Domain name record altered to hack Comcast.net
By
Robert McMillan
,
IDG News Service
, 05/29/2008
- Share/Email
- Tweet This
- Print
Hackers knocked Comcast.net offline late Wednesday night, preventing customers from getting to their Comcast Web mail and
account records on the company's Internet portal.
The criminals somehow got their hands on passwords used to alter domain-name registration information with Comcast's registrar,
Network Solutions, said Susan Wade, a Network Solutions spokeswoman. With access to the Comcast.net record, the hackers were
able to switch the DNS (Domain Name System) servers associated with Comcast.net and redirect Internet traffic to their own
server. They also added offensive comments to the Comcast.net record.
Visitors who went to Comcast's portal between approximately 11 p.m. Eastern time Wednesday and 12:30 a.m. Thursday were greeted
with either a "Site under construction" message or a cryptic note reading: "KRYOGENIKS EBK and DEFIANT RoXed COMCAST sHouTz
To VIRUS Warlock elul21 coll1er seven," an apparent reference to the hackers who had compromised the site and to their friends.
This attack is connected to recent defacement of the MySpace.com profiles of Justin Timberlake, Hilary Duff and Tila Tequila,
said security researcher Dancho Danchev.
No one knows how the hackers gained access to Comcast's Network Solutions account. In the past, registrars have been tricked
into handing over control of Internet domains. But Danchev said that lately, criminals have also been using phishing attacks to try to take control of Web domains.
Throughout Thursday, the Comcast.net Web page continued to experience problems. For many visitors, the page was missing graphics
and had the look and feel of an early 1990s Web site.
"We believe that our registration information at the vendor that registers the Comcast.net domain address was altered, which
redirected the site, and is the root cause of today’s continued issues as well," Comcast said Tuesday in a statement. " We
have alerted law enforcement authorities and are working in conjunction with them.”
Neither Comcast nor Network Solutions can say how the hackers got their hands on the Comcast password, but this type of problem
is not unheard of, Wade said. "It's not frequent, but it does happen," she said.
There are steps that companies can take to secure their domain name registration accounts, Wade said. "We tell folks, especially
big companies, to consolidate domains so you have someone in charge of all the domains," she said. "We encourage people to
update their passwords on a regular basis and make sure the passwords are complicated."
The IDG News Service is a Network World affiliate.
Comments (1)
Still vulnerableBy Anonymous on May 30, 2008, 10:53 amCOMCAST's (repaired) domain-registration lists: Record expires on 24-Sep-2008. Yes, only a few months away, before a "domain-squatter" will pounce upon their...
Reply | Read entire comment
View all comments