News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Network Security
Average Rating:
Rate this article:  
Comcast Hijackers Expose Flaws in Internet Comcast Hijackers Expose Flaws in Internet's DNS
By Richard Koman
May 30, 2008 10:12AM

    Bookmark and Share
Teen hackers Defiant and EBK apparently used "social engineering" to disrupt Comcast Web sites and redirect user e-mail. Defiant and EBK used the Domain Name System and registrar Network Solutions to reroute and deface Comcast sites. Defiant and EBK took comcast.net down for more than two hours and put obscenities in the WHOIS information.
 



Teenage hackers temporarily hijacked and defaced several Comcast Web sites and redirected user e-mail in an exploit that appears to expose fundamental weaknesses in the Internet's Domain Name System. The hackers, known as Defiant and EBK, apparently used "social engineering" -- persuading insiders to hand over account information -- to break into Comcast's account at domain registrar Network Solutions.

Comcast.net -- Comcast's main Web site -- was down for more than two hours, sporting a pink-on-white message that "KYROGENIX Defiant and EBK RoXed COMCAST sHouTz To VIRUS Warlock elul21 coll1er seven."

In addition, the WHOIS database of domain ownership spewed out a stream of obscenities when queried for information on Comcast sites.

Domain Jacking

Andrew Storms, director of security operations at nCircle Network Security, explained the nature of the exploit in an e-mail. "While we haven't seen all the details on exactly what did transpire, more than likely the hackers performed what would be considered a well-known and understood attack called domain hijacking," Storms said.

"The persons who maintain control over the centrally housed domain-name information with a registrar have the ability to control the DNS information for that domain. Once you have control over DNS, it's quite simple to propagate information into the Internet, telling computers where a Web site can be found."

In essence, the hackers could reroute the proper IP address for comcast.net to some other IP address -- and every time Comcast corrected the information, the hackers were able to reroute the domain.

'Really Bad'

It doesn't appear that the hackers did much more than deface Comcast's Web site and interrupt users' access to e-mail. With the level of control they had, "they could have done a lot worse," Storms said. "Instead of displaying a defacement, they could have just as easily used their control to set up a fake Webmail site to capture login information or launch phishing attacks."

In an interview with Wired's Threat Level blog, the hackers expressed fear that what may have been intended as a stunt to prove their hacking prowess could land them in trouble. "The situation has kind of blown up here, a lot bigger than I thought it would," 19-year-old Defiant told writer Kevin Poulsen. "I wish I was a minor right now, because this is going to be really bad."

The hackers said they exploited a flaw at Network Solutions, but the registrar denies any lapse. "We now know that it was nothing on our end," spokesperson Susan Wade said. "There was no breach in our system Relevant Products/Services or social-engineering situation on our end."

Comcast Hatred

According to Wired, Defiant and EBK managed to get control of more than 200 Comcast domains. They said that when they initially broke in, they called the Comcast employee listed as technical contact at home to tell him what they had done. When he hung up on them, they started redirecting Comcast domains to servers under their control. They said they went through more than 50 servers in a matter of hours. "You know how hard it is to find hosting handling that kind of traffic?" EBK asked Wired. "The first one went in two minutes."

The hackers denied speculation that the hack was retribution for Comcast's blocking of BitTorrent traffic. "I'm sure they hate us, too," says Defiant. "Comcast is just a huge corporation and we wanted to take them out, and we did."
 

Tell Us What You Think
Your Comment:



Advertisement


 Network Security
1.   China Cyberattacks: Pervasive Threat
2.   Patch Tuesday Will Tie MS Record
3.   Cybersecurity Appears Hot for 2010
4.   EPIC Objects To Google-NSA Ties
5.   Torrent Traps Used To Harvest Logins


advertisement
EPIC Objects To Google-NSA TiesEPIC Objects To Google-NSA Ties
Cyberattack meant to rattle Google?
Average Rating:
Torrent Traps Used To Harvest LoginsTorrent Traps Used To Harvest Logins
Web sites sold with backdoor access.
Average Rating:
Social Networks: A Hacker's DelightSocial Networks: A Hacker's Delight
Workers urged to be 'trained skeptics.'
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Intel Launches Quad-Core Itanium 9300 Series Processor
After two unexpected delays, Intel has launched the Itanium 9300 series, a 64-bit, quad-core processor code-named Tukwila that is expected to double the performance of its predecessor.
 
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.