Text
Barbarians At The Gate(way)
Examination of actors, tools and defenses
#whoami
Dave Lewis
@gattaca
dave@akamai.com
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
W E F O U N D H I M !
M Y S T E RY S O LV E D !
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
It left me wanting…
Game Plan
Actors
Attacks
Tools
Trends
Data
Now what?
Actors: For Hire
Current(ish) prices on the
Russian underground market:
	Hacking corporate mailbox: $500
	Winlocker ransomware: $10-20
	Intelligent exploit bundle: $10-$3,000
	Hiring a DDoS attack: $30-$70/day, $1,200/month
	Botnet: $200 for 2,000 bots
	DDoS botnet: $700
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Actors: Bored Kids
B O R E D T E E N S
A N D
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
H A C K T I V I S T S
T H E
Actors: Nation States
S TA N D A R D V I L L A I N S
T H E R E A R E
A R C H V I L L A I N S
A N D T H E R E A R E
Actors: al-Qassam Cyber
Fighters, QCF
QCF is an Iranian group that has been focused on
attacking US and Canadian banks.
They use the Brobot botnet that attacks from
compromised servers. Using server hardware and
connection they can usually overwhelm scrubbers with
traffic.
Attacks
Attack Vectors Over HTTP
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Types of Attacks
SYN Floods
UDP Floods
ICMP Floods
NTP Amplification
HTTP Flood
Attacks: Volumetric
Your website can be
overwhelmed…
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Attacks: Application Layer
Application Layer DDoS
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Attacks: Extortion
DD4BC
Began by targeting sites with ransom demands
Failure to pay lead to increased $$$ to stop the attack
Earlier attacks focused on businesses that would avoid
reporting the attacks to law enforcement.
Once research published they relocated their campaigns
to APAC
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Attacks: Amplification
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Tools
Tools: Havij
Tools: Donut
Tools: Donut (con’t)
GET / HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-
flash, application/msword, application/vnd.ms-powerpoint, application/vnd.ms-excel, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705)
Host: www.foo.bar
Connection: Close
Tools: HULK
Tools: HULK (con’t)
GET /?NJB=VURZQ HTTP/1.1
Accept-Encoding: identity
Host: www.foo.bar
Keep-Alive: 112
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.1.3) Gecko/
20090913 Firefox/3.5.3
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Connection: close
Referer: http://www.foo.bar
Cache-Control: no-cache
Tools: LOIC
Tools: HOIC
Tools: Brobot	
Brobot is a PHP trojan that allows an attacker to take
control of a victim's compromised hosted Web server and
use it to launch DDOS attacks.
Tools: Mirai
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Tools: WGET
Trends
Media Grandstanding
Commoditization of DDoS
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
What’s your fancy?
What’s a Booter?
OK, What’s a Stresser?
Stressers or Booters
xBOOT
Flash Stresser
Hyper Stresser
Grim Booter
Anonymous Stresser
Titanium Stresser / Lizards
Big Bang Booter…and so on.
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Some other highlights
DDoS agents targeting Joomla and other SaaS apps
A heap-based buffer overflow vulnerability in Linux 
systems
Attackers using new MS SQL reflection techniques
Data breaches fueling login attacks 
OK so, attribution?
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Other Observations
SQLi
Local/Remote File Inclusion
Popping shells
PHP Injection
Malicious File upload
JAVA …best remote access platform ever!
SQL Injection…still
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Why this is a problem.
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Passwords
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
File Inclusions
Malicious Uploads
	KCFinder file upload vulnerability
	Open Flash Chart file upload vulnerability
(CVE-2009-4140)
	appRain CMF (uploadify.php) unrestricted file upload
exploit (CVE-2012-1153)
	FCKeditor file upload vulnerability (CVE-2008-6178)
Undead Army
Link: https://www.flickr.com/photos/scabeater/3272684874/sizes/o/
So, what to do?
SQL INJECTION IS A SOLVABLE PROBLEM
Harden systems
Work with your ISP on mitigation strategies
Use ACL lists to deal with known bad IPs
IP Rate limiting
PATCH PATCH PATCH
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
Howard
Schmidt
In memoriam
STATEOFTHEINTERNET.COM
Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017
A K A M A I I S H I R I N G !
A N D W I T H T H A T …
Grazie per aver ascoltato!
Questions?
Visit our booth!
Dave Lewis
@gattaca
dave@akamai.com

