Jump to content

New DDoS attack uses smartphone browsers to flood site with 4.5bn requests

jos
Researchers suspect a mobile advertising network has been used to point hundreds of thousands of smartphone browsers at a website with the aim of knocking it offline.
According to distributed denial-of-service protection service CloudFlare, one customer's site recently came under fire from 4.5 billion page requests during a few hours, mostly from smartphone browsers on Chinese IP addresses.
 browser-based 'Layer 7' flood attacks have been viewed as a theoretical threat for several years, but haven't become a reality due to difficulties in efficiently distributing malicious JavaScript to force a large number of browsers to make HTTP requests to a targeted site.
Here's how the attack works: when a user opens an app or browses the web, they are served an iframe with an ad whose content was requested from an ad network. The ad network then forwards the request to a third-party that successfully bids for that inventory and then forwards the user to an attack page.
"The user was served an attack page containing a malicious JavaScript which launched a flood of XHR requests against CloudFlare servers,"

 

 
As the usage of smartphone increases.. smartphones will become  main center of attack... It is just people just keep on getting smartphone... I does not care if it is apple, google, Microsoft or any other platform...

 

Link to comment
Share on other sites

Link to post
Share on other sites

Topkek.

"Try not to take things personally; what people say about you on the internet is a reflection of them, not you!"

Link to comment
Share on other sites

Link to post
Share on other sites

New DDoS attack uses smartphone browsers to flood site with 4.5bn requests

Researchers have found that smartphone browsers can deliver a powerful flooding attack.

 

---

Researchers suspect a mobile advertising network has been used to point hundreds of thousands of smartphone browsers at a website with the aim of knocking it offline.

According to distributed denial-of-service protection service CloudFlare, one customer's site recently came under fire from 4.5 billion page requests during a few hours, mostly from smartphone browsers on Chinese IP addresses.

As CloudFlare's Marek Majkowski notes, browser-based 'Layer 7' flood attacks have been viewed as a theoretical threat for several years, but haven't become a reality due to difficulties in efficiently distributing malicious JavaScript to force a large number of browsers to make HTTP requests to a targeted site.

Security researchers have previously suggested web ads as an efficient way to distribute malicious JavaScript.

Analysing the log files, Majkowski found the smartphone browser attack peaked at over 275,000 HTTP requests per second, with 80 percent coming from mobile devices and 98 percent from a Chinese IP address. The logs also reveal mobile versions of Safari, Chrome, Xiaomi's MIUI browser, and Tencent's QQBrowser.

"Strings like 'iThunder' might indicate the request came from a mobile app. Others like 'MetaSr', 'F1Browser', 'QQBrowser', '2345Explorer', and 'UCBrowser' point towards browsers or browser apps popular in China," Majkowski said.

Majkowski speculates that the attack was made possible by an ad network, and believes the reason so many mobile browsers visited the attack page hosting the malicious JavaScript was due to ads shown in iframes, either in mobile apps or mobile browsers.

 

"The user was served an attack page containing a malicious JavaScript which launched a flood of XHR requests against CloudFlare servers," explained Majkowski.

The attack site itself hosting the malicious JavaScript included instructions to launch an XHR in a loop.

 

 

 

http://www.zdnet.com/article/new-ddos-attack-uses-smartphone-browsers-to-flood-site-with-4-5bn-requests/

(Copy & pasted for those who don't trust external links) <_<

Chooser of the Slain

Link to comment
Share on other sites

Link to post
Share on other sites

Seriously, why do people even bother doing these things? It's so pointless...  <_<

Exactly. It's fucking pointless and the people that do it are useless asshat scumbags.

Main rig on profile

VAULT - File Server

Spoiler

Intel Core i5 11400 w/ Shadow Rock LP, 2x16GB SP GAMING 3200MHz CL16, ASUS PRIME Z590-A, 2x LSI 9211-8i, Fractal Define 7, 256GB Team MP33, 3x 6TB WD Red Pro (general storage), 3x 1TB Seagate Barracuda (dumping ground), 3x 8TB WD White-Label (Plex) (all 3 arrays in their respective Windows Parity storage spaces), Corsair RM750x, Windows 11 Education

