[176319] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Craigslist hacked?

daemon@ATHENA.MIT.EDU (Randy Epstein)
Mon Nov 24 19:25:19 2014

X-Original-To: nanog@nanog.org
Date: Mon, 24 Nov 2014 19:18:29 -0500
From: Randy Epstein <nanog@hostleasing.net>
To: George Herbert <george.herbert@gmail.com>
In-Reply-To: <DCC22FDF-E39B-4D85-A700-86B4465C3454@gmail.com>
Cc: "<nanog@nanog.org>" <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org

On 11/24/14, 7:16 PM, "George Herbert" <george.herbert@gmail.com> wrote:

>
>He didn't hack the registry, he hijacked its records.  And this is far
>from the first time a registry account was hacked.  But, yeah, *still*
>not secure enough.

Actually, he didn=E2=80=99t hack its records either.  He exploited a bug in BIND.

>George William Herbert
>Sent from my iPhone
>
>> On Nov 24, 2014, at 2:17 PM, Randy Epstein <nanog@hostleasing.net>
>>wrote:
>>=20
>>> On 11/24/14, 5:08 PM, "Michael T. Voity" <mvoity@uvm.edu> wrote:
>>>=20
>>> I hate to say this, But I think that Network Operators have not see the
>>> last of of this DNS Hijacking. Craigslist might have been a test to see
>>> how far they could get and how long it would take for it to be
>>> discovered.   I hope the FBI and the other Federal agencies out there
>>> are involved with Craigslist to determine how this happened and put in
>>> safeguards in place to help prevent this from happening again.
>>>=20
>>> -Mike
>>>=20
>>> Michael T. Voity
>>> Network Engineer
>>> University of Vermont
>>=20
>> Anyone heard from Eugene Kashpureff lately?
>>=20
>> Hello 1996.  :)
>>=20
>>=20



home help back first fref pref prev next nref lref last post