『尊米网』域名信息交流平台
设为首页 收藏本站
网站地图 RSS-订阅
反馈留言 高级搜索
尊米首页 | 域名新闻 | 域名知识 | 域名人物 | 域名标识 | 相关下载 | 信息专题 | 域名问答 | 域名经纪 | WHOIS查询 | Winindomain.com
 
╣当前位置╠
尊米首页 > 域名新闻 > 英文媒体报道 > 文章内容
Hackers Abuse Domain-Name Trust
来源:Internet News 作者:Andy Patrizio 发布时间:2007-11-21 09:33:53
欢迎您在线投稿(需先登陆),也可将您的新闻线索/稿件电子邮件至:editor@zunmi.com

Using variations on trusted, popular domains has long been a common tactic for scammers, spammers and porn sites. But cyber criminals have devised a new twist on the misspelled domain-name trick by hijacking IP addresses. And they tried it on Yahoo.

To fix the old problem, server-based security products would trace the IP address of the server behind the domain. Once the IP address resolved the misspelled domain name, the products would then compare the IP address against a database of known fraudulent sites or questionable locations. So if a site were masquerading as eBay but the filters found it was really a server in China that had only been established one week earlier, it would block access.

In the case of Yahoo, security firm Finjan said hackers exploited an unused IP address within Yahoo's hierarchy and used that as the domain address behind a forged Google Analytics domain name. This fooled the Web-filtering products into believing a person was going to a highly trusted Yahoo domain. The victims never knew they were on a malicious Web site, and neither did the security mechanisms on the network.

"They managed to resolve the domain name to an IP address owned by Yahoo. How they added an address into a DNS server to appear to be an IP address owned by Yahoo is unknown," Yuval Ben-Itzhak, CTO of Finjan, told InternetNews.com. He added that Yahoo, while responsive and quick to shut down the compromised address, did not disclose exactly what equipment was behind the compromised IP address.

Ben-Itzhak thinks something in the server was broken that enabled the bad guys to push that content down to users without Yahoo knowing. He said that's a flaw in social networks.

"In 2007, something very clear has come out: these Web 2.0 sites are great fun but also a great platform for hackers to host malicious code as well," said Ben-Itzhak. "You can upload anything you like, so you can upload malicious content, as well. On MySpace we found hundreds of pages with malicious code this year."

Ben-Itzhak said server-based security is still the primary mode of defense but also recommended browser plug-ins, such as Finjan's SecureBrowsing or Exploit Prevention Labs' LinkScanner, both of which scan the actual content coming over the wire from a site and alert the user if it's suspicious.


上一篇:DNS hacked again   下一篇:The 20 Most Influential People In The Domain Industry - 2007 Edition
【免责声明】
以上文章由本站会员发布或网络转载,除色情、暴力及反政府等法律明确禁止内容以外,尊米网对其不承担法律责任。
[收藏] [推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]
发表评论
用户名: 新注册) 密码: 匿名评论 (未注册可直接匿名评论)
评论内容:(250字以内)
 §最新评论
进入主题评论页  
本月热点
相关新闻
·Internet overhaul wins approva
·Phoenix Clothing Brand BLaZa F
·.Asia Landrush Closes with Hal
·Internet agency to battle doma
·Alberta premier threatens to s
·Internet Polling Fails in N.H.
·Domain Front Running by Regist
·Network Solutions snarfing you
·How 2...Buy a domain name
·Registrar denies‘front-runnin
·Pompano domain name firm sold
·Moniker Acquired By Oversee.ne
赞助商广告
尊米首页 - 关于我们 - 本站动态 - 联系我们 - 媒体关注 - 网站地图 - 友情链接 - 原创投稿 - 帮助中心