Feeds

Hackers now pick tools from script kiddies' toybox – report

Automated attack weapons help blackhats spread the pain

Protecting users from Firesheep and other Sidejacking attacks with SSL

Infosec 2012 Hackers are increasingly turning to automated software tools to launch attacks.

According to research from Imperva, more than 60 per cent of SQL injection attacks and as many as 70 per cent of Remote File Inclusion attacks (the two most common attack types) are automated. Remote File Inclusion attacks allows hackers to plant back doors on PHP-based websites.

Tools like Havij and SQLMap are used by miscreants to probe for vulnerabilities and execute SQL injection attacks. These tools also employ techniques to evade detection, such as periodically changing headers or splitting attacks through controlled hosts to avoid black-listing. In the past, using attack tools was purely for script kiddies but these attitudes are changing, according to Rob Rachwald, director of security strategy at Imperva.

Automatic attack tools aren't just for the clueless anymore, he says. These tools can be used to attack more applications and exploit more vulnerabilities than any manual method possibly could, making them a useful adjunct for even skilled attackers. "Automated tools are becoming better quality. Both experienced and inexperienced hackers use them but experienced hackers use them with more finesse," Rachwald explained.

By contrast, organisations still struggle to embrace automatic defences, often deploying technologies such as intrusion prevention systems in "alert only" mode. Rachwald argued that too much focus was being placed on attacks based on spear-phishing and malware (ie, advanced persistent threat attacks) at the expense of overlooking more commonplace assaults, such as SQL injection attacks.

Automated attacks have specific traffic characteristics such as rate, rate change and volume, all factors which can be used to fingerprint and block automated attacks. For example, IP addresses associated with automated attacks can be blocked. ®

Havij means "carrot" in Farsi, which is also the slang word for penis in Iran. The tool was developed by an Iranian blackhat with an obvious taste for crude humour. SQLMap, unlike Havij, is a command-line tool.

The next step in data security

More from The Register

next story
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
'Speargun' program is fantasy, says cable operator
We just might notice if you cut our cables
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.