Want To Hijack a Domain? Just Get a Fax Machine
msm1267 writes "Metasploit's HD Moore says hackers sent a spoofed DNS change request via fax to Register.com that the registrar accepted, leading to a DNS hijacking attack against the Metasploit and Rapid7 websites. The two respective homepages were defaced with a message left by the same hacker collective that claimed responsibility for a similar DNS attack against Network Solutions. Rapid7 said the two sites' DNS records have been locked down and they are investigating."
Social engineering is not hacking to me.
What is the legal crime committed here, simply fraud?
Some people die at 25 and aren't buried until 75. -Benjamin Franklin
There has been some commentary via mailing lists and Twitter feeds that this was not a big deal. Firstly, hats off to HD and his team, there was nothing they could have done about it. Secondly, this isn't to be taken lightly. Sure the attackers were minor script kiddies, but the reality is, the attack could have been extremely vicious. Consider an attacker replicating the content of the site and simply replacing the applications (nexpose, metasploit) with backdoored versions.
Companies like Register and GoDaddy are lacking in the validation category. ANYONE can create fake identification using GIMP, Photoshop, etc., the fact they did not offer anything other than a fax request is mind bogglingly stupid. They should have called BACK the registrant's number to confirm the change request. But, companies would argue: "that would be costly" not even thinking of turning that kind of validation into say a business model: "for $10 extra per year..." when they should be doing it from the jump. (Neither here nor there) Personally, I hadn't been running any updates, but if I did, I would be going back, wiping my machines, and re-installing.
"The DNS hijacking attack was resolved within an hour, Moore said."
Is that a DNS joke?
The only evidence actually quoted that the attack was by faxed change request is the defaced website. Do we trust the "hackers" that much that we believe they made the change by sending a fax? Could the group be giving a red herring?
I figured this out years ago and stole back a domain taken by an pissed off ex-employee that claimed ownership of the company's domain name. took about 2 days to iron out the issues, then transfer the domain to another registrar and lock it. from that point, i've done it several times since.
It's "Canadian Hacking". Instead of breaking into someone's computers and maliciously altering their data, you just call them up or send a note to ask politely if they would do it to themselves.
You'd be surprised at how often it works, eh?
The sad truth about the DNS.
Fax machines are still a thing because the old people using them haven't died yet. No, that's really it. It's a lot like a bunch of social movements. The vast majority opposed to a given thing don't have their minds changed, they just die. The younger generation won't have an attachment to fax machines, so they won't use them. The younger generation sometimes growing up having seen something different, so they don't have the same attitudes about certain things.
The quote on the bottom at the time of this posting is, "Progress means replacing a theory that is wrong with one more subtly wrong."
This is wrong. Progress is death keeping count.
I recently moved. As I called the various utilities to tell them to cancel my service few of them asked for any kind of identification except my address. I other words in could easily shut off anyone's gas, electricity, internet service
On the other hand it's pretty nice to live in a society with so much trust
In 1999/2000 all we had to do to get a dns change from network solutions was fax in a request with a company letter head. They would change the new clients DNS to use and off we went.
by TheSpoom (715771) Uncaring Linux user here. I have nothing to add to this but please continue. *munches popcorn*
Does DNSSEC could have prevented this situation to happen?
If I recall correctly, this was the same stunt somebody used to kidnap sex.com about 10 years ago.
why not use e-mail and text messaging? just asking. with email, you can just attach an OpenOffice document, jpg or PDF to an email and send the email.
I had to do this recently for a legitimate reason. A friend had bought a small hobby type operation (including the domain), but the old owner forgot to change the domain ownership over and dropped off the grid. It wasn't really a problem until we wanted to change hosting providers, at which point we couldn't update the DNS settings.
Since we actually had control of the domain, I used the account that was listed as the admin contact to send an email to the registrar explaining the situation and asking if they could change the info for us. Without any validation whatsoever they sent me the username and password (apparently stored in clear text) for the account, allowing me to do anything I wanted with it.
Thankfully I don't use that registrar for my own stuff. I expected at least to have to show some proof of ownership or something.
-- "So they told me that using the download page to download something was not something they anticipated." - Bill Gates
It always amazed me how much trust a fax carries for some companies/government agencies.
just to steal an internet domain?
> But we already HAD a word for that and it was not "hackers" it was con artists..
I think the distinction is in your last three words, "hacking a system".
A con man or fraudster will get a _person_ to hand over their property.
A hacker manipulates a _system_ to have it do something other than what it's supposed to do.
TFA says:
"The group was able to change the DNS records managed by Network Solutions for a number of security companies".
They did a number of companies by exploiting NetSol's SYSTEM, not simply tricking one person, but exploiting
holes in the system that the person what was part of. If you can fairly reliably exploit the system, it's a hack in my opinion whether that's a TCP/IP system, a phone system, a traffic light control system, or system that includes both
computers and human.
However, see also the Jargon File for original meanings of the term:
http://www.dourish.com/goodies/jargon.html
http://www.outpost9.com/reference/jargon/jargon_23.html#SEC30
Oh... I think I saw one of those at the antique store the other day. I was going to grab it until he told me the jack in it wasn't for ethernet. Apparently you had to plug it into a... I believe he called it a "land... line..."
I'm trying to teach myself to set people on fire with my mind... Is it hot in here?
Defaced implies that they were changed on the server. That didn't happen. The domain was hijacked and the replacement pages were put up on another server.
Want so jail time with Bubba? Use a fax machine to steal someones domain.
Jack of all trades,master of none
My post's on topic, useful, & correct - why down mod? Quoting ULTRON on this one, per my subject, addressed to "hit & run" unjustifiably downmodding my post trolls:
"You are NOTHING to me - 1 by 1, I will destroy you: I will never tire. I will Never SHOW MERCY, & I will never stop, until each and every one of you is gone..." - ULTRON (position 4:27 on the YouTube player control)-> http://www.youtube.com/watch?v=2_-Ar-LTeYk
* Truth be told? I don't just *think* I've 'destroyed' the one doing the unjustifiable downmodding before - I know I have - hence, their "not man" behavior downmodding 'hit & run' style, yet not technically justifying on topic validly, why.
(Their favorite color must be transparent - I see right thru it).
APK
P.S.=> Anyhow/anyways: This place is unbelievable - it condones weak weasels that you can't identify doing bogus abuses of the moderation system + proving they won't stand behind their bogus rating, or their words either - the moderation system here needs that adjustment put into place & it'd be a far better place here (& I'm FAR from the only one asking that around here)).
Especially vs. trollish worms that pull "hit & run" downmods that are technically unjustifiable - & if anyone doesn't like that, they're free to validly technically disprove any points here on the topic regarding hosts efficacy...
(Good luck - you'd need it, plus a miracle (& you know it, hence the bogus downmod, + doubtless futher ac trollinga afterwards))
... apk