GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 01-Nov-2024 03:09:04 JST Kevin Beaumont Kevin Beaumont

    Kingdom Bank in the UK have got their online banking available in the past 30 minutes by... changing the URL. It's now https://onl1ne44.kingdom.bank

    As before it's behind Microsoft Azure Application Gateway.

    Many of the NoName victims over the last few days use Azure Application Gateway. I've been in touch with a few - they have DDoS mitigation enabled in the Azure service, but it doesn't work against NoName doing basic attacks. This includes councils etc.

    #NoName #threatintel

    In conversation about 7 months ago from cyberplace.social permalink

    Attachments


    1. https://cyberplace.social/system/media_attachments/files/113/403/360/570/333/864/original/19e7b500a294137b.png

    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 13-Sep-2024 20:34:42 JST Kevin Beaumont Kevin Beaumont

      NoName057(16) are targeting their DDoS infrastructure at the UK and will announce shortly.

      So far none of the attacks are successful as they’re being defended against.

      They may do a cheesy video to go with it. #threatintel

      In conversation about 9 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 13-Sep-2024 20:56:07 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If you’re wondering what they’re targeting their “DDoS missiles”at, it’s some tram and ferry information websites #threatintel #noname

      In conversation about 9 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 13-Sep-2024 21:38:14 JST Kevin Beaumont Kevin Beaumont
      in reply to

      NoName announcement went out. #threatintel #noname

      In conversation about 9 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/130/277/781/681/358/original/8c176609028d79c9.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 14-Sep-2024 18:53:25 JST Kevin Beaumont Kevin Beaumont
      in reply to

      NoName continue to send “DDoS missiles” to the UK - they’re unsuccessfully targeting bus information websites in two towns.

      They plan announcement of their attack later today.

      #threatintel #noname

      In conversation about 9 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 14-Sep-2024 18:55:38 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Or how the cyber industry assesses NoName #threatintel #noname

      In conversation about 9 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/135/302/022/136/545/original/adc2078bd75627b4.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 28-Oct-2024 18:17:19 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Noname are upset at UK gov today, targets - they may have some success as most are new.

      * www.mossley-council.co.uk
      * oneonline.bradford.gov.uk
      * www.bradford.gov.uk
      * resident.dacorum.gov.uk
      * www.keighley.gov.uk
      * youraccount.salford.gov.uk
      * www.tameside.gov.uk
      * www.bury.gov.uk
      * www.dacorum.gov.uk
      * www.southampton.gov.uk
      * www.liverpool.gov.uk
      * my.trafford.gov.uk
      * www.salford.gov.uk
      * www.hertfordshire.gov.uk
      * www.stalbans.gov.uk
      * www.dudley.gov.uk

      #threatintel #noname

      In conversation about 8 months ago permalink

      Attachments


      1. No result found on File_thumbnail lookup.
        Account Suspended


      2. No result found on File_thumbnail lookup.
        Welcome to MyDacorum - MyDacorum











    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 28-Oct-2024 18:22:02 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If any of the targeted councils want a hand give me a shout, I can give you the botnet config which will give you an idea what to block (you’ll need a WAF first).

      Normally they recycle the same old, already mitigated config for the UK - they finally made a new one today. #threatintel #noname

      In conversation about 8 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 28-Oct-2024 18:46:59 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Announcement is out. #threatintel #noname

      In conversation about 8 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/384/410/352/824/388/original/a117401686d113d1.png
    • Embed this notice
      OSPF110 ☕ (ospf110@cyberplace.social)'s status on Monday, 28-Oct-2024 19:19:14 JST OSPF110 ☕ OSPF110 ☕
      in reply to

      @GossiTheDog Lol always makes me laugh when I see Keighley and Bradford on these lists. Didn't realise those big power houses of the north had so much say in foreign policy 😂

      In conversation about 8 months ago permalink
    • Embed this notice
      gwire (gwire@mastodon.social)'s status on Monday, 28-Oct-2024 21:39:16 JST gwire gwire
      in reply to

      @GossiTheDog I guess Dacorum Borough Council is going to have to reassess their foreign policy?

