HN user

danielcid

57 karma

Daniel B. Cid - Founder of cleanbrowsing, Sucuri, Trunc and OSSEC.

Posts16
Comments13
View on HN
dnsarchive.net 10mo ago

Show HN: Web Metadata search. Search for headers, apps, CMSs, and versions

danielcid
2pts0
dnsarchive.net 1y ago

Show HN: Web Metadata search. Search for headers, web apps, CMSs, and versions

danielcid
2pts0
trunc.org 1y ago

Investigating the 'Slince_golden' WordPress Backdoor

danielcid
1pts0
noc.org 3y ago

Hacked WordPress – over 17,000 spam links injected post compromise

danielcid
2pts0
trunc.org 3y ago

AWS Credential Harvesting Scans – looking for –/.aws/credentials files

danielcid
2pts0
trunc.org 3y ago

The Mozlila user agent and why it is part of many web attack campaigns

danielcid
39pts1
noc.org 3y ago

How a PHP Backdoor on a compromised WordPress site is used for DDoS Attacks

danielcid
5pts0
trunc.org 3y ago

Investigating a hacked WordPress site on Linode being used as a DDoS relay

danielcid
3pts1
trunc.org 4y ago

Analyzing a HTTP DDoS against a website. 7k IPs and over 20k requests per second

danielcid
4pts0
trunc.org 4y ago

Analysing the latest Brute force attacks against Windows Remote Desktop

danielcid
1pts0
search.noc.social 6y ago

Show HN: Discover and search for accounts across multiple Mastodon instances

danielcid
4pts2
cleanbrowsing.org 6y ago

Guide on how to block porn content – and protect your kids online

danielcid
3pts1
blog.sucuri.net 8y ago

WordPress and Formidable Forms and Shortcodes Ultimate Exploits in the Wild

danielcid
1pts0
blog.sucuri.net 9y ago

IPv4 x IPv6 performance comparison across the world

danielcid
21pts0
blog.sucuri.net 10y ago

Large IoT CCTV Botnet Leveraged in DDoS Attacks

danielcid
5pts0
blog.sucuri.net 10y ago

Critical 0-day Remote Command Execution Vulnerability in Joomla

danielcid
13pts0

That's a problem that will only get worse. To give an example, last year, Incapsula recorded ~9,000 IoT cameras attacking them. A few months ago, Sucuri recorded ~25,000.

CloudFlare is seeing close to 50k. And that's the attackers just using a small portion of their real power for http floods.

Our report from a few months ago breaking down the types of cameras and networking doing the attack - very similar to what CloudFlare saw:

https://blog.sucuri.net/2016/06/large-cctv-botnet-leveraged-...

*I work at Sucuri.

Very fun read. I love following the train of thought and seeing where they "failed".

Also, this Elasticsearch RCE has been patched a while ago and we still see a lot of servers hacked because of it. In fact, there is a DDoS botnet made of only ES servers that we have been tracking.

<unrelated>If you are using Elasticsearch, please patch it!</unrelated>

Curious why you say that of Sucuri? Have you tried us recently?

We have some very very large sites using our services now with great performance. During the last 6-12 months we basically rewrote our entire stack, built our anycast network and focused a lot on performance optimization and expanding out services.

You can ping me directly if you prefer too.

thanks!

Daniel Cid (CTO/Founder of Sucuri)