June 30, 2008 10:45 AM PDT

Turkish criminal hackers hijack ICANN sites

by Robert Vamosi
  • Font size
  • Print
  • 2 comments

On Thursday, the domains used by ICANN, the Internet Corporation for Assigned Names and Numbers, and IANA, the Internet Assigned Numbers Authority, were hijacked. A Turkish hacking group known as NetDevilz claimed =responsibility. There is no word on how the hijack was accomplished.

The group successfully redirected ICANN site visitors to a page with the following message:

"You think that you control the domains but you don't! Everybody knows wrong. We control the domains including ICANN! Don't you believe us? haha :) (Lovable Turkish hackers group)"

According to SANS, changes to the ICANN site were corrected within 20 minutes. However, the update took another 24 to 48 hours to propagate throughout all the DNS serves worldwide.

On June 19, NetDevilz evidently hijacked Photobucket's DNS records, which resulted in a denial of service against that service.

The timing of the attack on ICANN is embarrassing for the organization, to say the least. Last week, ICANN announced it was opening up the generic top-level domain name (gTLD) to include just about anything. Currently, gTLDs are limited to .com, .net, .org, and 18 others. Under the new plan, like businesses could be organized under .healthcare, for example. In his blog, Neal Krawetz looks at the pros and the cons of the change.

None of the DNS hijacks have involved serving up malicious software.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from Defense in Depth
Window Snyder to leave Mozilla
How to handle ID fraud's youngest victims
Is white listing going mainstream?
How Live OneCare changed the antivirus landscape
Express Scripts clients threatened with extortion
Study: DDoS attacks threaten ISP infrastructure
Security expert talks Russian gangs, botnets
Extortion used in Express Scripts database breach
Add a Comment (Log in or register)
by livecrunch June 30, 2008 12:17 PM PDT
Yes I wrote about it about 3 days ago on my blog http://www.livecrunch.com . So anyways how do you now feel about having domain name after incident like that? I mean there is always smarter people then your it group yet wouldnt you secure such site "ICANN" or IANA better?
Reply to this comment
by RobertFHarwood June 30, 2008 2:09 PM PDT
Several of the sites I host have been attacked by this group. They don't have FTP, they use WebDAV for updates and these gives overwrote the default.htm and index.html pages.
Reply to this comment
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right