-->

whaust

2020年4月1日 星期三

10 BEST DDoS Attack Tools in 2020 [Free/Paid]

10 BEST DDoS Attack Tools in 2020 [Free/Paid]

DoS (Denial of Service) is an attack used to deny legitimate user's access to a resource such as accessing a website, network, emails, etc. Distributed Denial of Service (DDoS) is a type of DoS attack that is performed by a number of compromised machines that all target the same victim. It floods the computer network with data packets.

There are numerous DDoS attack tools that can create a distributed denial-of-service attack against a target server. Following is a handpicked list of DDoS Attack Tools, with their popular features and website links. The list contains both open source(free) and commercial(paid) software.

1) LOIC (Low Orbit ION cannon)

LOIC (Low Orbit ION cannon) is open-source software use for DDoS attack. This tool is written in C#. This tool sends HTTP, TCP, and UDP requests to the server.
Features:
  • LOIC helps you to test the performance of the network.
  • It enables you to create a DDoS attack against any site that they control.
  • Loic does not hide an IP address even if the proxy server is not working.
  • It helps you to perform stress testing to verify the stability of the system.
  • This software can be used to identify programs that may be used by hackers to attack a computer network.
Link: https://sourceforge.net/projects/loic/

2) HOIC (High Orbit ION cannon)

High Orbit Ion Cannon is a free denial-of-service attack tool. It is designed to attack more than one URLs at the same time. This tool helps you to launch DDoS attacks using HTTP (Hypertext Transfer Protocol).
Features:
  • You can attack up to 256 websites at once.
  • It has a counter that helps you to measure the output.
  • It can be ported over to Linux or Mac OS.
  • You can choose the number of threads in the current attack.
  • HOIC enables you to control attacks with low, medium, and high settings.
Link: https://sourceforge.net/projects/highorbitioncannon/

3) HTTP Unbearable Load King (HULK)

HTTP Unbearable Load King (HULK) is a web server DDoS tool. It is specifically used to generate volumes of traffic at a webserver.
Features:
  • It can bypass the cache server.
  • This tool helps you to generate unique network traffic.
  • HTTP Unbearable Load King (HULK) can be easily used for research purposes.
Link: https://packetstormsecurity.com/files/112856/HULK-Http-Unbearable-Load-King.html

4) DDoSIM (DDoS Simulator)

DDoSIM (DDoS Simulator) is a tool that is used to create a distributed denial-of-service attack against a target server. It is written in C++ and can be used on the Linux operating system.
Features:
  • This tool indicates the capacity of the server to handle application-specific DDOS attacks.
  • It enables you to create full TCP connections to the target server.
  • DDoSIM provides numerous options to perform a network attack.
  • TCP connections can be flooded on a random network port.
  • Configuration & Installation
    • 1. ./configure
    • 2. make
    • 3. make install
    • sudo install apt-get install libnet-dev (if show Error you need libnet0)
      • sudo apt install autoconf automake libtool
      • git clone https://github.com/libnet/libnet.git
      • ./autogen.sh
      • ./configure && make
      • sudo make install 
      • (未完代續)
    • sudo install apt-get install libpcap (if show Error you need libpcap)

Link: https://stormsecurity.wordpress.com/2009/03/03/application-layer-ddos-simulator/

5) PyLoris

PyLoris is a software product for testing network vulnerability by performing Distributed Denial of Service (DDoS) attack online. It helps you to control poorly manage concurrent connections.
Features:
  • It provides easy to use GUI (Graphic User Interface).
  • This tool enables you to attack using HTTP request headers.
  • It has the latest codebase (collection of source code used to build a particular software system).
  • You can run PyLoris using Python script.
  • This tool supports Windows, Mac OS, and Linux.
  • It provides an advanced option having a limitation of 50 threads, each with a total of 10 connections.
Link: https://motoma.io/pyloris/

6) OWASP HTTP POST

The OWASP (Open Web Application Security Project) HTTP Post software enables you to test your web applications for network performance. It helps you to conduct denial of service from a single machine.
Features:
  • It allows you to distribute and transmit the tool with others.
  • You can freely use this tool for commercial purposes.
  • OWASP HTTP POST helps you to share the result under the license it provides.
  • This tool enables you to test against the application layer attacks.
  • It helps you to decide the server capacity.
Link: https://www.owasp.org/index.php/OWASP_HTTP_Post_Tool

7) RUDY

RUDY is a short form of R-U-Dead-Yet. It helps you to perform the DDoS attack with ease. It targets cloud applications by starvation of sessions available on the web server.
Features:
  • This is a simple and easy tool.
  • It automatically browses the target website and detects embedded web forms.
  • R-U-Dead-Yet enables you to conduct HTTP DDoS attack using long-form field submission.
  • This tool provides an interactive console menu.
  • It automatically identifies form fields for data submission.
Link: https://sourceforge.net/projects/r-u-dead-yet/

8) Tor's Hammer

Tor'shammer is an application-layer DDoS program. You can use this tool to target web applications and a web server. It performs browser-based internet request that is used to load web pages.
Features:
  • It allows you to create rich text markup using Markdown (a plain text formatting syntax tool).
  • Tor's Hammer automatically converts the URL into links.
  • This app uses web server resources by creating a vast number of network connections.
  • You can quickly link other artifacts in your project.
  • It holds HTTP POST requests and connections for 1000 to 30000 seconds.
Link: https://sourceforge.net/projects/torshammer/

9) DAVOSET

DAVOSET is software for committing DDOS attacks via abuse of any website functionality. This command line tool helps you to commit distributed denial of service attacks without any hassle.
Features:
  • It provides support for cookies.
  • This tool provides a command-line interface to perform an attack.
  • DAVOSET can also help you to hit attack using XML external entities (attack against an app that parses XML input).
Link: https://packetstormsecurity.com/files/123084/DAVOSET-1.1.3.html

10) GoldenEye

GoldenEye tool conducts a DDoS attack by sending an HTTP request to the server. It utilizes a KeepAlive message paired with cache-control options to persist socket connection busting.
Features:
  • This tool consumes all the HTTP/S sockets on the application server for the DDoS attack.
  • It is easy to use app written in Python.
  • Arbitrary creation of user agents is possible.
  • It randomizes GET, POST to get the mixed traffic.

Source : https://www.guru99.com/ddos-attack-tools.html

2020年3月30日 星期一

NTP Attack... (Oh my god)

弱點在那兒 ?


2020/03/28 爆出這一個月以來最大量流量
結果查的結果是NTP 攻擊



很難想像, 數量有多少.





  • NTP Amplification REQ_MON_GETLIST Request Found: 47,411,882 次 


  • NameNTP Amplification REQ_MON_GETLIST Request Found
    Unique Threat ID36343
    Description
    This alert indicates that there is a REQ_MON_GETLIST_1 request on NTP. If this event happened many times within a short period of time, it could indicate that someone is trying to brute force and cause DOS on the NTP server.  
    Categorydos
    PanOS Minimum Version6.1.0
    PanOS Maximum Version
    Severityinformational
    Actionallow
    CVE
    CVE-2013-5211  
    Vendor ID
    First Release421 (2014-02-25 UTC)
    Last Update599 (2016-07-20 UTC)
    Reference
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5211, https://www.us-cert.gov/ncas/alerts/TA14-013A  
    Statusreleased



  • NTP Amplification Denial-Of-Service Attack : 46,687,487




  • NameNTP Amplification Denial-Of-Service Attack
    Unique Threat ID40038
    Description
    This event indicates that someone is using a brute force attack to perform DOS attack to a NTP server. It is leverage CVE-2013-5211, which is the monlist feature vulnerability of NTP.  
    Categorybrute-force
    PanOS Minimum Version6.1.0
    PanOS Maximum Version
    Severitylow
    Actionalert
    CVE
    CVE-2013-5211  
    Vendor ID
    First Release421 (2014-02-25 UTC)
    Last Update599 (2016-07-20 UTC)
    Reference
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5211, https://www.us-cert.gov/ncas/alerts/TA14-013A  
    Statusreleased

