Millions of WordPress sites exploitable for DDoS Attacks using Pingback mechanism
May 01, 2013
    Distributed Denial of Service  attacks have increased in scale, intensity and frequency. The wide range of motives for these attacks political , criminal, or social makes every merchant or organization with an online presence a potential target.     Over the weekend Incapsula  mitigated a unique DDoS attack against a large gaming website, in which they have discovered  a DDoS attack using thousands of legitimate WordPress  blogs without the need for them to be compromised.     Incapsula released the list of approximately 2,500 WordPress sites from where the attack was originated, including some very large sites like Trendmicro.com, Gizmodo.it and Zendesk.com .     In a recent report , we posted about another method for DDoS attacks  using DNS amplification , where a DNS request is made to an open DNS resolver  with the source IP address forged so that it is the IP address of the targeted site to which the response is thus sent, but this new method uses HTTP rather tha...