Wednesday, 12 March 2014

DDoS Attack Is Launched From 162,000 Wordpress Sites

Last Monday hackers attacked over 162,000 Wordpress powered Websites. With Some old trick they were able to perform a distributed-denial-of-service attack against another websites. The Wordpress is a Content Management System by which user can go right to the login page with login credentials and after verification of information—they redirect into Dashboard. Security Firm Securi said that these Hackers have exploited a well known flaw that allows an attack to be amplified by attaching unwary websites. They still don’t confirm that which site the victim but they confirms site went down for hours. With a massive attack websites admin and Web hosting provider is not aware, to prevent such attack but just restore the site and move on further not taking any precaution. There are several website still running on outdated versions of Wordpress so one must be updated in order to stop hacking.


Securi CEO Daniel Cid said "It was a large HTTP-based (layer 7) distributed flood attack, sending hundreds of requests per second to their server All queries had a random value (like "? 4137049=643182?) That bypassed their cache and force a full page reloads every single time. It was killing their server pretty quickly.While hundreds of requests per second don't seem that big when looking at other recent DDoS attacks.. Can you see how powerful it can be? One attacker can use thousands of popular and clean Wordpress sites to perform their DDOS attack, while being hidden in the shadows.”

Hacker altered a huge number of website and makes them attack on other website which is vulnerableto the DDoS attack; Hackers tear apart over 162,000 different and legitimate Wordpress site in just a course of hours. They have detected many sites but then decided to block request at the edges with firewall. This massive attack was made possible by just a tiny XML-RPC file, which giving a ping back.

Here is some security Tips from Security Experts on Worpress Sites

Friday, 7 March 2014

Congressman deprecate SXSW for Allowing Snowden to Speak

After the Top secrete document of NSA leaked by contractor Edward Snowden, American Intelligence is chasing him but he was exiled to Russia and now he is invented to deliver a keynote at National Security Conference through Video conferencing. As reports says the American Security Intelligence is Keeping any on Information System around the world and on online activity, so the NSA’s congressman is in fear to disclose anything so Representative Mike Pompo, A member of house Intelligence Committee is asking the Festival South by Southwest to extract the invitation to Former Agency Contractor Snowden. He has already criticize the Snowden’s leak’s of thousands of Documents, added that his appearance through Video Conference would under estimate the “Fairness and Freedom” of the event, which supposed to promote.


Congressmansaid in a letterReturning to the U.S., I think, is the best resolution for the government, the public, and me, but it’s unfortunately not possible in the face of current whistle-blower protection laws. This discourse is undermined when a music, film and interactive conference and festival provides a venue to an at-large criminal, who has refused extradition to answer for his crimes in court, His presence will not advance the debate; it will merely create a circus. The questions include: Why did Snowden steal tactical military and strategic secrets? What is his relationship with Russia? Why didn’t he take the information to an inspector general or a member of Congress? Why is he not willing to come back the United States?


It seems that Surveillanceand online privacy is going to be the biggest topics of debate at 2014 SXSW Interactive Festival. And this is his First Live Interview after he leaked classified Documents last summer. Now he will be interviewed by American Civil Liberties, Union Technologist Christopher Soghoian at SXSW conference.

Previously Mike Defended NSA say it Keeping America Safe