Vietnam.vn - Nền tảng quảng bá Việt Nam

Microsoft confirms Azure, Outlook, and OneDrive services were disrupted due to a DDoS attack.

Báo Thanh niênBáo Thanh niên20/06/2023


Microsoft says these attacks use access to multiple virtual private servers (VPS) in combination with cloud infrastructure rentals, proxies, and distributed denial-of-service (DDoS) attack tools. Storm-#### (formerly DEV-####) is a temporary designation that the Windows owner assigns to unidentified, emerging, or developing groups whose identity or affiliation has not been clearly established.

While there was no evidence that any customer data was accessed illegally, Microsoft said the attacks temporarily affected the availability of some services. The Redmond-based company said it had further observed the group launching Layer 7 DDoS attacks from multiple cloud services and open proxy infrastructures.

It involves mass attacks on target services with a large volume of HTTP(S) requests; the attacker attempts to bypass the CDN layer and overload the servers using a technique known as Slowloris.

Microsoft's Security Response Center (MSRC) stated that these DDoS attacks originate from clients opening connections to web servers, requesting resources (e.g., images) but failing to confirm downloads or delaying acceptance, forcing the server to keep the connection open and the requested resources in memory.

Microsoft xác nhận dịch vụ Azure, Outlook và OneDrive bị gián đoạn vì bị DDoS - Ảnh 1.

Anonymous Sudan claims responsibility for the DDoS attack on Microsoft services.

As a result, Microsoft 365 services such as Outlook, Teams, SharePoint Online, and OneDrive for Business experienced outages in early May, with the company stating it detected an anomaly from the surge in request rates. Traffic analysis revealed that a large number of HTTP requests bypassed existing automatic safeguards and triggered service unavailability responses.

The hacker group Anonymous Sudan claimed responsibility for the attacks, but Microsoft did not link Storm-1359 to them. Anonymous Sudan had previously launched DDoS attacks against organizations in Sweden, the Netherlands, Australia, and Germany since the beginning of the year.

Analysts at Trustwave said the group openly links to Russia's KillNet, which often uses the narrative of protecting Islam as a justification for its attacks. KillNet also gained attention for DDoS attacks targeting healthcare organizations hosted on Microsoft Azure, which saw nearly 60 attacks daily in February 2023.

Anonymous Sudan collaborated with KillNet and REvil to form the "DARKNET parliament" and orchestrated cyberattacks on financial institutions in Europe and the US, with the primary objective of paralyzing SWIFT operations. Flashpoint's records indicate KillNet's motives were primarily financial, using Russian support to promote its rented DDoS services.



Source link

Comment (0)

Please leave a comment to share your feelings!

Same tag

Same category

The Christmas atmosphere is vibrant on the streets of Hanoi.
Enjoy the exciting night tours of Ho Chi Minh City.
A close-up view of the workshop making the LED star for Notre Dame Cathedral.
The 8-meter-tall Christmas star illuminating Notre Dame Cathedral in Ho Chi Minh City is particularly striking.

Same author

Heritage

Figure

Enterprise

The moment Nguyen Thi Oanh sprinted to the finish line, unrivaled in 5 SEA Games.

News

Political System

Destination

Product