On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

May 30th, 2008

How was Comcast.net hijacked?

Posted by Dancho Danchev @ 9:43 am

Categories: Black Hat, Denial of Service (DoS), Hackers

Tags: Comcast, Kryogeniks, Social Engineering, Network Solutions, Domain Hijacking, DNS Hijacking, Dancho Danchev

It’s official, even a pothead can social engineer Network Solutions. In an in-depth interview with the hijackers, featuringComcast’s DNS records hijacked, redirect to hacked page some screenshots showing they had access to the complete portfolio of over 200 domain names controlled by Comcast, the details of how they did it, and why they did it are now coming straight from the source of the attack :

The hackers say the attack began Tuesday, when the pair used a combination of social engineering and a technical hack to get into Comcast’s domain management console at Network Solutions. They declined to detail their technique, but said it relied on a flaw at the Virginia-based domain registrar. Network Solutions spokeswoman Susan Wade disputes the hackers’ account. “We now know that it was nothing on our end,” she says. “There was no breach in our system or social engineering situation on our end.”

However they got in, the intrusion gave the pair control of over 200 domain names owned by Comcast. They changed the contact information for one of them, Comcast.net, to Defiant’s e-mail address; for the street address, they used the “Dildo Room” at “69 Dick Tard Lane.” Comcast, they said, noticed the administrative transfer and wrested back control, forcing the hackers to repeat the exploit to regain ownership of the domain. Then, they say, they contacted Comcast’s original technical contact at his home number to tell him what they’d done.

Following ICANN’s recently released advisory on preventing the very same impersonation attacks, it appears that even a first-tier domain registrar is still susceptible to registrant impersonation attacks. Makes you wonder on the state of understanding, detecting, and preventing social engineering attacks on the rest of the domain registrars.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 4 Talkback(s)
RE: How was Comcast.net hijacked?
It is scary that this could happen and this vulnerability still exist now. I think that Master Joe is correct that blame could be casted on both Comcast and Network Solutions in this case. Network Sol... (Read the rest)
Posted by: phatkat Posted on: 06/02/08 You are currently: a Guest | | Terms of Use
I saw the date 2010  BALTHOR | 05/30/08
RE: How was Comcast.net hijacked?  vertchlngd | 06/02/08
Master Joe Says...  MasterJoe | 06/02/08
RE: How was Comcast.net hijacked?  phatkat | 06/02/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here