ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

AlertPay hit by a large scale DDoS attack

By | December 1, 2008, 8:07am PST

Summary: Timing is everything. Millions of account holders at privately owned online payment gateway AlertPay.com weren’t able to do business through the service yesterday, due to the fact that AlertPay was under a large scale DDoS attack, according to a notice left by a company representative. Seven hours of downtime right in the middle of the [...]

AlertPay - Online Payment GatewayTiming is everything. Millions of account holders at privately owned online payment gateway AlertPay.com weren’t able to do business through the service yesterday, due to the fact that AlertPay was under a large scale DDoS attack, according to a notice left by a company representative. Seven hours of downtime right in the middle of the Christmas shopping season with millions of businesses using the service affected, isn’t coincidental. This DDoS attack, just like the recent DDoS attack again a popular anti-fraud site, may have well been outsourced.

AlertPay’s statement on the situation posted yesterday :

“We are currently expericing a large scale DDOS attack that has hit our sites which started at approximately 6:00am EST Sunday.  We are working with our data center to resolve and/or mitigate this issue.  More information will be posted here as we get updates. For the time being customers can connect to AlertPay at an alternate location: https://67.205.87.226″

Several hours later, AlertPay issued an update to the situation :

“We have finally mitigated the massive DDOS attack that started at 6:00am EST.  Unfortunately it took almost all day to resolve.  The site is operational now, and hopefully we’ll continue to tweak it more tomorrow to ensure this doesn’t happen again. We sincerely apologize for the inconvenience and we understand that this outage affects each of you personally.  We’re sorry for that.  We will continue to put measures in place so that outages like this do not occur again.

Ferhan”

There are two possible explanations regarding who’s behind the DDoS attack. It’s either unethical competition which in times of international economic meltdown can easily restore its market position by damaging the reputation and reliability of known competitor, or cybercriminals in “revenge mode” against a particular online payment processor that has detected their fraudulent activity, thereby causing them huge monetary losses. Despite the fact that online payment gateways have always been targets for DDoS extortionists, with malicious attackers introducing new models like the DDoS for hire one, they have empowered literally everyone knowing how to contact them with the opportunity to forward the responsibility for an attack to a third-party. Here’s a brief retrospective of DDoS attacks against online payment processors that took place during the last couple of years, with only a single instance of DDoS extortion :

With DDoS extortion as a business model largely replaced by today’s DDoS for hire services, we’re inevitably going to witness more attacks throughout 2009.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
9
Comments

Join the conversation!

Just In

RE: AlertPay hit by a large scale DDoS attack
birumut Updated - 5th May 2011
Great!!! thanks for sharing this information to us!
seslisohbet seslichat
0 Votes
+ -
The fact that they failed to impliment them, means they are not serious about protecting their business.

If i ran a payment processing system, i would have every protection available running on my systems and network. There is no excuse for people who make money by processing money.
0 Votes
+ -
Spoken like a true newbie
URAMoron 1st Dec 2008
Fewer and fewer DOS attacks attempt to target your application or servers to cause the denial of service. That is too easy to defend against. At this point botnets are so large that they can attempt to fill up your network pipes. Even the largest data center operators are no longer safe from DOS attacks even though they deploy such protection devices.

At the end of the day, if you want to take someone down using a DOS attack it is still possible no matter what prevention equipment is deployed.
0 Votes
+ -
The alternative: Net cops
progan01@... 1st Dec 2008
If it is true that any DDoS attack will succeed, then the concomitant truism is that any criminal can be stopped, if you are but willing to take the step of eliminating him or her.

If attacks of this sort continue, then national governments will be forced to create dedicated police operations intended to identify the source of such attacks and eliminate them. That will require wide intrusive powers that can look inside every account, every ISP, every packet as needed to find the 'cyber-terrorists.' The end result could be an Internet that is little more than an online police station, with all traffic and all users frisked on entry and on exit. And a few detained 'just to be sure.'

You want to go this way? You're heading there at warp speed now. You had better ask yourself the question: What do I want the Net Cops to look like? Because you're going to get them one way or another.
0 Votes
+ -
RE: AlertPay hit by a large scale DDoS attack
donkeyfluffer 16th Dec 2008
Alertpay.com is a scam site used by Craigslist scammers. http://j-walk.com/other/conf/
0 Votes
+ -
RE: AlertPay hit by a large scale DDoS attack
donkeyfluffer 16th Dec 2008
Too Bad. AlertPay is scam site for scammers.

http://j-walk.com/other/conf/
0 Votes
+ -
RE: AlertPay hit by a large scale DDoS attack
donkeyfluffer 17th Dec 2008
Too bad so sad. Scam site for scammers
0 Votes
+ -
That's not true. I've used AlertPay multiple times and
it's been great each time. It's easy to say a website
is a scam. How can you prove it? You posted a link to
Nigerian email conference that doesn't even mention
AlertPay.
0 Votes
+ -
Hello, I don,t know what is DDoS attack, but I am glad to be able to contact with you AlerPay by that way too and would like to have an email if you had one, to baranyfelho@net-tv.hu. I am just starting with Personal Pro and would like to ask for your help in progressing in order to be able to make some money from that.

I wish a Happy New Year for you. Thank you
0 Votes
+ -
RE: AlertPay hit by a large scale DDoS attack
birumut Updated - 5th May 2011
Great!!! thanks for sharing this information to us!
seslisohbet seslichat

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix