ICANN downplays site hacks

By
Follow google news

The Internet Corporation for Assigned Names and Numbers (ICANN) is speaking out about a recent round of attacks perpetrated against its sites.

ICANN downplays site hacks
Hackers compromised a pair of mirror sites for the company and redirected users to a page taunting ICANN and claiming 'we control the domains.' The attacks were attributed to Turkish hacker group NetDevilz.

The attack was particularly embarrassing for ICANN as it came just days after the group approved a plan to open new domains for registration by the public.

According to ICANN, the hackers pulled off the attack by infiltrating systems run by ICANN's registrar. The hackers compromised the DNS servers and redirected requests for two of the group's domains.

The company noted that the attacks were only directed towards mirror sites, and that the main .org site was never compromised or altered in any way.

"It would appear the attack was sophisticated, combining both social and technological techniques, but was also limited and focused,” ICANN said in a statement.

"The redirect was noticed and corrected within 20 minutes; however it may have taken anywhere up to 48 hours for the redirect to be entirely removed from the Internet."

Later, a separate group of attackers used what ICANN described as an " automated attack" to exploit a vulnerability in WordPress and compromise the site's blog. The company does not believe that the two incidents were related.

ICANN said that it will launch an internal investigation on both attacks in order to determine possible safeguards against future attacks.


Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?