Anatomy of a DNS Hack


Screenshot of Hack SiteThis weekend, the DNS settings of a group of popular websites were hacked to redirect to the site of a Turkish hacker.

When users attempted to visit the sites of The Daily Telegraph, UPS, Vodaphone, The Register, National Geographic and others, they were greeted by a headline reading "Turkish Security, Come to Papa" in Turkish (see picture, left). The group behind the hack also claims credit for hacking the South Korean domain name registrar last month, an attack that affected over 100,000 domains, including those of HSBC Korea and Epson Korea.

When a site's DNS settings are hacked, it is not the same as the website itself being hacked. When hackers go after a website, they look for vulnerabilities in the site's code. When they target the DNS settings, they have to hack into the domain name registrar in order to gain access. Representatives from The Guardian reported that the hackers had gotten access through NetNames and others; CNET confirmed this yesterday.

The DNS settings of a given domain name basically tells it what IP address it should direct to; in this case, the hackers changed the IP addresses listed to the one for the "Turkish Security" site. Because of the way DNS changes work, not all visitors to these sites were affected by the hack at the same time. In turn, not all will be able to see the fixes that are made at the same time. As a precaution, The Register has opted to shut down its entire site as a precaution to shield its readers. Users can also clear their cookies in order to block the hackers from stealing their information.

Fortunately, this hack appears to merely be a prank. But the potential damages that DNS hacks are capable of wreaking are no joke.

Trackback URL for this post:

http://www.domainnamestrategy.com/trackback/273

Treat Your DNS Account Like Your Bank Account!

I just don't understand why/how people manage to get their DNS or Registrar accounts hacked. Treat that dang thing like your Bank Account. It's precious. Change your passwords frequently. Make it a difficult password etc.

And for goodness sake register your domain or manage your DNS (or both) with a reliable company. This type of hack should NEVER happen!

The content of this field is kept private and will not be shown publicly.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.

All comments must be approved before they are made available to the public. We will only approve comments that are directly related to the blog and use appropriate language.