Showing posts with label DNS hijacking. Show all posts
Showing posts with label DNS hijacking. Show all posts

Sunday, September 18, 2011

SSCC 72 - DigiNotar, DNS hijacking and Firesheep v2



Sophos Security Chet Chat logoThis week my guest for the podcast was Mike Wood, a Senior Threat Researcher at SophosLabs in Vancouver, Canada.
Mike is our expert on digital certificates and how malware authors try to use andabuse digital certificates for their own purposes.
I talked briefly about this month's Patch Tuesday, which fortunately is a small one compared to others this year.
I also briefly mentioned the compromise at DNS registrar NetNames. The attacker pointed the DNS for The Register, UPS and others to a Turkish hacker web site.
We discussed the latest version of Firesheep and how it is now able to steal your Google search history due to a flaw in how some Google sites handle cookies.
The meat of this Chet Chat was spent discussing the recent breach and impact of the hacker(s) who compromised certificate authority DigiNotar.
Mike went into some detail of how certificates have been abused and what these attackers might accomplish if they were to use bogus certificates they purloined from DigiNotar.

(8 September 2011, duration 27:22 minutes, size 12.5 MBytes)
You can also download this podcast directly in MP3 format: Sophos Security Chet Chat 72 or subscribe to our RSS.

Monday, September 5, 2011

DNS hack hits popular websites: Daily Telegraph, The Register, UPS, etc

Popular websites including The Register, The Daily Telegraph, UPS, and others have fallen victim to a DNS hack that has resulted in visitors being redirected to third-party webpages.
Web security tester Paul Mutton managed to capture a screenshot of what visitors to The Register saw:
Message seen by visitors to www.theregister.co.uk. Image credit @paulmutton
Part of the message reads:
TurkGuvengligi
"Gel Babana"
HACKED
"h4ck1n9 is not a cr1m3"
"4 Sept. We TurkGuvenligi declare this day as World Hackers Day - Have fun ;) h4ck y0u"
The phrase "Gel Babana" is Turkish for "Come to Papa", and "Guvenligi" is Turkish for "Security".
Further websites which have been affected by the DNS hack include National Geographic, BetFair, Vodafone and Acer.
It's important to note that the websites themselves have *not* been hacked, although to web visitors there is little difference in what they experience - a webpage under the control of hackers.
Instead of breaching the website itself, the hackers have managed to change the DNS records for the various sites affected.
PhonebookDNS records work like a telephone book, converting human-readable website names like nakedsecurity.sophos.com into a sequence of numbers understandable by the internet. What seems to have happened is that someone changed the lookup, so when you entered telegraph.co.uk or theregister.co.uk into your browser you were instead taken to a website that wasn't under the control of those websites.
Because of the way that DNS works, it may take some time for corrected DNS entries for the affected websites to propagate worldwide - meaning there could be problems for some hours ahead. If you're in the habit of visiting and logging into the affected sites, you might be wise to clear your cookies so the hackers aren't able to steal any information from you.
In many ways we have to be grateful that the message displayed appears to be graffiti, rather than an attempt to phish information from users or install malware.
The question now is how did the hackers manage to change the DNS records for these sites?
Here's a statement The Register published about the incident:
Statement from The Register
Image credit: @paulmutton.
Update: The Register has tweeted that its DNS records have been returned to normal.

The Register
So our DNS records have been restored to normality. Still no word from our provider.
As noted above, however, it may take some hours before the fix propagates around the net.