Microsoft, Kaspersky and Other Malaysian Domains Hacked

Update 2 (2/7/2013): Most sites that were reported to have been DNS Spoofed are now back online with slightly altered domain names, while Google Malaysia and Dell Malaysia seemed to have rectified the spoofing problem on their original URLs.

CA Technologies released a statement in regards to the issue at hand and shared of other similar threats that are prevalent:

“There is no denying that DNS Server Attacks are gathering momentum. To secure a DNS server, companies need to understand how others might exploit it. The most common threats are Denial of Service (DoS) attacks, tampering with DNS records, and information gathering. DoS attacks are probably the most common threat because they’re remarkably easy to pull off, thanks to the large number of incorrectly configured DNS servers on the Internet,” Vic Mankotia, CA Technologies Vice President for Security in Asia Pacific & Japan.

According to Mankotia, these servers are usual launching points for DoS attacks, wherein an attacker uses it to allow recursions to pummel another server with packets. “This kind of attack starves the target server of resources and prevents legitimate users from accessing it. This sort of DNS tampering, which takes several forms, is less common but still a threat,” he adds.

CA notes that the attack vector used for the latest DNS tampering is called cache poisoning. This method basically injects fake records into a DNS server’s cache. Other methods include forged packets, man-in-the-middle attacks, and rogue DNS servers. In addition to modifying records, attackers also work to gather information via server mining, zone transfers, and data packet interception.

“Having properly configured DNS servers can greatly limit your exposure to all these tactics,” Miknotia concludes.

 

Update 1: On that note, Microsoft Malaysia just released a statement:

“It has come to our attention that a number of URLs ending with the .my Top Level Domain (TLD) suffix are currently being redirected to an external third-party website. This has impacted several Malaysian company URLs with the .my suffix, including Microsoft Malaysia’s www.microsoft.com.my,” says Leigh Wong, Communications Lead of Microsoft Malaysia.

“At this time, we have no evidence that any customer or partner data has been affected. So far, simply URLs ending with “.my” are affected. www.microsoft.com/malaysia is still fully operational. We are working with the relevant authorities and industry partners to resolve this matter quickly.”

“We will keep the public updated via our Facebook page at www.facebook.com/MicrosoftMalaysia and www.twitter.com/mymicrosoft.”

 

****************

What a way to start a Monday with many of Malaysian domains attacked by TiGER-M@TE via DNS spoofing (DNS cache poisoning). This group is known to be a top hacker in Bangladesh. As of now, there is no mention of the reason why this is happening. However, this does raise questions on how powerful hackers are becoming and just how well managed is our own cyber-security.

Malaysian sites hacked

Here is a list of affected websites:

So, what is DNS spoofing? It is a form of computer hacking attack, whereby data is introduced into a Domain Name System (DNS) server’s cache database. In return, it cause the name server to return an incorrect IP address, hence, diverting traffic to another computer (often the attacker’s).

It was also reported that Google Malaysia was also affected by this attack. PC.com made a quick call to Google Malaysia to get an official statement. However, it declined to many any official statement. At press time, Google already filed reports with CyberSecurity Malaysia and MyNIC and is now working to resolve the issue.

Stay tune to this space for more updates.

Share this post:

One Response

Comment what you think!