ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Top level domain names hijacked

Will Knight ZDNet.co.uk

Published: 14 Apr 2000 16:19 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The domain names of high-profile companies like Adidas and Manchester United were hijacked this week by a group of Serbian crackers intent on redirecting traffic to a page containing a political message about the war in Kosovo.

The registration details and DNS (Domain Name System) entries of a large number of companies with .com domains registered by Network Solutions were altered on Sunday.

Network Solutions has confirmed the incident but denies reports stating that up to 2000 Web sites were affected. "Considerably fewer than those numbers of domain names already cited in some news accounts were subject to attack this week," says a spokeswoman. She refuses to disclose the actual figures.

According to Network Solutions, the domain names that were compromised belonged to sites with the lowest level of security they offer. This means that a single email from that domain was enough to verify a change of registration details and DNS server. For higher levels of security, administrators need to send an encrypted request and will then receive a confirmation code via email which they must reply to.

Parties apparently hailing from Serbia managed to spoof email addresses from a number of such sites in order to order these changes with Network Solutions.

The DNS servers for these sites were transferred to another provider and then each individual entry was redirected to a page proclaiming, "KOSOVO IS SERBIA," and "Be happy if we hacked your site because we hack ONLY the best sites on the Internet!"

The Network Solutions spokeswoman claims the company has taken the steps necessary to sort out the problem. "As soon as we became aware of the situation, we quickly addressed it and took steps to prevent further unauthorised changes. To the best of my knowledge, we have detected the unauthorised modifications and corrected the discrepancies," she says.

Other security experts are less forgiving of the security precautions put in place by these Web sites. Paul Cronin, head of penetration testing at CenturyCom comments, "This latest hacking episode appears to be more a case of sloppy security procedures than poor technology."

Although many sites have now been returned to normal, technical director of UK Internet company Web DNS Limited Alex Jeffreys points out that some administrators have not been alerted to the problem. "The onus is on whoever owns the domain," he says.

What do you think? Tell the Mailroom. And read what others have said.

Take me to Hackers

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
38 out of 70 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS, - Lambeth - 2198 RM helps to push the boundaries of technology to ...

Operations Engineer - Server2003/SAN/NetBackups/WINS/DNS/LDAP/London

Operations Engineer / Media/ Server2003/ SAN/ NetBackups/ WINS/ DNS/ LDAP/ London/ 60k My client is a market leading global Media Organisation ...

Senior IT Support Engineer

You will be fully capable of installing Windows Server 2000/2003 to domain level; you will have firsthand experience in designing Active Directory ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment