Live data from Hacker News

Google.ps domain was hacked

google.ps

31–40 of 92 posts

Re: Google.ps domain was hacked

#31
Aren't we seeing a lot of DNS based attacks in the recent past? I remember .pk TLD was hacked not too long ago.

Considering that most of the big sites run local variants of their services using these TLDs is it fair to assume that one of these next ones could be of the phishing kind? What's the best thing to do - always use the .com hoping that it is safer?

Re: Google.ps domain was hacked

#32
post #17

Earlier quoted context omitted.

I think saying "google.ps was hacked" is a perfectly reasonable way to describe what happened.

I don't agree at all, the system which was hacked is not in Google's control at all, even though it does depend on it for DNS SOA. Every site depends on root DNS servers to do their job right...the root for .ps was hacked...that's what happened here...google was affected, but not hacked.

You are using these words, but I don't think you know what they mean.

The SOA record is almost irrelevant in this case, unless you are seeing some trickery where they set high TTLs or something to keep the "hack" around longer after it has been corrected.

There is only one root (which is kinda what makes it a root) - and in this case the root servers are doing their job just fine. DNS is hardly even involved. As far as I can tell this was simply a compromise of the web UI that allows for the management of domains under the .ps ccTLD. Probably just another sloppy front end developer.

Re: Google.ps domain was hacked

#33
post #23
post #8

google.ps has not been hacked. The .ps registry was. Google DNS servers have been changed to omar.genious.net and hamza.genious.net

Hacking a registry is even more alarming.

Not all registries are created equal. I'm a heavy Internet user and I'd get along just fine without the .ps nameservers.

Re: Google.ps domain was hacked

#34
post #19

Oh man, imagine the heart attack the engineer who first got this ticket must have had before he realized it was a just a dns hijacking.

Google's incident response team deals with far bigger issues on a daily basis. This is hardly more than a few kids playing around.

Re: Google.ps domain was hacked

#36
post #32

Earlier quoted context omitted.

I don't agree at all, the system which was hacked is not in Google's control at all, even though it does depend on it for DNS SOA. Every site depends on root DNS servers to do their job right...the root for .ps was hacked...that's what happened here...google was affected, but not hacked.

You are using these words, but I don't think you know what they mean. The SOA record is almost irrelevant in this case, unless you are seeing some trickery where they set high TTLs or something to keep the "hack" around longer after it has been corrected. There is only one root (which is kinda what makes it a root) - and in this case the root servers are doing their job just fine. DNS is hardly even involved. As far…

Forgive me, it has been several years since I dealt with DNS authority, however it still does not change the argument that it was not google who was 'hacked'...the title of this post is just blatantly wrong.

Re: Google.ps domain was hacked

#37
post #31

Aren't we seeing a lot of DNS based attacks in the recent past? I remember .pk TLD was hacked not too long ago. Considering that most of the big sites run local variants of their services using these TLDs is it fair to assume that one of these next ones could be of the phishing kind? What's the best thing to do - always use the .com hoping that it is safer?

This isn't a DNS issue, it's a SQL injection attack.

ICANN needs to mandate stronger requirements for best practices with web based management UIs. Unfortunately they have little in the way of real control over ccTLDs.

You'd be best served registering ccTLDs and redirecting them to your gTLD of choice (say, .com) and not trying to serve localized content from them.

Re: Google.ps domain was hacked

#39
post #37
post #31

Aren't we seeing a lot of DNS based attacks in the recent past? I remember .pk TLD was hacked not too long ago. Considering that most of the big sites run local variants of their services using these TLDs is it fair to assume that one of these next ones could be of the phishing kind? What's the best thing to do - always use the .com hoping that it is safer?

This isn't a DNS issue, it's a SQL injection attack. ICANN needs to mandate stronger requirements for best practices with web based management UIs. Unfortunately they have little in the way of real control over ccTLDs. You'd be best served registering ccTLDs and redirecting them to your gTLD of choice (say, .com) and not trying to serve localized content from them.

How do you know what kind of attack vector was used?
Post reply on HN