HTTP DDoS attack mitigation using tarpitting
Recently, the anti-spam organization Spamhaus has come under yet another distributed denial-of-service attack. With some help from our good friends at myNetWatchman we were able to obtain a sample of the malware used in the attack. This one is particularly nasty, starting up 1500 threads to send randomized HTTP requests to Spamhaus' webserver in a loop. This attack tool doesn't have a command-and-control mechanism, so it was likely force-installed on all the infected systems of an existing botnet.
[ Read more ]