Wednesday, March 11, 2020

CompTIA to the rescue

The Association of Better Computer Dealers (ABCD) was founded in 1982 with the goal of improving the IT industry for all involved. Their influence and importance grew throughout the decade as ABCD became more prominent in the industry.

By 1990, CompTIA had a worldwide reach and a massive membership. Then, in 1993, CompTIA did something IT professionals had dreamed of doing for years. With one fell swoop, they changed the entire IT certification industry by introducing their A+ certification.
CompTIA Security+ SY0–501: Security+ exam is targeted for computer service technicians with at least 2-year on-the-job experience. To get Security+ certified, one needs to pass only one exam: SY0–501. this topic deals with Cryptography and PKI, Identity and Access Management, etc CompTIA Security+ Exam Cram Study Guide help you to get to know more details.
CompTIA Server+ SK0–004: The CompTIA Server+ certification is considered next to the level of A+ certification. It is recommended to have about 18 to 24 months experience in the server technologies industry.Server+ certification awarded to successful candidates will not expire over a period of time (indefinite validity). CompTIA Server+ Exam Cram Study Guide help you to get more details about server+ Certification.

Eventually, they changed their name to the Computing Technology Industry Association; now, they're better known by their acronym— CompTIA. Unlike previous certifications, CompTIA's A+ was vendor-neutral and comprehensive, covering a wide range of skills, technologies, and operating systems.
More Info: network plus certification salary

Tuesday, March 10, 2020

Bounding Through the Ranks with Certification

As the new guy on a small, scrappy IT team, Hodson was filling a lot of roles and learning a lot. But as he moved onto a bigger company with more regimented IT demands, he wanted a more structured understanding of how things actually worked, not just what it took to manage them.

It was the early ’00s. And just around the time that Hodson realized he needed a regimented walkthrough of ground-level computing, CompTIA had begun to provide it – with the first iteration of CompTIA A+.

For those of you panicking at the sight of Linux and Mac, you don’t need to go over installation procedures. These topics focus more on basic functionality. This exam is still largely Windows focused.

You do need to know command line tools. The benefit to this is that the vast majority of these commands interchange with one another. I didn’t find a single question asking me for Linux/Mac commands on the exam. Keep in mind that questions are random and your questions will vary.

In a part-time course at the National IT Learning Center, Hodson earned the IT certification and, shortly thereafter, picked up CompTIA Network+ as well.

“It [gave me] a confidence and a grounding,” Hodson said. “I began working on things like AS400 systems, looking at token ring networks people had at the time, understanding ethernet and [local area network (LAN)] constructions in more detail. I don’t think I’d have done that without the exposure of the A+ and Network+.”

From there, Hodson experienced more than a decade of career leaps, moving through the worlds of retail, gaming, finance and media, and into roles both more technologically sophisticated and more strategic
More Info: what kind of jobs can you get with comptia a+ certification

Friday, March 6, 2020

What is Distributed Denial of Service

Distributed denial of service (DDoS) is a category of malicious cyber-attacks that hackers or cybercriminals employ in order to make an online service, network resource or host machine unavailable to its intended users on the Internet. Targets of DDoS attacks are flooded with thousands or millions of superfluous requests, overwhelming the machine and its supporting resources. DDoS attacks are distinct from conventional denial of service incidents in that they originate from distributed or multiple sources or IP addresses. To get a sense of the enormous scope of the DDoS threat, the Check Point ThreatCloud Live Cyber Threat Map provides a global window into malware activity, providing a DDoS attacks map where exploits can be viewed in real time.
  • DDoS Protect Pro provides protection against complex and volume-based DDoS attacks
  • Three protection modules for the most extensive cover possible
  • Cloud Web: from the cloud for local and hosted systems
  • Backbone: in the Telekom backbone for Internet access
  • On Premises: on the customer's premises for the local infrastructure
  • Coupling Backbone and On Premises protection ensures that volume-based DDoS attacks are automatically mitigated
An application layer attack is sometimes referred to as a layer-7 DDoS attack (in reference to the 7th layer of the OSI model). The goal of these attacks is to exhaust the resources of the victim, by targeting the layer where web pages are generated on the server and delivered to the visitors in response to HTTP requests (that is, the application layer). Layer-7 attacks are challenging, because the traffic can be difficult to identify as malicious.
More Info: how to fix ddos attacks

Thursday, March 5, 2020

How Does a DDoS Attack Work

DDoS attacks may be scary, but there are a lot of ways you can set up WordPress DDoS protection.

If you’re proactive, you may never find yourself in a position where a DDoS attack takes down your website. Let’s take a look at five different methods.
1. Use a content delivery network (CDN)

CDNs are services that cache copies of your website on their data centers. The most popular CDNs offer data centers around the world and they act as a middleman between you and your site’s visitors.