      In conversation about 8 months ago permalink
    • Embed this notice
      lp0 on fire :unverified: (lp0_on_fire@social.linux.pizza)'s status on Monday, 28-Oct-2024 21:39:31 JST lp0 on fire :unverified: lp0 on fire :unverified:
      in reply to

      @GossiTheDog, “Prime Minister KEIRA Starmer”‽ (insert really bad-taste joke here)

      In conversation about 8 months ago permalink
    • Embed this notice
      jascar (jascar@cyberplace.social)'s status on Monday, 28-Oct-2024 23:16:27 JST jascar jascar
      in reply to

      @GossiTheDog what would be the best way to contact you?

      In conversation about 8 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 29-Oct-2024 03:54:58 JST Kevin Beaumont Kevin Beaumont
      in reply to

      NoName’s config is still targeting those UK councils. Makes a change from bus shed websites. #threatintel #noname

      In conversation about 8 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 29-Oct-2024 22:49:45 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Today #NoName are upset with three orgs in Ukraine, 3 financial services orgs in the UK, BAE and 3 UK councils. #threatintel

      In conversation about 8 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/391/022/910/676/130/original/64bc9e4aeaad8475.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 29-Oct-2024 22:58:41 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Only the two councils are impacted still.

      Eastleigh are using Azure App Service, which collapsed for them.

      Trafford Council are using on prem webserver, which couldn't cope with load.

      The problematic DDoS configs attached, $_1 is a variable for random gibberish - they basically stuff the search feature.

      In conversation about 8 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/391/047/248/603/496/original/80b8c98dc931da23.png

      2. https://cyberplace.social/system/media_attachments/files/113/391/049/823/028/532/original/f31fc316c856f68a.png

      3. https://cyberplace.social/system/media_attachments/files/113/391/060/012/593/604/original/2097ab443a0987bd.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 31-Oct-2024 03:16:07 JST Kevin Beaumont Kevin Beaumont
      in reply to

      #NoName continue to be mad at UK county councils.

      They're rotating through different councils and will be having much success this week, I imagine they will do a victory lap by Friday.

      Councils - contact the NCSC for assistance. I can give you the full botnet configs if it helps - kevin.beaumont@gmail.com

      The long story short is turn off the search feature or put a WAF - Web Application Firewall - in front of your services and use it to filter out the requests in the botnet conf.

      In conversation about 8 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/397/725/934/934/686/original/f6dfa641d19d89b2.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 31-Oct-2024 03:19:28 JST Kevin Beaumont Kevin Beaumont
      in reply to

      One other thing for UK councils to note, NoName store the configs and rotate them. E.g. by tomorrow morning, around 6am UK time, they'll likely change to different councils.

      But they will periodically rotate back to the same attack config whenever "Keira" (they can't spell the PMs name) does something they don't like. E.g. they've been doing the same attack at liverpool.gov.uk for over a year intermittently, despite it being mitigated nowadays. So have a process on how to deal the next time.

      In conversation about 8 months ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 31-Oct-2024 15:21:05 JST Kevin Beaumont Kevin Beaumont
      in reply to

      #NoName setting up for UK runs again today - they’re stopping councils and reconfiguring for transport and financial services. They usually go for obviously weakly protected systems.

      In conversation about 7 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 01-Nov-2024 03:21:28 JST Kevin Beaumont Kevin Beaumont
      in reply to

      This is the advanced* DDoS btw, see if you can spot how the rate limiting in Azure Front Door WAF isn't exactly well equipped for NoName arriving with 20k source IP addresses from Ddosia.

      In other news, you may have noticed Microsoft have shifted many of their customer facing services from Azure Front Door to behind Akamai in recent times.

