On BNET: Online porn struggles for profits
BNET Business Network:
BNET
TechRepublic
ZDNet

December 1st, 2008

AlertPay hit by a large scale DDoS attack

Posted by Dancho Danchev @ 8:07 am

Categories: Anti Virus, Botnets, Denial of Service (DoS), Hackers, Malware, Pen testing

Tags: Security, Cybercrime, DDoS, Distributed Denial of Service Attack, Payment Processor, AlertPay, Online Payment System, Online Payment Gateway, Dancho Danchev

AlertPay - Online Payment GatewayTiming is everything. Millions of account holders at privately owned online payment gateway AlertPay.com weren’t able to do business through the service yesterday, due to the fact that AlertPay was under a large scale DDoS attack, according to a notice left by a company representative. Seven hours of downtime right in the middle of the Christmas shopping season with millions of businesses using the service affected, isn’t coincidental. This DDoS attack, just like the recent DDoS attack again a popular anti-fraud site, may have well been outsourced.

AlertPay’s statement on the situation posted yesterday :

“We are currently expericing a large scale DDOS attack that has hit our sites which started at approximately 6:00am EST Sunday.  We are working with our data center to resolve and/or mitigate this issue.  More information will be posted here as we get updates. For the time being customers can connect to AlertPay at an alternate location: https://67.205.87.226″

Several hours later, AlertPay issued an update to the situation :

“We have finally mitigated the massive DDOS attack that started at 6:00am EST.  Unfortunately it took almost all day to resolve.  The site is operational now, and hopefully we’ll continue to tweak it more tomorrow to ensure this doesn’t happen again. We sincerely apologize for the inconvenience and we understand that this outage affects each of you personally.  We’re sorry for that.  We will continue to put measures in place so that outages like this do not occur again.

Ferhan”

There are two possible explanations regarding who’s behind the DDoS attack. It’s either unethical competition which in times of international economic meltdown can easily restore its market position by damaging the reputation and reliability of known competitor, or cybercriminals in “revenge mode” against a particular online payment processor that has detected their fraudulent activity, thereby causing them huge monetary losses. Despite the fact that online payment gateways have always been targets for DDoS extortionists, with malicious attackers introducing new models like the DDoS for hire one, they have empowered literally everyone knowing how to contact them with the opportunity to forward the responsibility for an attack to a third-party. Here’s a brief retrospective of DDoS attacks against online payment processors that took place during the last couple of years, with only a single instance of DDoS extortion :

With DDoS extortion as a business model largely replaced by today’s DDoS for hire services, we’re inevitably going to witness more attacks throughout 2009.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 8 Talkback(s)
RE: AlertPay hit by a large scale DDoS attack
Hello, I don,t know what is DDoS attack, but I am glad to be able to contact with you AlerPay by that way too and would like to have an email if you had one, to baranyfelho@net-tv.hu. I am just starti... (Read the rest)
Posted by: baranyfelho Posted on: 01/02/09 You are currently: a Guest | | Terms of Use
They make devices that quickly mitigate DDOS attacks  Been_Done_Before | 12/01/08
Spoken like a true newbie  URAMoron | 12/01/08
The alternative: Net cops  progan01@... | 12/01/08
RE: AlertPay hit by a large scale DDoS attack  donkeyfluffer | 12/16/08
RE: AlertPay hit by a large scale DDoS attack  donkeyfluffer | 12/16/08
RE: AlertPay hit by a large scale DDoS attack  donkeyfluffer | 12/17/08
RE: AlertPay hit by a large scale DDoS attack  dubjax | 12/19/08
RE: AlertPay hit by a large scale DDoS attack  baranyfelho | 01/02/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here