Tag Archive for: unprecedented

Inside the DNSpionage hacks that hijack domains at an unprecedented scale

Inside the DNSpionage hacks that hijack domains at an unprecedented scale

Enlarge (credit: Lion Kimbro)

Since the beginning of the year, the US government and private security companies have been warning of a sophisticated wave of attacks that’s hijacking domains belonging to multiple governments and private companies at an unprecedented scale. On Monday, a detailed report provided new details that helped explain how and why the widespread DNS hijackings allowed the attackers to siphon huge numbers of email and other login credentials.

The article, published by KrebsOnSecurity reporter Brian Krebs, said that, over the past few months, the attackers behind the so-called DNSpionage campaign have compromised key components of DNS infrastructure for more than 50 Middle Eastern companies and government agencies. Monday’s article goes on to report that the attackers, who are believed to be based in Iran, also took control of domains belonging to two highly influential Western services—the Netnod Internet Exchange in Sweden and the Packet Clearing House in Northern California. With control of the domains, the hackers were able to generate valid TLS certificates that allowed them to launch man-in-the-middle attacks that intercepted sensitive credentials and other data.

Short for domain name system, DNS acts as one of the Internet’s most fundamental services by translating human-readable domain names into the IP addresses one computer needs to locate other computers over the global network. DNS hijacking works by falsifying the DNS records to cause a domain to point to an IP address controlled by a hacker rather than the domain’s rightful owner. DNSpionage has taken DNS hijacking to new heights, in large part by compromising key services that companies and governments rely on to provide domain lookups for their sites and email servers.

Read 13 remaining paragraphs | Comments

Biz & IT – Ars Technica

‘Unprecedented’ DNS Hijacking Attacks Linked to Iran – Threatpost

  1. ‘Unprecedented’ DNS Hijacking Attacks Linked to Iran  Threatpost
  2. Iranian hackers suspected in worldwide DNS hijacking campaign  ZDNet
  3. A DNS hijacking wave is targeting companies at an almost unprecedented scale  Ars Technica
  4. A Worldwide Hacking Spree Uses DNS Trickery to Nab Data  WIRED
  5. DNS Hijacking Campaign Targets Organizations Globally  Dark Reading
  6. View full coverage on read more

“HTTPS hijacking” – read more

Hayden: Chinese cyber theft ‘on unprecedented scale’ – CNN (blog)


PolicyMic

Hayden: Chinese cyber theft 'on unprecedented scale'
CNN (blog)
All nations conduct espionage. But some nations, nations like ours, self-limit. We steal other nation's secrets to keep Americans safe and free. We don't do it to make Americans rich or to make American industry profitable. And what the Chinese are
Cyber War: China is the Cyber Espionage Capital Of the WorldPolicyMic
RSA 2013: China not the only cyber espionage country, says MandiantComputerWeekly.com
Faria: China – Spies, Sexpionage and Cyber Wars Against AmericaGOPUSA
USA TODAY –Deutsche Welle –Radio Free Asia
all 133 news articles »

Espionage China – read more

RIIS Develops Unprecedented New Mobile Security Tool to Stop Android … – Sacramento Bee

RIIS Develops Unprecedented New Mobile Security Tool to Stop Android
Sacramento Bee
Godfrey Nolan, RIIS President, published a book on Android security earlier this year. Decompiling Android shows why Android apps can be decompiled to recover their source code, what it means to Android developers and how to protect code from prying

“android security” – read more