reflection DDoS attacks exponentially successful is the aspect of it being low cost & easy to run.Yes, luck can sometimes rub the shoulder of billion dollar companies the wrong way with easy & economical campaigns. The observation of traffic indicates a similarity with attacks which use tools specifically designed to corrupt XML and Open Redirect functions, which in return produce a reflected response. This reflection technique takes the advantage of IP or application vulnerability which easily gives access to DDoS attackers to directly reflect malicious traffic to a 3rd party device or a server. Many experts at PLXsert believe that reflection techniques are very commonly used for DDoS attacks and Google Maps vulnerability makes it simple for attackers to get it act as a proxy.
DAVOSET tool which is used to make Joomla reflection attacks more efficient contains a default list of servers which comes in handy for exploiting the Google Maps vulnerability of the plugins which convert them into DDoS reflector machines.

UFONet is the other tool which is generally used to automate reflection attacks as it is simple to run Joomla Reflection DDoS attacks with it.
Akamai researchers and experts have examined various Joomla sites attacked by hackers since September last year with close to 1.5lakh vulnerable sites which could be used as a Joomla Reflector with attacks still continuing in early 2015 with the primary source of traffic of attacks is from Germany(31.8%) with US coming close(22.1) followed by Poland(17.9).

PLXsert has identified the following three DDoS mitigation procedures that can help mitigate this attack vector. These recommendations are by no means exhaustive and should not be taken as a sole means of DDoS protection.