More Related Content

PPTX
Cyber Security in Multi Cloud Architecture - Luca Di Bari - Codemotion Rome 2017
PPTX
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
PDF
Cyber Wars in the Cyber Space - Andrea Pompili - Codemotion Rome 2017
PDF
Xamarin.Forms Performance Tips & Tricks - Francesco Bonacci - Codemotion Rome...
ODP
Container orchestration: the cold war - Giulio De Donato - Codemotion Rome 2017
PDF
Component-Based UI Architectures for the Web - Andrew Rota - Codemotion Rome...
PDF
S3, Cassandra or Outer Space? Dumping Time Series Data using Spark - Demi Be...
PPTX
Commodore 64 Mon Amour(2): sprite multiplexing. Il caso Catalypse e altre sto...
Cyber Security in Multi Cloud Architecture - Luca Di Bari - Codemotion Rome 2017
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Cyber Wars in the Cyber Space - Andrea Pompili - Codemotion Rome 2017
Xamarin.Forms Performance Tips & Tricks - Francesco Bonacci - Codemotion Rome...
Container orchestration: the cold war - Giulio De Donato - Codemotion Rome 2017
Component-Based UI Architectures for the Web - Andrew Rota - Codemotion Rome...
S3, Cassandra or Outer Space? Dumping Time Series Data using Spark - Demi Be...
Commodore 64 Mon Amour(2): sprite multiplexing. Il caso Catalypse e altre sto...

Viewers also liked (20)

PDF
Comics and immersive storytelling in Virtual Reality - Fabio Corrirossi - Cod...
PDF
Docker Inside/Out: the ‘real’ real-world of stacking containers in production...
PPTX
An Introduction to Apache Ignite - Mandhir Gidda - Codemotion Rome 2017
PDF
Kunos Simulazioni and Assetto Corsa, behind the scenes- Alessandro Piva, Fabr...
PDF
Galateo semi-serio dell'Open Source - Luigi Dell' Aquila - Codemotion Rome 2017
PPTX
The busy developer guide to Docker - Maurice de Beijer - Codemotion Rome 2017
PDF
Handle insane devices traffic using Google Cloud Platform - Andrea Ulisse - C...
PDF
Il game audio come processo ingegneristico - Davide Pensato - Codemotion Rome...
PDF
Meetup Code Garden Roma e Java User Group Roma: metodi asincroni con Spring -...
PDF
Monitoring Big Data Systems Done "The Simple Way" - Demi Ben-Ari - Codemotion...
PPTX
Microservice Plumbing - Glynn Bird - Codemotion Rome 2017
PPTX
Event-Sourcing your React-Redux applications - Maurice de Beijer - Codemotion...
PDF
From a Developer's POV: is Machine Learning Reshaping the World? - Simone Sca...
PDF
Microservices in GO - Massimiliano Dessì - Codemotion Rome 2017
PDF
Cyber Analysts: who they are, what they do, where they are - Marco Ramilli - ...
PDF
Unreal Engine 4 Blueprints: Odio e amore Roberto De Ioris - Codemotion Rome 2017
PDF
Web Based Virtual Reality - Tanay Pant - Codemotion Rome 2017
PDF
Thinking Functionally - John Stevenson - Codemotion Rome 2017
PDF
Invader Studios: sviluppatori da “Incubo” - Tiziano Bucci - Codemotion Rome ...
PDF
Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017
Comics and immersive storytelling in Virtual Reality - Fabio Corrirossi - Cod...
Docker Inside/Out: the ‘real’ real-world of stacking containers in production...
An Introduction to Apache Ignite - Mandhir Gidda - Codemotion Rome 2017
Kunos Simulazioni and Assetto Corsa, behind the scenes- Alessandro Piva, Fabr...
Galateo semi-serio dell'Open Source - Luigi Dell' Aquila - Codemotion Rome 2017
The busy developer guide to Docker - Maurice de Beijer - Codemotion Rome 2017
Handle insane devices traffic using Google Cloud Platform - Andrea Ulisse - C...
Il game audio come processo ingegneristico - Davide Pensato - Codemotion Rome...
Meetup Code Garden Roma e Java User Group Roma: metodi asincroni con Spring -...
Monitoring Big Data Systems Done "The Simple Way" - Demi Ben-Ari - Codemotion...
Microservice Plumbing - Glynn Bird - Codemotion Rome 2017
Event-Sourcing your React-Redux applications - Maurice de Beijer - Codemotion...
From a Developer's POV: is Machine Learning Reshaping the World? - Simone Sca...
Microservices in GO - Massimiliano Dessì - Codemotion Rome 2017
Cyber Analysts: who they are, what they do, where they are - Marco Ramilli - ...
Unreal Engine 4 Blueprints: Odio e amore Roberto De Ioris - Codemotion Rome 2017
Web Based Virtual Reality - Tanay Pant - Codemotion Rome 2017
Thinking Functionally - John Stevenson - Codemotion Rome 2017
Invader Studios: sviluppatori da “Incubo” - Tiziano Bucci - Codemotion Rome ...
Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017
Ad

