Cyber Hacking News

Italian CERT: Hacktivists hit govt sites

0

Italy’s Computer Security Incident Response Team (CSIRT) has revealed recent DDoS attacks against government sites in the country over the past two days.

Pro-Russian hacktivists known as the Killnet group published a message to Telegram claiming responsibility for the attacks. They also stated that further attacks may also come in the future.

It is the same group that launched similar attacks against Romanian portals and the Bradley Airport in the US.

A Killnet representative posted a message, “Our Legion conducts military cyber exercises in your countries in order to improve their skills. Everything happens similarly to your actions – the Italians and the Spaniards are going to learn how to kill people in Ukraine. Our Legion is learning to kill your servers!,” “You must understand that this is training. Don’t make too much noise, I’m sick of the amount of news about attacks on the Senate. I give you my word of honor that our cyber army will soon finish training in your territory, and we will go on the offensive. It will happen suddenly and very quickly.”

Distributed denial of service (DDoS)is a malicious attempt to disrupt the normal traffic of a targeted server, making it unable to respond by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic.

CSIRT explained that the attacks on the country’s government, ministry, parliament, and even army websites, used the “Slow HTTP” technique. In this method, one HTTP request is sent at a time to webservers but sets the request at a very slow transmission rate or makes it incomplete, leaving the server waiting for the next request.

The server detects the incoming communication and allocates resources dedicated to waiting for the remaining data. When there are too many of these types of requests, the server is overwhelmed and cannot take any more connections, making the site inaccessible.

CSIRT emphasized that “slow HTTP” is an unusual type of DDoS attack and warns all system administrators that their existing defenses may not be effective if they are not targeted towards the attack. The team has shared techniques to mitigate this type of attack in their advisory.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Google I/O: New safety features include virtual payment cards

Previous article

Critical bug in Zyxel firewalls and VPNs exploited

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *