
DDoS-for-Hire Preys Upon SaaS Apps such as Joomla
Akamai Contacts Rob Morton
Media Relations
617-444-3641
rmorton@akamai.com
or
Tom Barth
Investor Relations
617-274-7130
tbarth@akamai.com
New DDoS attack and tools use Google Maps plugin as proxy to hide attacker identity
Threat advisory shares DDoS mitigation to help enterprises stop DDoS attacks
Cambridge, Mass. February 25, 2015 Akamai Technologies, Inc. (NASDAQ: AKAM), the leading provider of cloud services for delivering, optimizing and securing online content and business applications, today released, through the companys Prolexic Security Engineering & Research Team (PLXsert) in collaboration with PhishLabs R.A.I.D (Research, Analysis, and Intelligence Division), a new cybersecurity threat advisory. The advisory alerts enterprises and Software-as-a-Service (SaaS) providers of attackers using Joomla servers with a vulnerable Google Maps plugin installed as a platform for launching distributed denial of service (DDoS) attacks. The advisory is available for download from www.stateoftheinternet.com/joomla-reflection.
Vulnerabilities in web applications hosted by Software-as-a-Service providers continue to provide ammunition for criminal entrepreneurs. Now they are preying on a vulnerable Joomla plugin for which theyve invented a new DDoS attack and DDoS-for-hire tools, said Stuart Scholly, senior vice president and general manager, Security Business Unit, Akamai. This is one more web application vulnerability in a sea of vulnerabilities - with no end in sight. Enterprises need to have a DDoS protection plan in place to mitigate denial of service traffic from the millions of cloud-based SaaS servers that can be used for DDoS.
Vulnerability in Google Maps plugin for Joomla enables DDoS attacks
A known vulnerability in a Google Maps plugin for Joomla allows the plugin to act as a proxy. A proxy is an intermediary server that processes a request and returns the result on behalf of someone else. The vulnerable Google Maps plugin allows Joomla servers that use it to be used as a proxy. Attackers spoof (fake) the source of the requests, causing the results to be sent from the proxy to someone else - their denial of service target. The true source of the attack remains unknown, because the attack traffic appears to come from the Joomla servers.
With cooperation from PhishLabs R.A.I.D, PLXsert matched DDoS signature traffic originating from multiple Joomla sites, which indicates vulnerable installations are being used en masse for reflected GET floods, a type of DDoS attack. Observed attack traffic and data suggest the attack is being offered on known DDoS-for-hire sites.
PLXsert was able to identify more than 150,000 potential Joomla reflectors on the Internet. Although many of the servers appear to have been patched, reconfigured, locked or have had the plugin uninstalled, others remain vulnerable to use in this DDoS attack.
Details of a mitigated DDoS attack
PLXsert mitigated a DDoS attack of this type on behalf of an Akamai customer in November. The majority of the top attacking IP addresses originated from Germany. The same IP addresses that participated in this attack have participated in DDoS attacks against other Akamai customers in the industries of hosting, entertainment and consumer goods.
Multi-layered DDoS mitigation protects against reflection DDoS attacks
Refection-based DDoS attacks of many types are popular at this time. In the fourth quarter of 2014, Akamais PLXsert observed 39 percent of all DDoS attack traffic employed reflection techniques. Reflection DDoS attacks each take advantage of an Internet protocol or application vulnerability that allows DDoS attackers to reflect malicious traffic off a third-party server or device, hiding their identities and amplifying the amount of attack traffic in the process.
Cloud-based DDoS attack mitigation can combat this problem to protect organizations from malicious traffic. Edge-based security and scrubbing centers stop DDoS attack traffic long before it affects a clients website or data center.
Get the Joomla Reflection DDoS-for-Hire Threat Advisory to learn more
In the advisory, PLXsert shares its analysis and details, including:
Use of the GET flood in Joomla reflection
What to look for: Three sample payloads
Attacks from the DAVOSET DDoS tool
Attacks from the UFONet DDoS tool
GET flood requests observed during an attack
Geographical distribution of source traffic
Three DDoS mitigation procedures to stop DDoS attacks of this type
A complimentary copy of the threat advisory is available for download at www.stateoftheinternet.com/joomla-reflection.
About PhishLabs
PhishLabs is the leading provider of cybercrime protection and intelligence services that fight back against online threats and reduce the risk posed by phishing, malware, distributed denial-of-service (DDoS) and other cyber-attacks. The company fights back against cybercrime by detecting, analyzing and proactively dismantling the systems and illicit services cybercriminals depend on to attack businesses and their customers. With a fixed-price service model that ensures alignment with client goals, the company partners with businesses to stop account takeover attacks, reduce online fraud and prevent the loss of customer trust.
To learn more about PhishLabs, visit http://www.phishlabs.com or email info@phishlabs.com
About Akamai
Akamai is the leading provider of cloud services for delivering, optimising and securing online content and business applications. At the core of the Companys solutions is the Akamai Intelligent Platform providing extensive reach, coupled with unmatched reliability, security, visibility and expertise. Akamai removes the complexities of connecting the increasingly mobile world, supporting 24/7 consumer demand, and enabling enterprises to securely levera
Most recent headlines
06/10/2025
France T l visions, France's leading broadcaster, has received the 2025 EBU ...
04/09/2025
Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...
31/08/2025
Legrand | AV, a global specialist and industry leader in audiovisual solutions, returns to CEDIA Expo 2025, taking place Sept. 4-6 in Denver, with a powerful li...
31/08/2025
Global media technology company Backlight will unveil new capabilities in its Iconik, Wildmoka, and Zype product lines at IBC2025 (booth #1.D09), September 12 1...
30/08/2025
WASHINGTON The Federal Communications Commission has adopted its FY 2025 Regulatory Fees Order that establishes the regulatory fee rates for the broadcast stati...
29/08/2025
Australian Red Cross and SBS launch training to help workplaces in the fight aga...
29/08/2025
The National Film and Video Foundation (NFVF), an agency of the Department of Sp...
29/08/2025
L3Harris Technologies has concentrated decades of expertise across the entire enterprise to develop affordable and reliable best-of-breed solutions to rapidly c...
29/08/2025
BURBANK, Calif. The CW Network and the Pac-12 Conference have announced a new media rights deal that will extend their broadcast partnership beginning with the ...
29/08/2025
NEW YORK Gracenote has released a new analysis of its global video dataset showing that the number of FAST channels grew nearly 14% from Q1 2025 and 76% since 2...
29/08/2025
SAN JOSE, Calif. Harmonic has announced a series of improvements to its live sports streaming solution that the company said will improve fan engagement, protec...
29/08/2025
NEW YORK and LOS ANGELES Fox Corp. and YouTube TV last night announced a renewal of the full portfolio of Fox networks, including Fox News Channel, Fox Business...
29/08/2025
Budapest, Hungary, August 2025 - The integration of Microsoft Teams Rooms (MTR) with Lightware's Taurus universal matrix switchers delivers a new level of f...
29/08/2025
Frequency, the engine behind many of the world's best-known streaming television channels, today announced it will launch Studio Live, a next-generation uni...
29/08/2025
In an era when AI and cyber resilience are essential, Scality will mark the 10th anniversary of Scality Day on October 16, 2025 in Paris. This flagship global e...
29/08/2025
Disguise's In-House Creative and Technical Teams Pre-Visualised, Programmed and Delivered Content for the Experience, All Powered by EX 3+
Technology solu...
29/08/2025
Disguise will be demonstrating the latest workflows for TV, film and live events on a number of partner booths at the show
Disguise, the industry-leading tech...
29/08/2025
STOCKHOLM, Sweden Accedo will showcase Accedo Compose, its AI agent-powered modular orchestration layer that assists streaming providers in transitioning client...
29/08/2025
LOS ANGELES Cineverse has announced that it is working with Xperi to bring four of its streaming channels to automobiles for the first time as part of the DTS A...
29/08/2025
DALLAS & ATLANTA Gray Media has announced an agreement with the sports streaming service Victory+ to simulcast 17 Dallas Stars NHL games in 15 television market...
29/08/2025
NEW YORK AND CULVER CITY Comcast NBCUniversal and Amazon have announced new and extended distribution agreements that will expand the content available on their...
29/08/2025
FOOTHILL RANCH, Calif. RED Digital Cinema will feature its Cine-Broadcast Module supporting live broadcast workflows during IBC2025, Sept. 12-15, at the RAI Ams...
29/08/2025
29 Aug 2025
Kyivstar Rings Opening Bell at Nasdaq Marking Landmark Listing and ...
29/08/2025
More than half of all NFL games live on Sky for the first timeFriday 29 August 2025
Sky Sports has announced a new three-year deal with the NFL, extending its ...
29/08/2025
Back to All News
RIV4LRIES: The Trailer of the New Series With Samuele Carrino ...
29/08/2025
Get ready for an inspiring and emotional insight into the world of competitive Irish dancing with My Story: Tomi Champion of the World airing on RT 2 this monda...
29/08/2025
RT has today announced that David McCullagh is to be the new presenter of RT Radio 1's flagship Today programme, which airs every weekday at 10am, replaci...
28/08/2025
By Kristin Feeley, Director, Documentary Film & Artist Programs
If you want to tell untold stories, if you want to give voice to the voiceless, you've got ...
28/08/2025
Directed by Steven Bognar and Julia Reichert, Sundance Institute-supported Amer...
28/08/2025
Corridos have been a cornerstone of M sica Mexicana for generations, telling stories rooted in everyday life. Now, a new chapter is taking shape: motivational c...
28/08/2025
Los corridos han sido un pilar de la M sica Mexicana durante generaciones, contando historias enraizadas en la vida cotidiana. Ahora, un nuevo cap tulo est tom...
28/08/2025
Earlier this month, we promised our Verano Forever party would bring the heat, a...
28/08/2025
L3Harris will provide the Polish F-16V fleet with the Viper Shield electronic warfare system as part of an upgrade program....
28/08/2025
Bilbao, August 26, 2025 - AgileTV, an international television and video technol...
28/08/2025
Ken Wilkinson is an Emmy Awards nominated New York audio engineer who specialises in production sound mixing for film, commercial, episodic and documentary work...
28/08/2025
NEW YORK FuboTV today announced that it will launch Fubo Sports, a skinny bundle that focuses on sports with a subscription price of $56 monthly....
28/08/2025
NEVADA City, Calif. At IBC2025, Sept. 12-15 at the RAI Amsterdam, Telestream will debut its new Global Ingest strategy, introducing a next-generation ingest arc...
28/08/2025
Dr. Rhoda Bernard Releases Groundbreaking Debut Book on Accessible Arts Educatio...
28/08/2025
TAG Video Systems, the leader in software-based IP end-to-end workflow monitoring, deep probing, and real-time visualization, has named Oliver Gappa as Sales Di...
28/08/2025
AI-based voice enhancement will be among a series of innovations making their IBC 2025 debut on the DHD stand B46 in Hall 8 at the RAI Amsterdam Convention Cent...
28/08/2025
Telef nica Servicios Audiovisuales (TSA), the leading system integrator and service provider in the media sector in Spain, with the support of Appear, the globa...
28/08/2025
To fully immerse sailing fans in the world's biggest offshore yacht race, production company, Optical Media turned to LiveU's On-site Production solutio...
28/08/2025
Working with Calrec on its most recent overhaul, radio and television broadcaster, WNED has migrated to a fully IP infrastructure with multiple Type R consoles,...
28/08/2025
Cleeng, the Subscriber Retention Management (SRM ) inventor, has unveiled Cleeng Pro, the first-ever direct-to-consumer (D2C) subscription management platform t...
28/08/2025
Zixi, the industry leader in live broadcast-quality video over IP, today announced that French media distribution platform OKAST has selected Zixi to enable rel...
28/08/2025
Solution offers a streamlined, speaker-free architecture to optimize integration with premium external loudspeakers and advanced loudness metering
Nixer Pro Au...
28/08/2025
Cinegy, the premier provider of software-defined television technology, has announced a strategic partnership with Vision One Touch Film Production Services L.L...
28/08/2025
Telestream, a global leader in media workflow technologies, will debut its new Global Ingest strategy at IBC2025, introducing a next-generation ingest architect...
28/08/2025
Tier 1 operator selects Broadpeak to power high-performance, unified CDN solution across Norway, Sweden and Finland
Broadpeak, a leader in streaming and moneti...