Similar to Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017 (20)

PDF
Barbarians at the Gate(way) - Dave Lewis - Codemotion Amsterdam 2018
PDF
[2010 CodeEngn Conference 04] Max - Fighting against Botnet
PDF
Edge 2016 barbarians at the gateway
PPTX
Eradicate the Bots in the Belfry - Information Security Summit - Eric Vanderburg
PDF
about botnets
PDF
Modern cyber threats_and_how_to_combat_them_panel
PPT
091209 Mc Afee Roundtable
PPTX
Mcs2453 aniq mc101053-assignment1
PPTX
Surfing with Sharks KS ED TECH 2012
PPTX
DSS ITSEC 2013 Conference 07.11.2013 -Radware - Protection against DDoS
PDF
Taking the Fear out of WAF
PDF
Evolving Threat Landscapes Web-Based Botnet Through Exploit Kits and Scripts ...
PDF
Life Cycle And Detection Of Bot Infections Through Network Traffic Analysis
PDF
Taming botnets
PPT
Security threats facing SA businessess
PDF
Botnetsand applications
PPT
Malware Fighting
PPTX
Risk base approach for security management fujitsu-fms event 15 aug 2011
PPTX
Barbarians at the Gate(way) - Dave Lewis - Codemotion Amsterdam 2018
[2010 CodeEngn Conference 04] Max - Fighting against Botnet
Edge 2016 barbarians at the gateway
Eradicate the Bots in the Belfry - Information Security Summit - Eric Vanderburg
about botnets
Modern cyber threats_and_how_to_combat_them_panel
091209 Mc Afee Roundtable
Mcs2453 aniq mc101053-assignment1
Surfing with Sharks KS ED TECH 2012
DSS ITSEC 2013 Conference 07.11.2013 -Radware - Protection against DDoS
Taking the Fear out of WAF
Evolving Threat Landscapes Web-Based Botnet Through Exploit Kits and Scripts ...
Life Cycle And Detection Of Bot Infections Through Network Traffic Analysis
Taming botnets
Security threats facing SA businessess
Botnetsand applications
Malware Fighting
Risk base approach for security management fujitsu-fms event 15 aug 2011
Ad

More from Codemotion (20)

