Attacks/Breaches
2/16/2012
08:58 AM
50%
50%

Anonymous-Backed Attacks Took Nasdaq Website Offline

NASDAQ and BATS stock exchanges, and the Chicago Board Options Exchange (CBOE), were knocked offline earlier this week by hacktivists. Nasdaq emphasizes that stock trading remained unaffected.

Anonymous: 10 Facts About The Hacktivist Group
Anonymous: 10 Facts About The Hacktivist Group
(click image for larger view and for slideshow)
The websites of the Nasdaq and BATS stock exchanges, together with the Chicago Board Options Exchange (CBOE), were offline earlier this week after a hacktivist group with apparent Anonymous ties targeted them with distributed denial of service (DDoS) attacks. But while customers were intermittently unable to use some of the exchanges' websites, all said that their trading systems weren't affected.

The attacks had been previewed the day before they were launched. In a post to Pastebin, a group calling itself "the 'L0NGwave99' cyber group" said Sunday it was going to launch "Operation Digital Tornado" in support of the "99% movement" Monday at 9 a.m. New York time. A later message promised the same for Tuesday.

"The NASDAQ stock exchange besides a number of U.S. stock markets are going to face some problems and may need maintenance," said the L0NGwave99 statement, which promised to launch DDoS-driven takedowns against www.nasdaq.com, www.batstrading.com (BATS), www.cboe.com (CBOE), and www.ms4x.com (the Miami Stock Exchange).

"Will anybody be able to stop the people?s (sic) storm of seeking justice against the liar and deceptive Capitalism-Liberalism? Soon we will see..." read the group's statement.

[ Worried? Read 10 Strategies To Fight Anonymous DDoS Attacks. ]

The attack purportedly involved members of Anonymous. According to a Tuesday post to "TheAnonMessage" Twitter channel, "#Anonymous, in cooperation with #LONGwave99, have successfully taken down the #NASDAQ website." According to news reports, the BATS and CBOE sites were also only intermittently available, although the Miami Stock Exchange website appears to have remained online.

Nasdaq confirmed Tuesday that some of its public websites, including its nasdaqtrader.com portal for customer communications, had been partially unreachable during the DDoS attacks. "During the past 24 hours, Nasdaq OMX has experienced intermittent service disruptions on our corporate websites," according to a statement released by the company. "We are working with our Internet service providers to resolve these issues."

But Nasdaq emphasized that stock trading had remained unaffected. "The website wasn't hacked, nobody got any information. What they did was try to block access for our users," Nasdaq spokesman Joseph Christinat told Reuters.

Likewise, BATS issued a statement saying that it had suffered a DDoS attack, but noted that "our trading systems were not affected and there were no exchange customer disruptions associated with the incident."

These aren't the first DDoS attacks launched against stock exchanges--though a previous, supposedly Anonymous-led campaign against the New York Stock Exchange was labeled as a fake by members of Anonymous.

This also isn't the first attack leveled specifically at Nasdaq. Notably, the Nasdaq OMX Group revealed last year that attackers had managed to hack into Nasdaq's Directors Desk, a cloud-based service designed for facilitating discussions and collaboration between senior-level executives and corporate board members, including the exchange of confidential, regulated financial information. While the company has declined to offer full details about the attack, citing an ongoing FBI investigation, security experts have noted that the hackers may have been able to glean information that could have been used for insider trading purposes.

Furthermore, according to sources briefed on the FBI's investigation, Nasdaq was "easy pickings" for attackers, owing to poor patching, firewall misconfigurations, as well as outdated software, reported Reuters. But a senior Nasdaq manager has disputed that assertion, saying that very difficult to block advanced malware--of a type he declined to specify--had been used to breach the company's defenses.

The right forensic tools in the right hands are just a start. The new Digital Detectives issue of Dark Reading shows you how to better apply the lessons they teach. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Printers: The Weak Link in Enterprise Security
Kelly Sheridan, Associate Editor, Dark Reading,  10/16/2017
20 Questions to Ask Yourself before Giving a Security Conference Talk
Joshua Goldfarb, Co-founder & Chief Product Officer, IDDRA,  10/16/2017
Why Security Leaders Can't Afford to Be Just 'Left-Brained'
Bill Bradley, SVP, Cyber Engineering and Technical Services, CenturyLink,  10/17/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.