Application layer DDoS attacks aim to exhaust the resources of the target and disrupt access to the target’s website or service. Attackers load the bots with a complicated request that taxes the target server as it tries to respond. The request might require database access or large downloads. If the target gets several million of those requests in a short time, it can very quickly get overwhelmed and either slowed to a crawl or locked up completely.

Whenever possible, your CDN will serve a cached copy of your site from its servers, which translates to less strain on yours. What’s more, CDNs can also help you decrease overall loading times because they’re built with performance in mind.

CDNs act as a sort of firebreak to DDoS attacks by preventing the resultant traffic from overwhelming your website. They can detect anomalous patterns in traffic, and if things are scaling too fast, can act to mitigate the attack.


More Info: how to fix ddos attacks

Wednesday, March 4, 2020

DoS protection really necessary

Denial of service (DOS) attacks and distributed denial of service (DDoS) attacks are issues of concern for businesses because it results in loss in revenue from disrupted services. At the outset, let us try to understand what these terms DOS and DDoS mean.

The short answer is yes. The long answer is that a rapidly increasing number of DoS attacks are targeted directly at Layer 7 (applications). These attacks are painstakingly designed to look like legitimate traffic. They attempt to successfully compromise the targets—especially where Layer 3 and Layer 4 attacks failed. Layer 7 DoS attacks are frequently structured to overload specific elements of application server infrastructure. Even simple DoS attacks—for example, those targeting login pages with random user IDs and passwords, or repetitive random searches on dynamic web sites—can critically overload CPUs and databases. Be sure to ask your provider whether or not they provide Layer 7 protection as part of their solution to address these risks.

A DDoS attack is an attack intended to take an organization or a service offline, or otherwise render resources unusable, which originates from (or appears to originate from) multiple hosts. The "multiple hosts" part of the attack is what makes it "distributed," and is what makes the attack more difficult to defend against. An attack that originates from a single host or IP address can be easily blocked with a simple router access list or firewall rule.

In simple terms denial of service or DOS means a tactic that stops a website from running. The result is, the website stops displaying content or prevents it from operating on the internet appropriately. The attack can be for any duration and can strike more than one site at a time. The attack becomes a distributed denial of attack (DDoS) when the attacks originate from more than one computer. It is a network based attempt that makes a website or an inclusive infrastructure unavailable.

More Info: ddosed

Tuesday, March 3, 2020

currently fashionable DDoS

First things first, there is a little typical example of a DDoS we hear a lot about currently. It is, more precisely, a DrDoS, a Distributed reflection Denial of Service. The 3 key parameters are the following:
UDP (User Datagram Protocol) spoofing
Amplification factor
Type of vector used

UDP spoofing

It is the cornerstone of this attack. Spoofing enables the anonymity of the attack.

Thanks to the UDP, which does not ask for an exchange strictly speaking but emits information without caring about whether it will be correctly received or not, the attacker is anonymous and will send forged “spoofed” packets. Spoofing consists in changing the IP address of the packet (where it comes from) by replacing the real IP address of the hacker with the one of his target.

DDoS attacks have been in the spotlight recently after popular security journalist Brian Krebs had his site taken offline by what at the time was the largest DDoS attack ever recorded by traffic volume. That particular attack was eye opening, not just due to its size, but because it was powered by thousands of insecure IoT devices. It's no secret that Internet-connected devices have for years been sold with weak to nonexistent security and known default passwords that are never changed. This was, however, a moment where the risk posed by such devices was on clear display.

The answers to the sent packets will thus come back to the target, and not to the attacker; it is the “reflection”, bouncing, part of the attack.
More Info: ddos attack definition

Monday, March 2, 2020

What is a Distributed Denial-of-Service Attack?

Most DDoS attacks are designed to consume all available network bandwidth or resources on a target network, system, or website. The attacker uses one of many available methods and tools to flood the target with a barrage of malicious or nuisance requests, or to abuse a protocol or inherent vulnerability in such a way that the system can no longer respond to requests. The effects of a DDoS attack are a bit like having the entrance to a concert venue suddenly swarmed by busloads of troublemakers with counterfeit tickets. The legitimate ticket-holders, standing in an orderly line, would never get inside.

DDoS attacks can look like many of the non-malicious things that can cause availability issues – such as a downed server or system, too many legitimate requests from legitimate users, or even a cut cable. It often requires traffic analysis to determine what is precisely occurring.

From a single computer, it’s difficult for attackers to generate the volume of traffic necessary to crash a network or website. To get the bandwidth or processing power needed, attackers often use botnets—armies of hundreds or thousands of Internet-connected computers (zombies or bots) that are infected with malware and under the control of the attacker (the bot master, or bot herder). In most cases, the owners of these infected computers are not even aware they’ve been compromised.
More Info: what is ddos?