On TechRepublic: The 5 worst tech products of 2009
BNET Business Network:
BNET
TechRepublic
ZDNet

April 21st, 2009

Hackers hijack DNS records of high profile New Zealand sites

Posted by Dancho Danchev @ 8:21 am

Categories: Browsers, Hackers, Passwords, Web Applications

Tags: Security, Mass Defacement, Fanta, Sony, Cola Cola, HSBC, MSN, F-Secure, BitDefender, Dancho Danchev

Remember the DNS hijackings of such high profile sites such as Comcast, Photobucket, and ICANN/IANA domains that were taking place last year? Similar incidents are still happening.

Today, a web site defacement group known as “The Peace Crew” has successfully hijacked the DNS records for high profile New Zealand web sites, through what Zone-H claims to be a SQL injection at New Zealand’s based registrar Domainz.net, in order to redirect the visitors to a defaced page featuring the infamous Bill Gates pieing photo, as well as anti-war messages.

The mass defacement affected major Microsoft sites in New Zealand including WindowsLive.co.nz, MSN.co.nz, Microsoft.co.nz, Hotmail.co.nz, Live.co.nz next to HSBC.co.nz, Sony.co.nz, Coca-Cola.co.nz, Xerox.co.nz, Fanta.co.nz, F-Secure.co.nz and BitDefender.co.nz.

Here’s Microsoft’s comment:

According to NZHerald:

“MSN have responded by issuing a short statement from MSN business manager Liz Fraser this afternoon. “The cause of this discrepancy has been identified and we are currently working with our Microsoft technology and security teams in the US to resolve the matter as quickly as possible today. “We apologise for any inconvenience this may have caused,” the statement said.”

Once control to the domain registrar’s web panel was obtained, members of the Peace Crew used fatih1.turkguvenligi .info and fatih2.turkguvenligi .info as primary DNS servers delivering the defaced pages, and making it look like the sites themselves have been compromised.

The group is not new on the defacement scene, in fact one of its members has been keeping himself pretty busy during this month by having already defaced thirteen web servers belonging to NASA, using the same template.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 18 Talkback(s)
Yes, you did miss it
Re-read NonZealot's post three times. You will see it claims/infers that the server was running Linux - not the hackers.... (Read the rest)
Posted by: skiddo24 Posted on: 04/23/09 You are currently: a Guest | | Terms of Use
Hackers hijack DNS records of high profile New Zealand sites  Loverock Davidson | 04/21/09
Actually, the hacked DNS server ran Linux  NonZealot | 04/21/09
Then its really bad  Loverock Davidson | 04/21/09
I don't think so  honeymonster | 04/21/09
You got it. Parameterized queries stop SQL injection  no_zd_user_name | 04/21/09
Hacking the control panel is the same than hacking the OS???  Caudiox | 04/21/09
NOT the DNS server itself... but  pcguy777 | 04/22/09
Missing it  Lunatic59 | 04/21/09
It doesn't say  mikefarinha | 04/21/09
By any chance ...  Lunatic59 | 04/21/09
You owe me a screen cleaner  honeymonster | 04/21/09
dooood he laughed so hard he iBagged it broh.  pcguy777 | 04/22/09
MacHacker 1.0  gjsherr | 04/22/09
Yes, you did miss it  skiddo24 | 04/23/09
Another FUD meesage from your friendly neighbourhood CMIC.  linux for me | 04/22/09
One doesn't mean all.  phatkat | 04/22/09
Wow...  DCMann | 04/22/09
RE: Hackers hijack DNS records of high profile New Zealand sites  tomdyninc | 04/22/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here