Network Security Lean Security Expert Network Security Lean Security Expert

Bots, Bots Everywhere: 5 Largest DDoS Attacks in the History of the Internet

We know how a DDoS attacks can overwhelm a system’s resources and take it down to the ground.  

We know how a DDoS attacks can overwhelm a system’s resources and take it down to the ground.  

But sometimes DDoS attacks can scale beyond our wildest imaginations. We’re talking about attacks that clock bandwidths in tera and giga bite ranges and notoriously leave their marks in history books.

Spamhaus

Spamhaus is a non-profit anti-spam organization based in London and Geneva.

In 2013, Spamhaus website, email servers and DNS IPs were taken down by a DDoS attack that measured in at 300 gigabits per second.

Investigations traced the attack to a member of Dutch company named Cyberbunker.

CloudFlare

CloudFlare is a content delivery network (CDN) and security service provider headquartered in San Francisco.

In 2014, CloudFlare’s network was slammed by a DDoS attack that peaked at more than 400 gigabits per second.

The attack was originally directed at a CloudFlare customer, but it was so powerful that it brought down the company’s entire network to its knees.   

The perpetrators leveraged the NTP servers to launch the attack.

Occupy Central Movement

Occupy Central was a Hong Kong civil disobedience campaign initiated by Benny Tai, Reverend Chu Yiu-ming and Dr. Chan Kin-man in 2013, advocating for a democratic electoral system.

Unimpressed by the movement, attackers sent large amount of traffic to Occupy Central’s webhosting services, causing the servers to crash.

The DDoS attack recruited five botnets and measured in at 500 gigabits per second.

2) Dyn

Dyn, Inc. is an internet performance management and web application security company based in the U.S.

In 2016, Dyn was targeted by a series of DDoS attacks which spiked up to 1.2 terabits per second.  The attacks used mirai-infected IoT-enabled devices to bombard the company’s servers.

The SpainSquad, New World Hackers and Anonymous claimed the responsibility for the attacks.

GitHub

GitHub is a code hosting platform for collaboration and version control.

On February 28, 2018, GitHub was taken down by a DDoS attack that clocked in at a whopping 1.35 terabits per second.  

Interestingly, the attack did not use any botnet network, and instead relied on misconfigured Memcached servers for amplification.   

The attack remains the largest DDoS attack ever recorded in the history of the internet. 

Is your business protected against potential DDoS attacks? Don’t be vulnerable; call our cybersecurity experts today and make sure you’re covered from any and all threats.    

Read More
Lean Security Expert Lean Security Expert

Cloud-Based Mobile Application Testing—What Should You Focus On?

Here are some important things to focus while getting your application tested through a cloud-based server.

As the mobile app industry thrives globally, Australia has also observed a stark increase in the usage of mobile applications over the past few years. The total revenue generated by Australian mobile app industry was expected to be $2 billion between the years 2018–2019. This increased demand also calls for quality and secure experience.

Understanding Mobile App Security

To measure the performance of applications, every mobile application has to pass standard tests and checks. And one of the most techniques for testing apps is cloud-based testing. Hiring a service provider for cloud-based app testing allows business owners to simulate the hardware of a device virtually. This significantly reduces the time required to check a mobile application for threats and vulnerabilities.

What Comes Next?

If you’re all set to get your application checked, you need to consider a few points beforehand. Here are some important things to focus while getting your application tested through a cloud-based server.

Know About Your Device

Testing your device on a cloud isn’t as easy as it seems. You need to learn about the type of your machine and all the other devices and technologies that are compatible with it. It might be possible that the platform of your app doesn’t support cloud computing. This can be a major problem for business owners.

development process of your mobile app.png

 

During the development process of your mobile app, prioritize all the security tests. Learn about the model of your device, system software and core information of your app to ensure compatibility with your cloud server.

Infrastructure Issues

Your services provider might not be able to provide all the relevant resources for a cloud-based mobile app testing. They might need to create the testing environment from scratch for you. This can create a huge hurdle during your procedure, wasting a lot of time and money.

 

Before selecting a security consultant, make sure they have the necessary technology, configuration, and storage space to carry out your security checks.

Cost of the Procedure

Before you start working with a company to test your business application on a virtual server, it’s better to learn about any hidden charges. Amateurs often end up using test environments incorrectly. This can result in a sudden rise in the cost of the testing procedure.

To avoid this, make sure to plan your testing procedure in detail with the vendor and consider all additional costs like data encryption and extra use of resources.

For sophisticated and trustworthy cloud-based testing, secure cloud managed hosting and mobile application penetration testing, contact Lean Security at 61 (2) 8078 6952. Our wide range of services can help you detect all sorts of software vulnerabilities.