PDF
Fuzz-testing: A hacker's approach to making your code more secure | Pascal Ze...
PDF
Pompili - From hero to_zero: The FatalNoise neverending story
PPTX
Pastore - Commodore 65 - La storia
PPTX
Pennisi - Essere Richard Altwasser
PPTX
Michel Schudel - Let's build a blockchain... in 40 minutes! - Codemotion Amst...
PPTX
Richard Süselbeck - Building your own ride share app - Codemotion Amsterdam 2019
PPTX
Eward Driehuis - What we learned from 20.000 attacks - Codemotion Amsterdam 2019
PPTX
Francesco Baldassarri - Deliver Data at Scale - Codemotion Amsterdam 2019 -
PDF
Martin Förtsch, Thomas Endres - Stereoscopic Style Transfer AI - Codemotion A...
PDF
Melanie Rieback, Klaus Kursawe - Blockchain Security: Melting the "Silver Bul...
PDF
Angelo van der Sijpt - How well do you know your network stack? - Codemotion ...
PDF
Lars Wolff - Performance Testing for DevOps in the Cloud - Codemotion Amsterd...
PDF
Sascha Wolter - Conversational AI Demystified - Codemotion Amsterdam 2019
PDF
Michele Tonutti - Scaling is caring - Codemotion Amsterdam 2019
PPTX
Pat Hermens - From 100 to 1,000+ deployments a day - Codemotion Amsterdam 2019
PPTX
James Birnie - Using Many Worlds of Compute Power with Quantum - Codemotion A...
PDF
Don Goodman-Wilson - Chinese food, motor scooters, and open source developmen...
PDF
Pieter Omvlee - The story behind Sketch - Codemotion Amsterdam 2019
PDF
Dave Farley - Taking Back “Software Engineering” - Codemotion Amsterdam 2019
PDF
Joshua Hoffman - Should the CTO be Coding? - Codemotion Amsterdam 2019
Fuzz-testing: A hacker's approach to making your code more secure | Pascal Ze...
Pompili - From hero to_zero: The FatalNoise neverending story
Pastore - Commodore 65 - La storia
Pennisi - Essere Richard Altwasser
Michel Schudel - Let's build a blockchain... in 40 minutes! - Codemotion Amst...
Richard Süselbeck - Building your own ride share app - Codemotion Amsterdam 2019
Eward Driehuis - What we learned from 20.000 attacks - Codemotion Amsterdam 2019
Francesco Baldassarri - Deliver Data at Scale - Codemotion Amsterdam 2019 -
Martin Förtsch, Thomas Endres - Stereoscopic Style Transfer AI - Codemotion A...
Melanie Rieback, Klaus Kursawe - Blockchain Security: Melting the "Silver Bul...
Angelo van der Sijpt - How well do you know your network stack? - Codemotion ...
Lars Wolff - Performance Testing for DevOps in the Cloud - Codemotion Amsterd...
Sascha Wolter - Conversational AI Demystified - Codemotion Amsterdam 2019
Michele Tonutti - Scaling is caring - Codemotion Amsterdam 2019
Pat Hermens - From 100 to 1,000+ deployments a day - Codemotion Amsterdam 2019
James Birnie - Using Many Worlds of Compute Power with Quantum - Codemotion A...
Don Goodman-Wilson - Chinese food, motor scooters, and open source developmen...
Pieter Omvlee - The story behind Sketch - Codemotion Amsterdam 2019
Dave Farley - Taking Back “Software Engineering” - Codemotion Amsterdam 2019
Joshua Hoffman - Should the CTO be Coding? - Codemotion Amsterdam 2019

Recently uploaded (20)

PDF
CloudStack 4.21: First Look Webinar slides
PDF
OpenACC and Open Hackathons Monthly Highlights July 2025
PDF
Transform-Quality-Engineering-with-AI-A-60-Day-Blueprint-for-Digital-Success.pdf
PDF
Convolutional neural network based encoder-decoder for efficient real-time ob...
PPTX
Internet of Everything -Basic concepts details
PPTX
Module 1 Introduction to Web Programming .pptx
PDF
STKI Israel Market Study 2025 version august
PDF
Enhancing plagiarism detection using data pre-processing and machine learning...
PDF
Transform-Your-Streaming-Platform-with-AI-Driven-Quality-Engineering.pdf
PDF
Dell Pro Micro: Speed customer interactions, patient processing, and learning...
PDF
The-Future-of-Automotive-Quality-is-Here-AI-Driven-Engineering.pdf
PDF
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
PDF
“A New Era of 3D Sensing: Transforming Industries and Creating Opportunities,...
PPTX
Training Program for knowledge in solar cell and solar industry
PDF
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
PPTX
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
PDF
sustainability-14-14877-v2.pddhzftheheeeee
PPT
Geologic Time for studying geology for geologist
PPT
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
PDF
Comparative analysis of machine learning models for fake news detection in so...
CloudStack 4.21: First Look Webinar slides
OpenACC and Open Hackathons Monthly Highlights July 2025
Transform-Quality-Engineering-with-AI-A-60-Day-Blueprint-for-Digital-Success.pdf
Convolutional neural network based encoder-decoder for efficient real-time ob...
Internet of Everything -Basic concepts details
Module 1 Introduction to Web Programming .pptx
STKI Israel Market Study 2025 version august
Enhancing plagiarism detection using data pre-processing and machine learning...
Transform-Your-Streaming-Platform-with-AI-Driven-Quality-Engineering.pdf
Dell Pro Micro: Speed customer interactions, patient processing, and learning...
The-Future-of-Automotive-Quality-is-Here-AI-Driven-Engineering.pdf
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
“A New Era of 3D Sensing: Transforming Industries and Creating Opportunities,...
Training Program for knowledge in solar cell and solar industry
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
sustainability-14-14877-v2.pddhzftheheeeee
Geologic Time for studying geology for geologist
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
Comparative analysis of machine learning models for fake news detection in so...

Barbarians at the Gate(way) - Dave Lewis - Codemotion Rome 2017