On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

June 18th, 2008

Photobucket's DNS records hijacked by Turkish hacking group

Posted by Dancho Danchev @ 6:27 am

Categories: Black Hat, Hackers, Passwords

Tags: Photobucket, Fox Interactive Media, Turkish Hackers, NetDevilz, DNS Poisoning, DNS Hijacking, Web Site Defacement, Dancho Danchev

Yesterday, Photobucket the world’s most popular photo sharing site according to Hitwise had its DNS records hijackedPhotobucket Hacked by Turkish Hacking Group to return a hacked page courtesy of the NetDevilz hacking group, a Turkish web site defacement group most widely known for its defacement of the adult video site Redtube earlier this year. Photobucket users across the world are reporting minor outages of the service and problems when trying to access their accounts, the consequence of what looks like the type of DNS records hijacking that redirected Comcast.net to a third-party domain last month.

Third-party site monitoring services indicate that the site was down for 15 minutes yesterday, from from 17:39:39 to 17:55:10, whereas according to a comment left by a Photobucket Forum Support representative, the downtime due to the propagation of the corrected DNS entries was longer :

“On Tuesday afternoon, some users that typed in the Photobucket.com URL were temporarily redirected to an incorrect page due to an error in our DNS hosting services. The error was fixed within an hour of its discovery, but due to the nature of the problem, some users will not have access to Photobucket for a few hours as the fix rolls out. It is important to note that only a portion of Photobucket users encountered the problem and that no Photobucket content, password information or other personal information was affected by the redirect.”

The NetDevilz hacking group left the following message, that appears to have been loading from a third-party domain,Photobucket downtime netdevilz atspace.com in this case :

“… ve NeTDevilz yeniden sahnede

Bizi hatırlayan var mı ? Unutulduğumuzu düşündük ve tekrar hatırlatmaya karar verdik !
( Turkish hackers group )

ZeberuS - GeCeCi - MiLaNo - The_BeKiR - h4ckinger - SerSaK - KinSize

we are came back !
©2008 NetDevilz Co.
We’re not first,But We’re the BEST!”

The hacking group appears to have been using the hosting services of atspace.com, the web hosting service of Zetta hosting solutions, and users of Photobucket attempting to access the site with the old DNS entries are still being redirected to a default hosting ad page within atspace.com. The effect of the redirection can also be seen by taking a peek at the publicly obtainable stats for atspace.com, where the sudden peak in traffic resulting in 118,864 visitors for today came from the default ad page used in the redirection.

With the second DNS hijacking attack against a high-profile domain in the recent months, it seems that adaptive malicious parties unable to directly compromise a site will continue taking advantage of good old-fashioned DNS hijacking. At least to prove that it’s still possible even on a high-profile domain using the services of a Tier 1 domain registrar.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 22 Talkback(s)
RE: : "That's why I don'y use PhotoBucket"
All popular websites are targets for hackers. To hack anything else would not gain hackers the notoriety they crave. To say " That's why I don't use Photobucket" does not show your intelligence... or maybe it does.... (Read the rest)
Posted by: onedavester@... Posted on: 06/20/08 You are currently: a Guest | | Terms of Use
Just wait until Paypal gets hijacked  Michael Kelly | 06/18/08
RE: Photobucket's DNS records hijacked by Turkish hacking group  laralynzy@... | 06/18/08
RE: Photobucket's DNS records hijacked by Turkish hacking group  laralynzy@... | 06/18/08
RE: Photobucket's DNS records hijacked by Turkish hacking group  rsherry@... | 06/18/08
won't solve the problem either  sfazly | 06/18/08
Or do what the US does...  Marty R. Milette | 06/18/08
Harsh  infoz | 06/18/08
Do you think Turkey is another Iran?  birdwings | 06/18/08
ah 10000 sit ups 100000 pull ups would suffice  iamjackalope@... | 06/20/08
RE: Photobucket's DNS records hijacked by Turkish hacking group  laralynzy@... | 06/18/08
RE: Photobucket's DNS records hijacked by Turkish hacking group  jbcoops | 06/18/08
What will they do with your password?  birdwings | 06/18/08
RE: Photobucket's DNS records hijacked by Turkish hacking group  laralynzy@... | 06/18/08
RE: Photobucket's DNS records hijacked by Turkish hacking group  laralynzy@... | 06/18/08
RE: Photobucket's DNS records hijacked by Turkish hacking group  f'dbyphtobucket | 06/18/08
RE: Translation of the Turkish message left by Turkish hacking group  birdwings | 06/18/08
RE: Photobucket's DNS records hijacked by Turkish hacking group  rmstock | 06/18/08
RE: Photobucket's DNS records hijacked by Turkish hacking group  Knightwolfe | 06/19/08
RE: Photobucket's DNS records hijacked by Turkish hacking group  Knightwolfe | 06/19/08
RE:thats why i dont use photobucket  f'dbyphtobucket | 06/19/08
Consider this:  Dem0072 | 06/19/08
RE: : "That's why I don'y use PhotoBucket"  onedavester@... | 06/20/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here