Read More
Lean Security Expert Lean Security Expert

Web Application Security Testing: Focusing on Certain Areas of Web App

Here are some important aspects that should be considered before you perform a security test on your web application.

Nowadays, businesses are highly depended on web-based data. The Australian e-commerce market experienced a growth of 11.5% from 2016–2017 and has been following a similar trend since then. A huge amount of data is exchanged, stored and transferred through online platforms on a daily basis.

With such a rapid rate of growth, accountability and security of online assets are of utmost priority for all businesses. Therefore, companies are advised to carry out necessary tests to ensure the safety of their websites and online applications.

Stringent web security tests are imperative in the modern world. It ensures that confidential information remains safe from malicious online attacks and hackers. It makes sure that only authorized users can access sensitive data.

Here are some important aspects that should be considered before you perform a security test on your web application.

Keep Strong Login Credentials:

A user name and password of your online site plays a key role in its protection. And hackers are always finding tools to crack this information.  All they need is to guess possible keywords for your login credentials. Once they find their way in, they can access your applications inside and out.

Login Credentials.png

 

Web security testing will help you detect vulnerabilities in your application such as your password strength. Therefore, it’s always advised to keep a complex password, something that isn’t easy to guess. Weak passwords are cracked easily and hacked by cybercriminals, leaving your information vulnerable.

Regular Checks:

This is one of the most crucial steps for securing web platforms. But it’s often neglected or forgotten. Businesses that store customer information should perform routine checks. These tests will check for potential vulnerabilities and threats to your application.

This step is often considered a compulsory requirement by many government industries. It should be followed regularly during web application security testing.

Software Testing Practices:

During software development, security testing should be one of the first steps and shouldn’t be neglected at any cost. Don’t leave security tests for the end. Perform an early security test while you design the website or application for your business.

If any vulnerability is identified during the process, it can be a huge setback in the development of your application. Involve your development operation team to reduce the risk and cost of remediation.

Fixing Bugs:

During the process of security testing, the development team often finds vulnerabilities called software bugs. Rather than making a list of these issues to be solved later on in the development cycle, it’s a great approach to fix them at hand. Prioritize these fixes and avoid delays.

mobile application penetration test.png


If you’re looking for an expert opinion on the advanced web security testing and mobile application penetration test, get in touch with Lean Security. Our services will safely secure all of  your confidential data.

Read More
Lean Security Expert Lean Security Expert

How to Keep Your Website Safe from a DDoS Attack

If you consider your website vulnerable to such attacks, it’s time you look into some preventative measures. Here are a few tips to prevent your website from a DDoS attack.

While the internet has opened endless possibilities for businesses, the risk of threats from cybercrime has also increased considerably. As of July 2019, more than 4000 malware programs attack the Australian population on a daily basis. And one of the most common and malicious attacks among these threats is a DDoS attack.

A DDoS attack can wreck the foundation of any website and can prove to be troublesome for website owners. Such attacks send fake traffic toward a website, causing it to crash. Websites lacking proper protection against hackers and viruses are usually the victims of such threats.

If you consider your website vulnerable to such attacks, it’s time you look into some preventative measures. Here are a few tips to prevent your website from a DDoS attack.

Invest in Quality Hardware:

The main purpose of a DDoS attack is to flood your website with excessive traffic. This can be detected by quality hardware. Your network hardware receives traffic in the form of voltages. A high spike indicates a sudden rush of traffic, which can be prevented by appropriate electronic components. This includes your router, a quality data transferring cable and network switches.

 

You should modify the firewall settings of your network to block out such attacks and keep your website safe.

Use a Strong Network:

Hackers usually look for the weakest targets on a website that are vulnerable to such attacks. If your website isn’t maintained by a strong network and a powerful hosting server, you’re an easy target in the pool.

penetration testing services.png

 

To eliminate vulnerabilities, keep your system up to date. Don’t forget to update the version of WordPress, if you’re using one. Ask your hosting provider to upgrade their software and systems regularly.

Increase Internet Bandwidth:

The aftermath of DDoS results in a crashed website. The main reason why it happens is a small network bandwidth. Your internet bandwidth is unable to handle such a high amount of traffic sent by a hacker. This completely destroys your online platform.

To avoid this issue, buy extra bandwidth to combat the sudden surge of data. Increase the capacity of your server to manage a large amount of traffic efficiently. This way, your website will work fine even after a DDoS attack.

Avail DDoS Mitigation Service:

DDoS mitigation services act as a filter that removes all the excess traffic from your server, allowing only genuine traffic to visit your website. It’s an excellent option for multinational companies and large-scale businesses. Small businesses can opt for a managed hosting service.

For quality security consultancy and penetration testing services, contact Lean security. Give us a call at 61 (2) 8078 6952.

Read More