Contributors

Jeremiah Grossman
(WhiteHat Security)

Ofer Shezaf
(Breach Security ) [Project Leader]

The Web Hacking Incidents Database
Last update:07 November 2007

List of incidents of class Denial of Service

Other WASC threat classifications:
Abuse of Functionality, Brute Force, Content Spoofing, Credential/Session Prediction, Cross-site Scripting, Defacement, Denial of Service, Directory Indexing, HTTP Response Splitting, Information Leakage, Insufficient Anti-automation, Insufficient Authentication, Insufficient Authorization, Insufficient Process Validation, Insufficient Session Expiration, Known Vulnerabity, Misconfiguration, OS Commanding, Other, Path Traversal, Phishing, Predictable Resource Location, Redirection, SQL Injection, Unknown, Weak Password Recovery Validation, Worm


There are 3 incidents of class Denial of Service
WHID 2007-52: Hacker halts Rivkin auction of 37 watches
Date: 05 November 2007
Incident Type: Security Breach
WASC Threat Classification: Denial of Service

Seems that the there is a new trend to disrupt on line bidding using denial of service attacks. In this case, an auction for 37 very expensive watches was halted 20 minutes before the end as the site crashed, in what official sources describe as a hacker attack that did not result in a site compromise.

References:

WHID 2007-49: Hackers Block Sale of Colorado Rockies World Series Tickets
Date: 23 October 2007
Incident Type: Security Breach
WASC Threat Classification: Denial of Service

The site of the Rockies was taken down by a denial of service preventing fans from buying tickets for the World Series games.

Like any DDoS attack, it is very hard to know if it was an application layer or network layer attack, but since this attack had a very significant financial impact by crippling a web site, we think it deserve a place in WHID.

References:

WHID 2005-38: Massachusetts Teen Convicted for Hacking into Internet and Telephone Service Providers
Date: 08 September 2005
Incident Type: Security Breach
WASC Threat Classification: Denial of Service, Unknown

Teen convicted of threatening an ISP with DOS attack, among other computer hacking activities

References:




This work is licensed under the Creative Commons Attribution License. To view a copy of this license, visit http://creativecommons.org/licenses/by/2.5/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

© Copyright 2005, Web Application Security Consortium. All rights reserved.