Showing posts with label Turkish Hackers. Show all posts
Showing posts with label Turkish Hackers. Show all posts

Kaspersky’s Malaysian site hacked by Turkish hacker

According to Zone-h.org, Kaspersky’s Malaysian site has been defaced by a Turkish hacker during the weekend, through a SQL injection, leaving the following message - “hacked by m0sted And Amen Kaspersky Shop Hax0red No War Turkish Hacker Thanx to Terrorist Crew all team members“.

The image “http://blogs.zdnet.com/security/images/kaspersky_malyasia_hacked1.JPG” cannot be displayed, because it contains errors.

“The official Malaysian Kaspersky Antivirus’s website has been hacked yesterday by a Turkish cracker going by the handle of “m0sted”. Along with it, the same cracker hacked also the official Kaspersky S.E.S. online shop and its several other subdomains. The attacker reported “patriotism” as the reason behind the attack and “SQL Injection” as the technical way the intrusion was performed.

Both websites has been home page defaced as well as several other secondary pages. The incident, though appearing a simple website defacement, might carry along big risks for end-users because from both the websites, evaluation copies of the Kaspersky Antivirus are distributed to the public. In theory, the attacker could have uploaded trojanized versions of the antivirus, infecting in this way the unaware users attempting a download from a trusted Kaspersky’s file repository (remember the trojan in the Debian file repository?).”

Are users at risk due to the compromise? Not in this case, however, the attack is a wake up call which if not taken seriously enough could result in an ironic situation where a security vendor’s site is infecting its visitors with malware. It has happened before, and it will definitely happen again.

This is not an isolated incident. According to Zone-h’s archive, since 2000 there have been 36 web site defacements of international Kaspersky sites, with Kaspersky’s French site getting hacked and re-hacked on an yearly basis. And while in none of the incidents there was any malicious software served, or a live exploit URL that could have been embedded into the legitimate site, there’s an ongoing trend related to web site defacements in regard to their interest in monetizing the access they have to the vulnerable sites, by injecting malware URLs, hosting phishing pages, and also, locally hosting blackhat SEO junk pages where they would eventually earn money through affiliate based networks.

In the time of blogging there’s no indication of a malware attack at the site, and kaspersky.com.my remains offline, presumably in an attempt to audit the site for web application vulnerabilities before putting it back online.

Related posts :

[Source: zdnet]

ICANN and IANA’s domains hijacked by Turkish hacking group

What happens when the official domain names of the organizations that issue the domain names in general, and provide allNetDevilz ICANN IANA the practical guidance on how the prevent DNS hijacking, end up having their own domain names hijacked? A wake up call for the Internet community.

The official domains of ICANN, the Internet Corporation for Assigned Names and Numbers, and IANA, the Internet Assigned Numbers Authority were hijacked earlier today, by the NetDevilz Turkish hacking group which also hijacked Photobucket’s domain on the 18th of June. Zone-H mirrored the defacements, some of which still remain active for the time being :

The ICANN and IANA websites were defaced earlier today by a Turkish group called “NetDevilz”. ICANN is responsible for the global coordination of the Internet’s system of unique identifiers. These include domain names, as well as the addresses used in a variety of Internet protocols. The Internet Assigned Numbers Authority (IANA) is responsible for the global coordination of the DNS Root, IP addressing, and other Internet protocol resources.

NetDevilz left the following message on all of the domains :

“You think that you control the domains but you don’t! Everybody knows wrong. We control the domains including ICANN! Don’t you believe us? haha :) (Lovable Turkish hackers group)”

NetDevilz ICANN IANA

The following domains were hijacked, and some of them still return the defaced page - icann.net; icann.com; iana-servers.com; internetassignednumbersauthority.com; iana.com.

The hackers are once again redirecting the visitors to Atspace.com, 82.197.131.106 in particular, the ISP that theyNetDevilz ICANN IANA used in the Photobucket’s DNS hijacking. And while Photobucket hasn’t issued an official statement on the DNS hijack, Atspace.com did so last week, a copy of which you can find here.

The NetDevilz hacking group seems to be taking advantage of a very effective approach when hijacking domain names, and while they declined to respond to an email sent by Zone-H on how they did it,  cross-site scripting or cross-site request forgery vulnerability speculations are already starting to take place.

One thing’s for sure though, if the ICANN and IANA can lose control of their domains, anyone can.





[Source: zdnet]

Photobucket’s DNS records hijacked by Turkish hacking group

June 18th, 2008


Yesterday, Photobucket the world’s most popular photo sharing site according to Hitwise had its DNS records hijackedPhotobucket Hacked by Turkish Hacking Group to return a hacked page courtesy of the NetDevilz hacking group, a Turkish web site defacement group most widely known for its defacement of the adult video site Redtube earlier this year. Photobucket users across the world are reporting minor outages of the service and problems when trying to access their accounts, the consequence of what looks like the type of DNS records hijacking that redirected Comcast.net to a third-party domain last month.

Third-party site monitoring services indicate that the site was down for 15 minutes yesterday, from from 17:39:39 to 17:55:10, whereas according to a comment left by a Photobucket Forum Support representative, the downtime due to the propagation of the corrected DNS entries was longer :

“On Tuesday afternoon, some users that typed in the Photobucket.com URL were temporarily redirected to an incorrect page due to an error in our DNS hosting services. The error was fixed within an hour of its discovery, but due to the nature of the problem, some users will not have access to Photobucket for a few hours as the fix rolls out. It is important to note that only a portion of Photobucket users encountered the problem and that no Photobucket content, password information or other personal information was affected by the redirect.”

The NetDevilz hacking group left the following message, that appears to have been loading from a third-party domain,Photobucket downtime netdevilz atspace.com in this case :

“… ve NeTDevilz yeniden sahnede

Bizi hatırlayan var mı ? Unutulduğumuzu düşündük ve tekrar hatırlatmaya karar verdik !
( Turkish hackers group )

ZeberuS - GeCeCi - MiLaNo - The_BeKiR - h4ckinger - SerSaK - KinSize

we are came back !
©2008 NetDevilz Co.
We’re not first,But We’re the BEST!”

The hacking group appears to have been using the hosting services of atspace.com, the web hosting service of Zetta hosting solutions, and users of Photobucket attempting to access the site with the old DNS entries are still being redirected to a default hosting ad page within atspace.com. The effect of the redirection can also be seen by taking a peek at the publicly obtainable stats for atspace.com, where the sudden peak in traffic resulting in 118,864 visitors for today came from the default ad page used in the redirection.

With the second DNS hijacking attack against a high-profile domain in the recent months, it seems that adaptive malicious parties unable to directly compromise a site will continue taking advantage of good old-fashioned DNS hijacking. At least to prove that it’s still possible even on a high-profile domain using the services of a Tier 1 domain registrar.

[Source: Zdnet]