Slashdot Mirror


Hackers Compromise ICANN, Access Zone File Data System

Trailrunner7 writes with this news from ThreatPost: Unknown hackers were able to compromise vital systems belonging to ICANN, the organization that manages the global top-level domain system, and had access to the system that manages the files with data on resolving specific domain names. The attack apparently took place in November and ICANN officials discovered it earlier this month. The intrusion started with a spear phishing campaign that targeted ICANN staffers and the email credentials of several staff members were compromised. The attackers then were able to gain access to the Centralized Zone Data System, the system that allows people to manage zone files. The zone files contain quite bit of valuable information, including domain names, the name server names associated with those domains and the IP addresses for the name servers. ICANN officials said they are notifying any users whose zone data might have been compromised." (Here's ICANN's public note on the compromise.)

6 of 110 comments (clear)

  1. fire them by Megor1 · · Score: 1, Insightful

    Any employee dumb enough to fall for a phish should be fired.

    --
    Everyone that disagrees with me is a paid shill
    1. Re:fire them by CaptainDork · · Score: 3, Insightful

      Any IT shop that ain't got the sense god gave a pissant to identify a phishing attack programmatically and shield employees who work on the INCOME side of the ledger, as opposed to IT, which is on the EXPENSE side, needs to be hit over the head with a wet squirrel and stuff.

      --
      It little behooves the best of us to comment on the rest of us.
    2. Re:fire them by Mr+D+from+63 · · Score: 2, Insightful

      Any employee dumb enough to fall for a phish should be fired.

      I agree, when you work for ICANN or an organization of similar responsibility, there has to be some accountability at the employee level.

    3. Re:fire them by Archangel+Michael · · Score: 3, Insightful

      If my PM sent me a word doc via email, especially if it was sensitive, I would fire the PM for incompetence. Files should be stored on servers where proper security can be enabled and monitored. Once a doc gets attached to email, you have lost all control over it.

      Document control systems need to be in place, and email is not a document control system.

      --
      Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
    4. Re:fire them by sjames · · Score: 3, Insightful

      If anyone doesn't think IT is on the INCOME side, they should give the sales guys a pad and a pencil and shut down IT services for a week. Let's see how much INCOME they have then. Make that week during payroll and lets see what their INCOME looks like when nobody gets paid.

  2. Apparently I've been a hacker for years by kdub007 · · Score: 4, Insightful

    I've been able to get all of that info for 15 years using the apparently malicious tool, WHOIS. Now, if they were able to change that data, that's different, but according to this post, all the "hackers" got was publicly available information.

    --
    The correct answer is 42.