Domain shadowing the new kind of attack

Domain shadowing is a new type of attack. It is the latest evolution of online crime and is set up to endanger before security researchers and system administrators can react.hackers Domain shadowing

Cisco security researcher Nick Biasini reports that "massive" and ongoing that use Adobe Flash and Microsoft's Silverlight were launched in December, compared to the small, sporadic campaigns of 2011. Here's his breakdown:

"To Domain shadowing uses stolen registrant credentials, which are the most effective, difficult to exclude, with techniques used to date. Accounts are largely random, so there is no way of detection that will mislead the next victim domain.

In addition, subdomains are very popular, short-lived, and random, with no discernible patterns. This fact makes locking them increasingly difficult. Finally, the . It's getting progressively harder to get active samples from the page set up by an exploit kit after it's been active for less than an hour.”

Fast Flux versus Domain Shadowing
Fast Flux versus Domain Shadowing

 

Ο Biasini αναφέρει ότι οι επιθέσεις ξεκινούν με phishing which are supposed to come from the targeted registrar and are effective because most people don't regularly monitor their domain accounts.

Rotation speed (Fast Flux versus Domain Shadowing) is a new form of rapid flow that keeps emerging exploits out of the eyes of security researchers. Biasini says it is the new "industrialization of hacking."

One third of the 10.000 dummy domains used come from GoDaddy.

Domain Shadowing attacks on the up

The first series of individual domains is generally used to redirect victims to sub-level landing pages that host the Angler exploit kit.

You can read more about the new type of attack in the researcher's publication.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).