Domain name hijacking on the rise
On the night of Monday, January 23, the hacktivist group UGNazi hijacked Coach.com, the Internet domain name of luxury goods manufacturer Coach. For several hours, fashionistas who wanted to ogle Coach's new Willis handbag on Coach.com or get a deal on its Penelope shoulder bag at Coachfactory.com were redirected to UGNazi's cryptic website. Imagine the confusion—and frustration—the redirect must have caused in their coiffed little heads—not to mention the wear and tear on their manicured nails as they typed and retyped coach.com and coachfactory.com into their browser windows.
Coach was lucky that its hackers' motives were political rather than financial. UGNazi targeted Coach because the company, whose exclusive products are heavily counterfeited, supports the controversial Stop Online Piracy Act (SOPA). If UGNazi wanted to do more harm to Coach and its customers, it might have taken control of incoming email to Coach.com or redirected customers to a phishing website. UGNazi stated on its website, "We don't steal users' data, only here to make them aware [of the dangers SOPA, PIPA and ACTA pose to the Internet]."
A spokeswoman for Coach told CIO.com that the domain (or DNS) hijacking had a "de minimus impact on our business."
Other companies that have had their domains hijacked haven't been so lucky. In 2008, for example, when hackers hijacked CheckFree.com, they redirected traffic to a website in the Ukraine that downloaded malware on CheckFree customers' computers. (The malware was designed to steal usernames and passwords.) CheckFree customers weren't the only individuals vulnerable to the attack. Also susceptible were customers of small banks that had partnered with CheckFree to provide online bill payment services, since their sites directed to the checkfree.com domain, says Lars Harvey, CEO of Internet Identity, a security company based in Tacoma, Wash.
Domain hijacking is also serious because it puts sensitive corporate information at risk. It compromises all of the normal ways by which confidential information is shared by giving the hacker access to all of the company's incoming email, says Ram Mohan, CTO of domain registrar Afilias.
Mohan says he knows of a company that had its domain hijacked for nearly five months without even knowing it. The company didn't realize its domain had been taken over because the hackers were so subtle: Instead of redirecting visitors to another website, they sent users to the intended domain, but they "listened" to all the traffic, he says. During that time, all of the company's website traffic and emails were routed through a set of servers that the hackers had set up.
"It was a major compromise," says Mohan, who is also a member of ICANN's board of directors and co-authored an article on domain hijacking for the organization in 2005. "That's one of the worst cases because it's disguised and hidden and nobody knows unless you notice where the address is going."
Domain Hijacking: A Rising Threat
Harvey and Mohan say that domain hijacks are growing more prevalent because they're so damaging, because so much commerce is moving online and because they can be so easy to execute.
"Criminals have figured out that the value of hijacking a [domain] name is far greater than many other forms [of attack]," says Mohan. "Hackers have now effectively done the online equivalent of identity theft. They've taken over an organization's online identity and the organization's brand is now solely in the hacker's control."
Related articles:
Send us your comments
Comments
security News and Opinions
embedded_ad
Growth, Agility and New Business Capabilities
Cisco enables the world of many clouds – private, public, and hybrid. We offer a portfolio of cloud services and solutions that uniquely bring together the intelligence of the network, the power of the data center, and the flexibility of applications. The result is a compelling, assured, and consistent user experience with every service delivered from the clouds, anywhere, any time, on any device.
Hong Kong government CIO to form cloud expert group
Datacenters in Hong Kong can never become greener as the local government is lukewarm to the use of renewable energy, said Greenpeace during an interview with Computerworld Hong Kong on Monday...









wedding dress stores
affordable wedding dresses
plus size evening dresses
evening dress cheap
.The attendants and also fathers happen to be outfitted the same, or some may choose any matching baby strollers coat together with possible variations with the tie as well as shirt.
FORMALISED DAYTIME
By using a ceremony well before 4 g.m., any groom determines a gray stroller by using striped skirts, pearl vest, 4-in-hand tie by using a white lay down collar t-shirt.The ushers and also fathers happen to be dressed identical to the groom along with a different boutonniere.
The Current trends make it easy for tuxedos to generally be selected through modern interpretations of the formal dress code.This category's instructions are calm with freedom of preference.
ULTRAFORMAL EVENING
Utilizing this type of look, grooms can buy a dark colored, white, off white or decorated tailcoat plus matching products, or formal white (Mon, 2012-02-06 06:04)
tiffany silver bracelets
tiffany necklace
tiffany jewelry
tiffany key necklaces
.Think concerning this, would acquire an overpriced item in a stranger without some serious other documentation?
By having the step to see the Diamond Grading State all question with the quality would be removed and you will be able to help discern what your probable purchase warrants which keeps you by paying too much and promise you in the quality that you're most likely getting.
After you complete the actual transaction you will need to be for sure to transmit a copy with the certificate in your direction insurance company to being able to add it towards your policy.By carrying out this you can be providing the business with undeniable proof the value any time your diamond is without a doubt stolen and / or lost at a later date (Sat, 2012-02-04 05:27)