[154126] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Whois data compromised?

daemon@ATHENA.MIT.EDU (James Downs)
Tue Jun 26 18:08:29 2012

From: James Downs <egon@egon.cc>
In-Reply-To: <CADfGf67aMjhr+bSDo4kLpfzcyZJZw5bx0uscW_9sgrQ7rz6nsQ@mail.gmail.com>
Date: Tue, 26 Jun 2012 15:07:46 -0700
To: Nanog <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


On Jun 26, 2012, at 2:44 PM, Eric Rosenberry wrote:

> Not sure where this data got injected into the system (or who knows,
> perhaps it's a DNS injection attack or something), but this certainly =
is

It's an old trick, been around forever. You just register some random A =
record with a registrar.
Same thing happens for google.com, microsoft.com, probably every big =
company.

Cheers,
-j=


home help back first fref pref prev next nref lref last post