Sunday, January 26, 2014

Google's Malaysia site latest to be felled in DNS attacks

Google is the latest victim of an ongoing spate of attacks on DNS records

IDG News Service - Google's website for Malaysia was briefly tampered with on Friday, underscoring continuing weaknesses in entities administering crucial website address database records.

The site, "google.com.my," was functioning normally later on Friday, but had briefly displayed a page put in place by the hackers.

A group calling itself "Team Madleets" claimed responsibility for the hack on Facebook. According to the group's Facebook page, it claimed to have modified Google domains for Serbia, Kenya, Burundi and Pakistan over the last few weeks.

The country-code top level domain ".my" is administered by the Malaysia Network Information Center (MYNIC). An official contacted Friday morning said the organization was investigating a DNS (Domain Name System) attack. It wasn't immediately clear how the group performed the attack.

Later in the day, MYNIC confirmed that "google.my" was also affected and redirected to a page controlled by Team Madleets. "At the moment, we are undertaking all necessary measures to monitor the situation and prevent further related issues," according to a statement on its website.

The DNS is a distributed database that allows a domain name to be translated into an IP address that can be requested by a Web browser. Companies and organizations that hold those records have come under attack by hackers in recent weeks.

Attackers have found success in capturing login credentials for people authorized to modified the records through targeted email attacks known as spear phishing.

If a DNS record is modified, it can cause a person looking for a website to be redirected to a different one controlled by the hacker. That's dangerous because the site a person is redirected to could be engineered to attack a person's computer and deliver malicious software.

Team Madleets describes itself as an ethical hacking group on its Facebook page. In a post, it said the MYNIC hack was not the "result of any kind of hate."

Google did not immediately comment on the attack.

Top-level domains such as ".com" and country-code top level domains are held by a variety of companies and organizations. The security of those records is managed by those companies and is often mostly out of the control of the entities whose DNS records they hold.

A string of prominent companies have been affected by DNS hacks recently, including the New York Times, Huffington Post, Twitter and LeaseWeb.

Earlier this week, a pro-Palestinian group gained entry to Network Solutions' network and modified DNS records for the website of the security companies AVG and Avira; the messaging platform WhatsApp; RedTube, a pornography site; and Alexa, a Web metrics company.
    

Thursday, December 5, 2013

Social Network Security Breached



NATION

Mass hack affects almost 2 million Internet accounts



By Toby Talbot, AP
In this Jan. 10, 2002, file photo, a computer screen shows a password attack in progress at the Norwich University computer security training program in Northfield, Vt.
Almost 2 million accounts on Facebook, Google, Twitter, Yahoo and other social media and Internet sites have been breached, according to a Chicago-based cybersecurity firm.
The hackers stole 1.58 million website login credentials and 320,000 e-mail account credentials, among other items, the firm Trustwave reported. Included in the breaches were thefts of 318,121 passwords from Facebook, 59,549 from Yahoo, 54,437 from Google, 21,708 from Twitter and 8,490 from LinkedIn. The list also includes 7,978 from ADP, the payroll service provider. According to a Trustwave blog, "Payroll services accounts could actually have direct financial repercussions."
The hacking began Oct. 21 and might still be taking place, according to CNN.
John Miller, a security research manager at Trustwave, told CNN, "We don't have evidence they logged into these accounts, but they probably did."
There are several other servers Trustwave has not yet tracked down, Miller told CNN.
ADP, Facebook, LinkedIn and Twitter told CNN they have notified users and reset passwords for compromised accounts. Google declined to comment and Yahoo did not respond immediately, CNN reported.
The majority of passwords were from the Netherlands, followed by Thailand, Germany, Singapore, Indonesia and the United States, which accounted for 859 reports from machines and 1,943 passwords, according to Trustwave. In all, just over 100 countries were affected, and Trustwave said this shows the attack is "fairly global."
In compiling the data, Trustwave also discovered that many users are doing just what computer specialists advise against – using simplistic passwords that can easily be guessed. For instance, the top five passwords Trustwave found in researching the breaches were: 123456, 123456789, 1234, password and 12345.
According to its website, Trustwave helps businesses fight computer crime, protect data and reduce security risks.
The breaches operated through software maliciously installed on computers around the world, CNN reports Trustwave said. The virus borne from the software has been sending the stolen information over to a server in the Netherlands controlled by the hackers, according to CNN.
Trustwave researchers on Nov. 24 detected the server and found compromised credentials for about 100,000 websites.