Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

November 25th, 2010, 09:42 GMT · By

Vulnerability Research Vendor's Domain Hijacked

SHARE:

Adjust text size:


Secunia's domain hijacked by Turkish hackers
Enlarge picture
The domain name of vulnerability research company Secunia was redirected earlier today to an unrelated Web page showing a message in Turkish, after its DNS records were altered.

Secunia is one of the world's leading vulnerability intelligence and management vendors. Based in Denmark, the company tracks, rates and catalogs security vulnerabilities in more than 30,000 software applications, operating systems and appliances.

For one hour and ten minutes today, starting with 00:40 AM CET, users who visited secunia.com saw a page displaying a message reading "Is?ms?z Kahramanlar Sunar.. System Get Down Gel Babana..." and a graphic showing a dragon with the text "TurkGivenligi" (Turk Security).

Screenshot of hijacked secunia.com domain
Enlarge picture
According to the vendor, the attack was the result of the authoritative DNS hosting being redirected. The exact circumstances under which this happened are still being investigated.

The Domain Name System (DNS) is one of the building blocks of the Internet and is responsible for translating domain names into IP addresses.

The secunia.com domain normally resolves to 213.150.41.226, an IP address in Denmark, which belongs to the security company.

However, according to SANS ISC, during the attack, the domain pointed to 81.95.49.32, an IP registered to an UK company called Avensys Networks.

The most straight-forward method of hijacking a domain in this way, short of compromising its authoritative DNS server, is to change its corresponding NS records from the registrar-provided administration panel.

The technique usually involves socially engineering registrar employees and has previously been used to hijack high profile domains like comcast.net, twitter.com and  baidu.com.

Three hackers responsible for hijacking Comcast's domain in 2008 have already received prison sentences for their action.

Baidu sued Register.com last year for gross negligence, after the company's staff gave hackers access to its domain name despite failing to pass the required security checks.

TELL US WHAT YOU THINK:

1,196 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hackers Hijack Cryptome and Delete Everything

Comcast Domain Hijackers Jailed for Eighteen Months

Baidu Blames Domain Registrar for Security Breach

Iranian Hacktivists Hijack Twitter

Comcast Domain Hijackers Indicted

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM