[圖]
 


[圖]
 




   
   
 



http://grahamcluley.com/2013/10/avg-website-palestinian-hackers/


AVG and Avira anti-virus websites attacked by pro-Palestinian hackers

Graham Cluley | October 8, 2013 10:40 am | Filed under: Malware, Vulnerability |  3
If you're new here, you may want to subscribe to the RSS feed, like us on Facebook, or sign-up for the free email newsletter which contains computer security advice, news, hints and tips. Thanks for visiting!

AVGThe website of AVG, makers of one of the world’s most popular free anti-virus products, appears to have been hacked by a pro-Palestinian group.

Visitors to http://www.avg.com will not be greeted by the normal promotions for anti-malware software but instead be greeted by a patriotic rendition of the Palestinian national anthem (courtesy of an embedded YouTube video) and a message from a group calling itself “KDMS Team”.

AVG hacked

Here is the (not terribly well spelt) message left by the website’s defacers:

MISSION COMPLETED
HACKED
KDMS TEAM
PLAESTINIAN HACKERS

Hello World

We Are Here To Deliver Tow Messages

First one:

we want to tell you that there is a land called Palestine on the earth
this land has been stolen by Zionist
do you know it ?
Palestinian people has the right to live in peace
Deserve to liberate their land and release all prisoners from israeli jails
we want peace

long live Palestine

Second Message:

There Is No Full Security
We Can Catch You !

Hacked by KDMS team
Now .. We Will Quit Hacking

It’s possible that the hackers managed to change the website’s DNS records, redirecting anyone who attempted to visit www.avg.com to a different IP address.

It’s clearly embarrassing for a security company to hit in this fashion by hackers, but there is no indication that any customer information or sensitive data has been compromised.

AviraUpdate: Another anti-virus company, Avira, has also been hit in what appears to be the same attack.

Softpedia reports that Avira has confirmed that the cause of the disruption was DNS hijacking, and quotes Avira’s Sorin Mustaca as blaming bogus password resets at Network Solutions:

It appears that several websites of Avira as well as other companies have been compromised by a group called KDMS. The websites of Avira have not been hacked, the attack happened at our Internet Service Provider Network Solutions.

It appears that our account used to manage the DNS records registered at Network Solutions has received a fake password-reset request not being initiated by anyone at Avira.

Network Solutions appears to have honored this request and allowed a 3rd party to assume control of our DNS. Using the new credentials the cybercriminals have been able to change the entries to point to their DNS servers. We are working with the ISP to receive control on the domain name and only when we have solved the problem we will restore the access to the Avira services.

At this point we are not aware of any effect to our customers.

DNS records work like a telephone book, converting human-readable website names like avira.com or avg.com into a sequence of numbers understandable by the internet. What seems to have happened is that someone changed the lookup, so when you entered whatsapp.com into your browser you were instead taken to a website that wasn’t under the legitimate company’s control.

The question now is how did the hackers manage to change the DNS records for these sites?

Could it be that cybercriminals managed to guess the passwords used to secure access to the information, and log in as though they were the administrators of the sites’ DNS records?

Or was Network Solutions – which manages the DNS records for these companies – tricked into changing the passwords, and as a result allowed the hackers to gain access to the DNS entries?

Hopefully the AVG and Avira teams will be able to resolve this issue quickly, and normal service will be resumed.

















 
 









※ 編輯: ott 時間: 2013-10-08 23:54:15
※ 看板: ott 文章推薦值: 0 目前人氣: 0 累積人氣: 522 
分享網址: 複製 已複製
guest
x)推文 r)回覆 e)編輯 d)刪除 M)收藏 ^x)轉錄 同主題: =)首篇 [)上篇 ])下篇