On The Insider: Oprah's Next Project on HBO
BNET Business Network:
BNET
TechRepublic
ZDNet

July 30th, 2008

HD Moore pwned with his own DNS exploit, vulnerable AT&T DNS servers to blame

Posted by Dancho Danchev @ 8:08 am

Categories: Black Hat, Exploit code, Hackers, Metasploit

Tags: Google Inc., DNS, DNS Server, AT&T Corp., Server, Domain Names, Networking, Internet, Dancho Danchev

A week after |)ruid and HD Moore release part 2 of DNS exploit, HD Moore’s company BreakingPoint has suffered a trafficMetasploit Logo redirection to a rogue Google site, thanks to the already poisoned cache at AT&T servers to which his company was forwarding DNS traffic :

“It happened on Tuesday morning, when Moore’s company, BreakingPoint had some of its Internet traffic redirected to a fake Google page that was being run by a scammer. According to Moore, the hacker was able to do this by launching what’s known as a cache poisoning attack on a DNS server on AT&T’s network that was serving the Austin, Texas area. One of BreakingPoint’s servers was forwarding DNS (Domain Name System) traffic to the AT&T server, so when it was compromised, so was HD Moore’s company. When Moore tried to visit Google.com, he was actually redirected to a fake page that served up a Google page in one HTML frame along with three other pages designed to automatically click on advertisements.”

Moreover, last month, before the latest DNS cache poisoning vulnerability and exploits started taking place,  Metasploit Project’s site was temporarily hijacked through ARP poisoning, perfectly demonstrating that old-fashioned DNS attacks remain intact.

UPDATE: HD Moore’s explanation of the situation, and the impact of the attack that took place :

“Most of the facts of the article are correct. I have no problem detailing the attack, how it worked, and how we detected and resolved it. I am careful about the wording, because I want to be clear that while this type of attack can be serious, in this case it was a five minute annoyance that was designed as a revenue generator for the folks who launched it (click-through advertisement revenue). No systems were been compromised, no data was stolen, and most importantly, the target of the attack was the ISP, not the company that I work for. Stating that my company was “compromised” leads the reader to believe that there was some sort of security breach, which is reinforced by the fabricated quote.”

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 14 Talkback(s)
LOL, its been years since i heard the orgins of it.
I remembered it being from a game and a foreigner having something to do with it... good call.

BTW: Someone tell him Wiki is not the end all answer to everything, its essentially history by agreement.... (Read the rest)
Posted by: Been_Done_Before Posted on: 08/02/08 You are currently: a Guest | | Terms of Use
On top of this  nmcfeters | 07/30/08
So HD wasn't pwnd...  Jennifer LeggioZDNet Moderator | 07/30/08
Yes it should.... maybe HD's ISP was pwned.  Been_Done_Before | 07/30/08
Take 2 xanax and call me in the morning!  dunn@... | 07/30/08
It was a joke. I used the AOL translator to generate that.  Been_Done_Before | 07/30/08
I Apologize For Seeming Stuffy Myself...  dunn@... | 07/31/08
Why not?  nmcfeters | 07/30/08
"Why Not?" What?  dunn@... | 07/30/08
Pwned is a gaming term, Owned is a hacker term.  Been_Done_Before | 07/30/08
All your base belong to us...  duhrain@... | 07/31/08
it was foreign gamer, in a way  ChazzMatt | 08/02/08
LOL, its been years since i heard the orgins of it.  Been_Done_Before | 08/02/08
RE: HD Moore pwned with his own DNS exploit, vulnerable AT  pmadamstx@... | 07/31/08
Switch to OpenDNS  seanferd | 07/31/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline