Several Sites Defaced

Published: 2011-09-04
Last Updated: 2011-09-05 08:40:22 UTC
by Lorna Hutcheson (Version: 4)
8 comment(s)

3rd Update: Update with more details of the incident from The Register itself: http://www.theregister.co.uk/2011/09/05/dns_hijack_service_updated/ (thanks Alex)

2nd Update: The root problem appears to be mitigated now. However, many DNS servers now have bad results cached. Please flush the cache of your recursive DNS servers.

Host names and IP addresses to watch:

ns1.yumurtakabugu.com. or 68.68.21.195
ns2.yumurtakabugu.com. or 68.68.21.196
ns3.yumurtakabugu.com. or 68.68.21.197
ns4.yumurtakabugu.com. or 68.68.21.198
 

IP Address used as A record for affected domains: 68.68.20.116

In particular IP addresses may change at any time. Please keep watching them and remove from blocklist as appropriate.

---

There have been several widespread defacements reported to us today.  It appears their DNS name server entries all point to the same thing as seen below:

ups.com.  85621 IN NS ns1.yumurtakabugu.com.
ups.com.  85621 IN NS ns2.yumurtakabugu.com.
ups.com.  85621 IN NS ns4.yumurtakabugu.com.
ups.com.  85621 IN NS ns3.yumurtakabugu.com.
 

Here are a few examples of the sites so far:

ups.com
theregister.co.uk
acer.com
telegraph.co.uk
betfair.com
vodafone.com
nationalgeographic.com

The one commonality is they all appear to be all registered via ascio.com

More details as we learn more.

 

UPDATE:  This IP is hosted by BlueMile.  We have contacted them and they are aware of the situation and working on it.

8 comment(s)

Comments

cwqwqwq
eweew<a href="https://www.seocheckin.com/edu-sites-list/">mashood</a>
WQwqwqwq[url=https://www.seocheckin.com/edu-sites-list/]mashood[/url]
dwqqqwqwq mashood
[https://isc.sans.edu/diary.html](https://isc.sans.edu/diary.html)
[https://isc.sans.edu/diary.html | https://isc.sans.edu/diary.html]
What's this all about ..?
password reveal .
<a hreaf="https://technolytical.com/">the social network</a> is described as follows because they respect your privacy and keep your data secure:

<a hreaf="https://technolytical.com/">the social network</a> is described as follows because they respect your privacy and keep your data secure. The social networks are not interested in collecting data about you. They don't care about what you're doing, or what you like. They don't want to know who you talk to, or where you go.

<a hreaf="https://technolytical.com/">the social network</a> is not interested in collecting data about you. They don't care about what you're doing, or what you like. They don't want to know who you talk to, or where you go. The social networks only collect the minimum amount of information required for the service that they provide. Your personal information is kept private, and is never shared with other companies without your permission
https://thehomestore.com.pk/

Diary Archives