Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,151,527 members, 7,812,643 topics. Date: Monday, 29 April 2024 at 04:47 PM

How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised - Webmasters - Nairaland

Nairaland Forum / Science/Technology / Webmasters / How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised (1625 Views)

How Google Tracks You. / How Google Adsense Approved Me With Just 8 Blog Posts / Economic And Financial Crimes Commission (efcc) Website Compromised (2) (3) (4)

(1) (Reply) (Go Down)

How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised by Slyr0x: 8:48pm On Nov 24, 2012
Today morning, when i accessed google.com.pk, I was surprised to see the defacement page of turkish hackers, Later on i came to know that other websites such as Microsoft.com.pk were also defaced this morning. On checking the name servers with nslookup, the DNS servers were pointing towards another website, It was clear that the hacker compromised the DNS server and changed the DNS servers to their own, where they had their defacement page. The above image appeared on major .pk domains, when users were trying to access them.


Some time later the page started pointing towards google.com instead of google.com.pk, However the name servers of all .pk domains are still pointing towards freehostia.

[img]http://4.bp..com/-6V4N-HpFIQs/ULCSebuAM-I/AAAAAAAACTU/amY5JWVJFjU/s1600/nameservers.png[/img]

So as i mentioned earlier that it looks to me that the registrar that was responsible for Google's DNS records may have been compromised and the records were changed, so when users went to google.com.pk they were redirected to different website which was setup by Turkish hacker to make it look that google.com.pk has been actually compromised.

[img]http://4.bp..com/-1sSqFFJvAzc/ULCWnw1LuEI/AAAAAAAACTw/xrgS02PbpZY/s1600/whois.png[/img]

By a quick whois search i came to know that the registrar that is responsible to PKNIC domains is MarkMonitor, The is a huge chance that the turkish hackers may have gained access to MarkMonitor and then would have changed the DNS servers. Another possibility is that the hackers may have used an attack called "DNS Cache Poisoning" in order to change the DNS servers. I will update this page as soon as i have more updates regarding this attack.


http://www.rafayhackingarticles.net/2012/11/how-google-pakistan-was-hacked.html
Re: How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised by Slyr0x: 8:49pm On Nov 24, 2012
Update: Here is the Full List Of Compromised Domains:

google.com.pk
microsoft.pk
biofreeze.com.pk
blackstone.pk
.pk
itunes.pk
gmails.pk
zynga.com.pk
chrome.com.pk
chrome.pk
visa.com.pk
bx.com.pk
abbvie.com.pk
abbvie.pk
cgma.pk
chacos.com.pk
cimacpa.pk
cisco.pk
ciscosystems.pk
.com.pk
cpacima.pk
cpaintl.pk
cpaldglobal.pk
cpalwglobal.pk
drivealliance.pk
eastman.biz.pk
eastman.net.pk
eastman.org.pk
ebay.pk
monatin.pk
everyblock.pk
youtube.pk
3com.web.pk
hp.web.pk
revlon.pk
streetwear.pk
windows7.pk
windows8.pk
windowsrt.pk
yahoo.pk
yahoomaktoob.pk
zynga.pk
firstdirect.com.pk
flickr.pk
fordgofurther.pk
gbuzz.pk
gmailbuzz.pk
gmail.pk
googlebrowser.com.pk
google.pk
googlebuzz.pk
googlechrome.com.pk
abbviepharmaceuticals.pk
abbviepharmaceuticals.com.pk
hewlettpackard.pk
hexagon.com.pk
hsbcamanah.biz.pk
hotmail.com.pk
hpcloud.com.pk
hp.com.pk
hpscalene.com.pk
hsbc.biz.pk
hsbcadvance.com.pk
hsbc.pk
hsbcpremier.com.pk
hsbcprivatebank.biz.pk
hsbcamanah.com.pk
hsbcdirect.com.pk
hsbcnet.com.pk
hsbcpremier.biz.pk
hsbcpremier.pk
hsbcprivatebank.com.pk
investdirect.biz.pk
investdirect.com.pk
ipod.pk
jaiku.pk
kellyservices.com.pk
maktoob.pk
markmonitor.pk
microsoftsmartglass.com.pk
microsoftsmartglass.pk
xboxsmartglass.com.pk
xboxsmartglass.pk
msn.org.pk
windowsstore.pk
windowsstore.com.pk
opteron.com.pk
parkplaza.pk
paypal.pk
postini.pk
scalene.com.pk
schwab.biz.pk
schwab.com.pk
sonystyle.com.pk
streetwear.com.pk
theworldslocalbank.com.pk
genapp.pk
genapp.com.pk
generationapp.pk
generationapp.com.pk
windows.com.pk
windows7.com.pk
windows8.com.pk
3com.biz.pk
3com.fam.pk
3com.net.pk
3com.org.pk
gchrome.com.pk
aicpacima.pk
Re: How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised by Nobody: 9:01pm On Nov 24, 2012
thats the ugly side of security, you have less control over some things

if goodaddy.com gets hacked today, same may apply
Re: How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised by Slyr0x: 9:15pm On Nov 24, 2012
webdezzi: thats the ugly side of security, you have less control over some things

if goodaddy.com gets hacked today, same may apply

Exactly man. .and the blames won't be on Godaddy but the sites hacked
Re: How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised by Nobody: 9:20pm On Nov 24, 2012
So Google uses Freehostia.com shocked shocked shocked
Re: How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised by Slyr0x: 9:52pm On Nov 24, 2012
Brand_new: So Google uses Freehostia.com shocked shocked shocked

You missed it bro.

The hackers broke into MarkMonitor (Google PK's domain registrar) and changed their DNS settings to point to two alternative nameservers at freehostia.com.

So the defaced page was actually called from the hacker's site hosted on freehostia.com but made it look like twas google's own 'cos of the DNS that was compromised.
Re: How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised by Nobody: 10:05pm On Nov 24, 2012
Slyr0x:

You missed it bro.

The hackers broke into MarkMonitor (Google PK's domain registrar) and changed their DNS settings to point to two alternative nameservers at freehostia.com.

So the defaced page was actually called from the hacker's site hosted on freehostia.com but made it look like twas google's own 'cos of the DNS that was compromised.
And how did you arrive at that?
Re: How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised by spikesC(m): 11:44pm On Nov 24, 2012
DNS hacking....thats the worst someone would do to you. One is browsers cache dns records for a very long time.
Slyrox, can u write an article on how/steps to check the source of attacks when hacked.
Re: How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised by DualCore1: 12:45am On Nov 25, 2012
Or they just paid MarkMonitor some $$$ to get access. Its Pakistan, people (no offense).
Re: How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised by yamakuza: 1:17am On Nov 25, 2012
i wonder how secure NIRA is ...
Re: How Google, PayPal, Microsoft, Ebay Pakistan Were Hacked/compromised by Slyr0x: 7:21pm On Nov 25, 2012
Brand_new:
And how did you arrive at that?

Simple logic

spikes C: Slyrox, can u write an article on how/steps to check the source of attacks when hacked.

I'll try

Dual Core: Or they just paid MarkMonitor some $$$ to get access. Its Pakistan, people (no offense).

Not likely. .as this hack has soiled their image badly. .

yamakuza: i wonder how secure NIRA is ...

Great question. .We need our own "Eboz" to prove that to us wink

(1) (Reply)

I Need An Affordable Website Or Blog For My Startup Cab Service / Naijaloaded Blogger Template Clone For 15k Flat Rate / Traffic Is What You Need If You Want To Make Money As A Blogger..read Now

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 22
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.