Sleeper HP Pavilion A6137C

Spoiler

Intel Core i7 6700K @ 4.4GHz, 4x8GB G.SKILL Ares 1800MHz CL10, ASUS Z170M-E D3, 128GB Team MP33, 1TB Seagate Barracuda, 320GB Samsung Spinpoint (for video capture), MSI GTX 970 100ME, EVGA 650G1, Windows 10 Pro

Mac Mini (Late 2020)

Spoiler

Apple M1, 8GB RAM, 256GB, macOS Sonoma

Consoles: Softmodded 1.4 Xbox w/ 500GB HDD, Xbox 360 Elite 120GB Falcon, XB1X w/2TB MX500, Xbox Series X, PS1 1001, PS2 Slim 70000 w/ FreeMcBoot, PS4 Pro 7015B 1TB (retired), PS5 Digital, Nintendo Switch OLED, Nintendo Wii RVL-001 (black)

Link to comment
Share on other sites

Link to post
Share on other sites

Seriously, why do people even bother doing these things? It's so pointless...  <_<

Its usually one of three things.

1: Money

2: Because they just want to watch the world burn

3: "For da lolz"

Da Rig : Mobo: Asus M5A97-r2.0 | Cpu: FX-8320 (4.1ghz) Stock cooler | Gpu: Sapphire R9 290 | RAM: 16GB Patriot Intel Extreme (1600mhz...for now >:]) | PSU: Antec 620w continuous | SSD: Corsair Force 60gb (boot) | HDD: WD 500GB 7200rpm  WD Blue 1TB | OS: WIndows 7 Ultimate 64-bit |

Link to comment
Share on other sites

Link to post
Share on other sites

3: "For da lolz"

 

But it's not even funny... all that happens is that a website goes down.

i7 4790K || R9 290X + R9 290 || 16GB G.Skill TridentX 1866 || Gigabyte Z97MX Gaming 5 || Crucial MX100 256GB || WD Caviar Blue 1TB

Link to comment
Share on other sites

Link to post
Share on other sites

When all the smart devices come on line later. We shall see "Massive DDOS by millions of smart microwaves and refrigerators" "Website was DDOS by millions of smart cars".

 

Golden age for hackers.

 

You may laugh, but this has already supposedly happened... http://arstechnica.com/security/2014/01/is-your-refrigerator-really-part-of-a-massive-spam-sending-botnet/

Link to comment
Share on other sites

Link to post
Share on other sites

Skynet...* insert it's happening meme*

MARS_PROJECT V2 --- RYZEN RIG

Spoiler

 CPU: R5 1600 @3.7GHz 1.27V | Cooler: Corsair H80i Stock Fans@900RPM | Motherboard: Gigabyte AB350 Gaming 3 | RAM: 8GB DDR4 2933MHz(Vengeance LPX) | GPU: MSI Radeon R9 380 Gaming 4G | Sound Card: Creative SB Z | HDD: 500GB WD Green + 1TB WD Blue | SSD: Samsung 860EVO 250GB  + AMD R3 120GB | PSU: Super Flower Leadex Gold 750W 80+Gold(fully modular) | Case: NZXT  H440 2015   | Display: Dell P2314H | Keyboard: Redragon Yama | Mouse: Logitech G Pro | Headphones: Sennheiser HD-569

 

Link to comment
Share on other sites

Link to post
Share on other sites

Cant we just shoot these people and later throw them into the river for the piranhas to eat theyr remains?

 

What a waste of metal. I think we can just throw them into the river right away. If they somehow manage to get out, we can simply throw them back in. 

i7 4790K || R9 290X + R9 290 || 16GB G.Skill TridentX 1866 || Gigabyte Z97MX Gaming 5 || Crucial MX100 256GB || WD Caviar Blue 1TB

Link to comment
Share on other sites

Link to post
Share on other sites

But it's not even funny... all that happens is that a website goes down.

Its really funny to them but to the sane ones who are not idiots or immature we don't understand why its so funny. THey enjoy that we don't understand it and will use that to troll you. Such is the way of the internet and little shits that inhabit it

Da Rig : Mobo: Asus M5A97-r2.0 | Cpu: FX-8320 (4.1ghz) Stock cooler | Gpu: Sapphire R9 290 | RAM: 16GB Patriot Intel Extreme (1600mhz...for now >:]) | PSU: Antec 620w continuous | SSD: Corsair Force 60gb (boot) | HDD: WD 500GB 7200rpm  WD Blue 1TB | OS: WIndows 7 Ultimate 64-bit |

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×