      In conversation about 7 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/403/395/759/130/119/original/f6564ccc31a0aaeb.png

      2. https://cyberplace.social/system/media_attachments/files/113/403/411/013/811/485/original/161be40d0a5ae74f.png

    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 01-Nov-2024 03:28:31 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The other pattern for the past week is orgs with on prem systems, either just directly internet exposed or - more likely - behind BIG-IP.

      Having a big link and DDoS scrubbing doesn't work on prem if you allow inbound web requests unfiltered - NoName just send valid HTTP requests from 20k systems at the same time 24/7 to search pages.

      Orgs need cloud WAFs.

      Another thought - somebody like the NCSC needs to provide a managed, central WAF service to councils. They can't deal with this stuff.

      In conversation about 7 months ago permalink
    • Embed this notice
      Bálint Szilakszi (szbalint@x0r.be)'s status on Friday, 01-Nov-2024 05:40:37 JST Bálint Szilakszi Bálint Szilakszi
      in reply to

      @GossiTheDog 20k isn’t even a large number of systems, i regularly see probing ddos attempts with many multiples of that

      Councils definitely can’t self-manage ddos mitigation

      In conversation about 7 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 02-Nov-2024 19:51:14 JST Kevin Beaumont Kevin Beaumont
      in reply to

      NoName is back to targeting 15 UK council sites this weekend, they've recycled config from earlier in the week.

      Unfortunately a majority have fallen over again.

      Councils should contact NCSC for assistance (what assistance there is I don't know). I can give you configs for what pages are being targeted if needed.

      #NoName #threatintel

      In conversation about 7 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/412/965/303/895/790/original/f25fafd92daef40c.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 02-Nov-2024 19:56:56 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Btw, if you use Azure's anti-DDoS - it doesn't work against NoName because the rate limiting in Front Door sucks. The best move right now is disable or change the URL they are targeting. It's usually a search page.

      NoName can adapt the config to change to a different URL.. but they usually don't bother, e.g. they use the same config that doesn't work on Liverpool.gov.uk for over a year, even today.

      In conversation about 7 months ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Sunday, 03-Nov-2024 16:40:12 JST Kevin Beaumont Kevin Beaumont
      in reply to

      #NoName UK targeting today - 12 councils, 4 UK banks.

      They're targeting my.kingdom.bank - which you may remember up thread, doesn't exist any more as the bank changed the URL. So their online banking remains online today.

      In conversation about 7 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Sunday, 03-Nov-2024 19:00:15 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody is interested, out of the 12 councils targeted today, 7 are okay, 5 have websites down for past 4 hours.

      In conversation about 7 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/418/424/925/162/231/original/ee4aeeb6f0b0d9f7.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 04-Nov-2024 01:25:36 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The same five UK council websites have been down for 10 hours consecutively now. #NoName #threatintel

      In conversation about 7 months ago permalink
    • Embed this notice
      Hambone Fakenamington (centuryavocado@fosstodon.org)'s status on Monday, 04-Nov-2024 04:16:48 JST Hambone Fakenamington Hambone Fakenamington
      in reply to

      @GossiTheDog cardiff loads for me.

      In conversation about 7 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 04-Nov-2024 05:36:53 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Cardiff.gov.uk returned a few hours ago, burnley.gov.uk in the past 5 minutes. #NoName #threatintel

      In conversation about 7 months ago permalink

      Attachments



    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 04-Nov-2024 16:48:46 JST Kevin Beaumont Kevin Beaumont
      in reply to

      #NoName have moved on to South Korea, probably for the rest of the week.

      Any UK orgs hit during the prior week, they'll return with same config later whenever PM upsets them - they always do. So do some mitigations in advance.

      In conversation about 7 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 04-Nov-2024 16:52:52 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The Return of The Councils

      In conversation about 7 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/423/595/943/872/149/original/4209aa7ff3d027e7.png

    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 06-Nov-2024 03:26:23 JST Kevin Beaumont Kevin Beaumont
      in reply to

      swcouncils.gov.uk just came back online, after several days outage. #NoName #threatintel

      In conversation about 7 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/431/749/309/758/636/original/9853db9c2ca7a376.png

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.