OPISRAEL).
" />

OPUSA


April 29, 2013 02:00 PM

AnonGhost – A hacking group affiliated with Anonymous announced a new cyber-attack campaign against US websites named #OPUSA, scheduled for May 7th, 2013.

The planned attack follows a similar attack campaign organized by AnonGhost that took place exactly one month earlier – on Apr 7th, 2013 and was launched against Israeli web sites (aka OPISRAEL).

Similar to OPISRAEL, several cyber hacking groups, including Anonymous, have announced their participation in the upcoming attack. One noticeable group, although not yet confirmed, is Izz ad-Din al-Qassam cyber fighters, which is considered to be responsible for the recent attacks on American banks and financial institutions.

Dozens of U.S based sites have been already defaced, mainly to validate the threats made so far. As in past campaigns, it is expected the initial attacks will involve web site defacement of poorly protected sites. Once the campaign gains publicity and enrolls additional attackers, we can expect coordinated DDoS attacks to start taking place. The various groups participating in #OPUSA have published the attack targets, tools and techniques on several sites. The following is a summary of the information gathered from these sites.

Attack Tools

Though larger lists of attack tools were published, we expect these attack tools to be the most frequently used in OPUSA:

Attack Vectors

The DDoS attack vectors most expected from the attacks tools include:

  • SYN Floods
  • Out-Of-State floods
  • Empty Connection Floods
  • UDP Floods
  • HTTP GET Floods
  • Slow POST Floods
  • Slow GET Floods
  • ICMP floods
  • DNS Query floods
  • Reflected DNS floods

Attack Targets

US government sites are the main target of the OPUSA attack:

  • www.defense.gov
  • pentagontours.osd.mil
  • www.pentagonchannel.mil
  • www.archives.gov
  • www.whs.mil
  • www.nsa.gov
  • nsa.nato.int
  • www.fbi.gov
  • www.whitehouse.gov

Secondary attack targets include a long list of US (and US located) financial web sites.

与Radware销售部门接洽

我们的专家将回答您的问题、评估您的需求,并帮助您了解哪些产品最适合您的业务。

已经是客户?

无论您需要支持或更多服务,还是需要解答有关我们产品和解决方案的问题,我们都会随时提供帮助。

公司地点
马上从知识库获得答案
获得免费在线产品培训
联系Radware技术支持部
加入Radware客户计划

参与社交

联系专家并加入有关Radware技术的对话。

Blog
安全研究中心
CyberPedia