Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

Google Vietnam DNS Hijacked

GOOGLE Vietnam's Primary webpage www.google.com.vn had its DNS hijacked. The responsibility for the hack was claimed by a group called  Lizard Squad. The where abouts of the group were still untraced!

google vietnam dns hijacked 3

( screenshot of the twitter handle of Lizard Squad claiming responsibility)

Over a period of 2 days, it was observed that the DNS infrastructure was turned from usual Google name servers (ns1.google.com, ns2.google.com) to CloudFlare (173.245.59.108, 173.245.58.166) as reported by OpenDNS which was further confirmed by various publicly available tools. The visitors to the regular www[.]google[.]com[.]vn site were instantly redirected to the DigitalOceanhosted server with the following message for a brief period!

google vietnam dns hijacked 1

The DigitalOcean IP which was serving as the endpoint for Google Vietnam was reported to be based out of Netherlands till the time it was taken down.

Technical Details

Whats interesting is that the IP address in question was an IPv6 IP  2a03:b0c0:2:d0::23a:c001. Prefix: 2a03:b0c0:2::/48 Prefix description: DigitalOcean Country code: NL Origin AS: 202018 Origin AS Name: DOAMS3  DigitalOcean Amsterdam RPKI status: No ROA found First seen: 2014-08-13 Last seen: 2015-02-23 Seen by #peers: 170

google vietnam dns hijacked 2

Theories doing the round!

It is still not clear if whether the hacker group wanted to confuse the network analysts & legacy tools or they simply wanted to map a domain to any of the IP address they get their hands on. As hosting the site in Netherlands if combined with the facility of load balancing of CloudFlares infrastructure,it does show that some thought was weighed into managing the significant amount of traffic which was generated by the Google related requests. It is increasingly being speculated that the use of IPv6 for malicious & fraudulent sites will soon become commonplace with VPS providers not offering the option of selecting either IPv4 or IPV6 address for their servers to the customers anymore. It should be commended that CloudFlare did a great rescue operation in taking down this fraudulent site immediately after it was detected.

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.