    尖峰時段



    半小時 73.809k 次攻擊

    73.809 x 1000 / 30 / 60 = 41次/sec

    一秒鐘大概 41次


    從PRTG上看, 對總量影響不大, 但是對客戶上網就會變慢
    搞不懂這樣攻擊的目的是什麼 ?

    L7 Threat Log filter 2020/03/30

    ( name-of-threatid eq 'Mirai.Gen Command And Control Traffic' ) OR ( name-of-threatid eq 'Gafgyt.Gen Command And Control Traffic' ) OR
    ( name-of-threatid eq 'ZeroAccess.Gen Command and Control Traffic' ) OR ( name-of-threatid eq 'NJRat.Gen Command and Control Traffic' ) OR
    ( name-of-threatid eq 'SIPVicious Scanner Detection' ) OR ( name-of-threatid eq 'Metasploit VxWorks WDB Agent Scanner Detection' ) OR
    ( name-of-threatid eq 'Backdoor.gafgyt:switchnets.net' ) OR
    ( name-of-threatid eq 'Multiple CCTV-DVR Remote Command Injection Vulnerability' ) OR
    ( name-of-threatid eq 'TVT-Digital CCTV-DVR Remote Code Execution Vulnerability' ) OR
    ( name-of-threatid eq 'Netis/Netcore Router Default Credential Remote Code Execution Vulnerability' ) OR
    ( name-of-threatid eq 'RPC Portmapper DUMP Request Detected' ) OR
    ( name-of-threatid eq 'NTP Amplification REQ_MON_GETLIST Request Found' ) OR
    ( name-of-threatid eq 'NTP Amplification Denial-Of-Service Attack' )

    Threat List from 2020/03/28 - 2020/03/30

    Top 20 Threats




    Top 100 Threats

    ---------------------------







    NTP Amplification REQ_MON_GETLIST Request Found
    NTP Amplification Denial-Of-Service Attack
    Non-RFC Compliant DNS Traffic on Port 53/5353
    Suspicious TLS Evasion Found
    Telnet Authentication Failed
    Windows SMB Login Attempt
    Suspicious HTTP Evasion Found
    MSSQL DB Login Authentication Failed
    MSSQL Login failed for user 'sa' execution
    SMB: User Password Brute Force Attempt
    Telnet Authentication Brute Force Attempt
    Microsoft SQL Server User Authentication Brute Force Attempt
    Virus.mirai:ciqrgscslt.hopto.org
    SIPVicious Scanner Detection
    Microsoft Windows SMB Negotiate Request
    Non-RFC Compliant TELNET Traffic on Port 23
    Non-RFC Compliant FTP Traffic on Port 21
    DNS ANY Request
    Non-RFC Compliant DNS Traffic on Port 53/5353
    NetBIOS null session
    HTTP Non-RFC Compliant Request
    Non-RFC Compliant HTTP Traffic on Port 80
    Abnormal SSL traffic on port 443
    Mirai.Gen Command And Control Traffic
    Gafgyt.Gen Command And Control Traffic
    Non-RFC Compliant SSL Traffic on Port 443
    Non-RFC Compliant DNS Traffic on Port 53/5353
    HTTP Unauthorized Error
    POODLE Bites Vulnerability
    Netis/Netcore Router Default Credential Remote Code Execution Vulnerability
    Microsoft Communicator INVITE Flood Denial of Service Vulnerability
    Suspicious HTTP Response Found
    Non-RFC Compliant DNS Traffic on Port 53/5353
    RPC Portmapper DUMP Request Detected
    SSH2 Login Attempt
    HTTP Non RFC-Compliant Response Found
    SIP Register Request Attempt
    HTTP WWW-Authentication Failed
    Non-RFC Compliant TELNET Traffic on Port 23
    Suspicious or malformed HTTP Referer field
    HTTP Unauthorized Brute Force Attack
    DNS ANY Queries Brute Force DOS Attack
    Use of insecure SSLv3.0 Found in Server Response
    JavaScript Obfuscation Detected
    SIP Invalid Sent-by Address Found
    Suspicious JavaScript Evasion Detected
    Suspicious DNS Query (Virus.virut:formatmcl.gicp.net)
    PHP DIESCAN Information Disclosure Vulnerability
    Suspicious DNS Query (Virus.virut:formatmcl.gicp.net)
    NetBIOS nbtstat query
    GTPv1 Echo Request Message
    Metasploit VxWorks WDB Agent Scanner Detection
    Non-RFC Compliant TFTP Traffic on Port 69
    Non-RFC Compliant HTTP Traffic on Port 80
    DDoS.nitol:iamnull.no-ip.org
    Malware.mdrop:xmr.pool.minergate.com
    DNS Long qname Detection
    JavaScript Obfuscation Detected
    Non-RFC Compliant HTTP Traffic on Port 80
    JavaScript Obfuscation Detected
    HTTP: User Authentication Brute Force Attempt
    dropper.Gen Command And Control Traffic
    Non-RFC Compliant MS-DS-SMB Traffic on Port 445
    Non-RFC Compliant MS-DS-SMB Traffic on Port 445
    IP Address Disclosure Detection
    SIP Malformed Request: Unknown URI Schemes in Header Fields
    Non-RFC Compliant HTTP Traffic on Port 80
    Non-RFC Compliant NTP Traffic on Port 123
    SSH User Authentication Brute Force Attempt
    HTTP OPTIONS Method
    Backdoor.gafgyt:switchnets.net
    Non-RFC Compliant MS-DS-SMB Traffic on Port 445
    Non-RFC Compliant MS-DS-SMB Traffic on Port 445
    ASUS/Netcore Router Default Credential Remote Code Execution Vulnerability
    JavaScript Obfuscation Detected
    Non-RFC Compliant HTTP Traffic on Port 80
    Suspicious DNS Query (Virus.sality:alain.forgeot.free.fr)
    SIP Register Message Brute Force Attack
    TrojanDropper.delfsnif:0x0ss.sytes.net
    XMRig Miner Command and Control Traffic Detection
    Morto RDP Request Traffic
    SSH2 Failed Login Attempt
    Non-RFC Compliant SMTP Traffic on Port 25
    Bifrose Command And Control Traffic
    generic:bt.7081.com
    generic:download.zzb5.cn
    Non-RFC Compliant HTTP Traffic on Port 80
    Failed Authentication Through Mail Protocol
    Suspicious File Downloading Detection
    Non-RFC Compliant DNS Traffic on Port 53/5353
    flystudio.buqi C2 traffic
    generic:deepsecu.com
    Suspicious DNS Query (trojan.softcnapp:i.fahpvdxw.cn)
    VBScript Obfuscation
    Avtech Devices Unauthenticated Command Injection Vulnerability
    Multiple CCTV-DVR Remote Command Injection Vulnerability
    Ncrack RDP scan
    Microsoft Windows SMB Remote Code Execution Vulnerability
    generic:transmapp.com

    Summary of National Cyber Security Current Situation Survey in 2019



    Summary of National Cyber Security Current Situation Survey in 2019

    In order to understand the current status of the first year implementation of the Cyber Security Management Act, cyber threats encountered and protection measures by government agencies and schools at various cyber security responsibility levels, to review the completeness of the cyber security protection as the reference for the subsequent development of the cyber security policy. Through the National Cyber Security Current Situation Survey in 2019, we will review the current status of cyber security protection of the government agencies and schools, used them as references for drafting the National Cyber Security Program, and promoting the Cyber Security Management Act and various cyber security protection mechanisms.

