Ransomware Found On Sites Hosted By Go Daddy
Users who have their websites hosted by Go Daddy are being infected with ransomware following a recent cyberattack on the company’s DNS records, online security experts are reporting.
According to Fraser Howard, a Principal Virus Researcher with SophosLabs, the hackers behind these attacks are “exploiting DNS by hacking the DNS records of sites, adding one or more additional subdomains with corresponding DNS entries (A records) referencing malicious IP addresses. The legitimate hostname resolves to the legitimate IP address, but the added sub-domains resolve to rogue servers.”
By doing so, the criminals are able to set-up URLs that seem legitimate, potentially sneaking through security filtering systems and duping Internet surfers into believing they are harmless, he explained in a Friday blog entry. In some instances, multiple subdomains were added to each user’s account, with each of them redirecting viewers to at least one malicious IP address.
Howard reports the exploit kit being used to create the false subdomains is called “Cook EK” and is Russian in origin, based on the “login page for the admin panel.” The method used in the attack is “very similar to Blackhole exploit kit,” he added, and anyone unfortunate enough to arrive at the malicious destination page “are hit with various malicious files, exploiting several vulnerabilities, in order to infect them with ransomware… Once running, the ransomware displays the familiar payment page, with contents that vary based on the country of the victim.”
So how were the hackers able to gain access to the Go Daddy domain name system records? While there was no definitive answer to that as of Friday, Sophos believes that easily cracked or stolen passwords were one possible cause. Howard requested one affected webmaster review his log-in history, but he was unable to do so, and attempts to contact the domain hosting firm offered no insight into the matter either, as they refused to release information related to account log-ins or other activity.
“Enabling users to view historical login activity is a very simple way of helping to spot malicious activity early. Let’s hope Go Daddy change their stance on this,” Howard said. “Given the prevalence of attacks against web sites for the purpose of malware distribution it is high time that associated services (Registrars, hosting providers etc) pay adequate consideration to security.”
He said he has contacted some of those webmasters that have been victims of the attack, as well as Go Daddy themselves, and suggests anyone wanting to see if they were attacked should go to their Go Daddy support page to review their DNS configuration. Howard also urged strengthening security measures to prevent the use of weak passwords, and to enable (and perhaps require) the use of two-factor authentication.
This may not have been the first hacking attempt against Go Daddy this fall. In September, a hacker from the shadowy group Anonymous claimed to have taken down the domain registry and web hosting company. However, one day after the attack, Go Daddy denied they had been targeted by cybercriminals.
“The service outage was not caused by external influences,” CEO Scott Wagner said in a statement. “It was not a ‘hack’ and it was not a denial of service attack (DDoS). We have determined the service outage was due to a series of internal network events that corrupted router data tables. Once the issues were identified, we took corrective actions to restore services for our customers and GoDaddy.com.”
redOrbit.com
offers Science, Space, Technology, Health news, videos, images and
reference information. For the latest science news, space news,
technology news, health news visit redOrbit.com frequently. Learn
something new every day.\”
2012-11-25 16:54:25
Source: http://www.redorbit.com/news/technology/1112736106/hacker-go-daddy-ransomware-sophos-112512/
Source:
Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.
"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.
Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world. Anyone can join. Anyone can contribute. Anyone can become informed about their world. "United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.
LION'S MANE PRODUCT
Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules
Mushrooms are having a moment. One fabulous fungus in particular, lion’s mane, may help improve memory, depression and anxiety symptoms. They are also an excellent source of nutrients that show promise as a therapy for dementia, and other neurodegenerative diseases. If you’re living with anxiety or depression, you may be curious about all the therapy options out there — including the natural ones.Our Lion’s Mane WHOLE MIND Nootropic Blend has been formulated to utilize the potency of Lion’s mane but also include the benefits of four other Highly Beneficial Mushrooms. Synergistically, they work together to Build your health through improving cognitive function and immunity regardless of your age. Our Nootropic not only improves your Cognitive Function and Activates your Immune System, but it benefits growth of Essential Gut Flora, further enhancing your Vitality.
Our Formula includes: Lion’s Mane Mushrooms which Increase Brain Power through nerve growth, lessen anxiety, reduce depression, and improve concentration. Its an excellent adaptogen, promotes sleep and improves immunity. Shiitake Mushrooms which Fight cancer cells and infectious disease, boost the immune system, promotes brain function, and serves as a source of B vitamins. Maitake Mushrooms which regulate blood sugar levels of diabetics, reduce hypertension and boosts the immune system. Reishi Mushrooms which Fight inflammation, liver disease, fatigue, tumor growth and cancer. They Improve skin disorders and soothes digestive problems, stomach ulcers and leaky gut syndrome. Chaga Mushrooms which have anti-aging effects, boost immune function, improve stamina and athletic performance, even act as a natural aphrodisiac, fighting diabetes and improving liver function. Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules Today. Be 100% Satisfied or Receive a Full Money Back Guarantee. Order Yours Today by Following This Link.