    There were 1,877 government agencies and 2,209 schools completed this survey.  In this online survey, the response rate of government agencies at all levels were above 60%, of which the agencies with cyber security responsibility level A and B reached 80%. The response rate of schools at all levels was close to 60%, of which colleges and universities reached 70%. The response rates are not only enough to reflect the current situation of the whole group, but also shows that units with higher cyber security responsibility levels will pay more attention to cyber security preparation.

    In terms of the 2019 security budget planning, the overall increase is much larger than the previous survey.  The total security budget increased from 2.84 billion to 3.417 billion compared with 2017, and the overall cyber security funding ratio increased from 9.2% to 10.79%.  The allocation of cyber security personnel, more than half of the government agencies with cyber security responsibility level A and B follow the requirements of the Cyber Security Management Act.  The procurement of domestic security products (including services) with nearly 40% of government agencies purchase more than 80% of domestic products, which shows that high security level of government agencies with a high trust in domestic products.  To deal with matters, most of government agencies and schools’ core information systems at all levels have been implemented ISMS and passed third-party verification.  On the information asset management system, the government agencies with cyber security level A and B shows better performance.  The most of cyber security incidents in 2018 were hacking and trespass.  The biggest worry of cyber security was the interruption of network and information services.

    This survey is conducted in every two years.  The purpose of this survey is to understand the current situation of government agencies and schools in the first year implementation of the Cyber Security Management Act, the cyber threats encountered and the protective measures taken, review the completeness of the cyber security protection, use the survey result as the reference for the future development of cyber security policies, and to build a comprehensive cyber security environment for Taiwan.



    2019年我國資安現況調查摘要

    為了解各資安責任等級之政府機關與學校於資通安全管理法施行第一年之情況,以及所遭遇之資安威脅與其防護措施,透過2019年資安現況調查,檢視政府機關與學校之資安防護完備性,以做為擬定國家資通安全發展方案、推動資通安全管理法及建立資安防護機制之參考。
    本次調查,共1,877個政府機關與2,209個學校完成問卷調查,政府機關樣本回收率達6成以上,其中資安責任等級A級與B級政府機關更高達8成;學校樣本回收率也近6成,其中大專院校回收率達7成,足以推論母體的現況。同時,調查結果也顯示資安責任等級愈高之政府機關與學校,對於資安愈重視。

    2019年資安預算編列方面,總資安預算較2017年28.4億提高至34.17億,整體資安經費占資訊經費比例自9.2%提高至10.79%;資安專職人員配置方面,超過6成之資安責任等級A、B級政府機關符合資安法規定;採購國內資安產品(服務)比例方面,近4成之政府機關採購國產品比例超過8成,資安責任等級愈高之政府機關對於國產品之信任度與資安產品自主發展政策之配合度愈高;資安法應辦事項方面,政府機關與學校之核心資通系統已導入及通過第三方驗證,各項資安防護要求已逐步落實;導入資訊資產管理系統部分,資安責任等級A、B級政府機關導入情形較佳;2018年發生資安事件來源,以駭客最多,而事件類型以非法入侵最多;政府機關與學校最大的資安隱憂為網路與資通服務中斷。

    綜覽上述資安調查結果,資安責任等級A級與B級政府機關與學校大致符合資安法規定,期未來所有政府機關與學校均能符合資安法之法遵要求。本調查每2年進行一次,本次調查主要在了解政府機關與學校在資安法施行後第一年之執行情況,以及所遭遇之資安威脅及其防護措施,檢視資通安全防護之完備性,以做為擬定資通安全政策之參考。


    Source : https://nicst.ey.gov.tw/Page/7AB45EB4470FE0B9/285fd050-3090-4fd9-ad3b-19b9c0b63d0e

    2020年3月28日 星期六

    Popular