[AfrICANN-discuss] Google blames DNS insecurity for Web site defacements

SM sm at resistor.net
Sun May 17 22:58:06 SAST 2009


At 02:42 17-05-2009, Calvin Browne wrote:
>I agree with this - the release is just way too short on details to
>understand what went wrong here.
>More details are needed.

There are reports that the following web sites were affected:

  www.google.co.ma

  www.aol.ug
  www.bmw.co.ug
  www.cisco.co.ug
  www.cnn.co.ug
  www.defenceuganda.mil.ug
  www.google.ug
  www.hotmail.ug
  www.hotmail.co.ug
  www.microsoft.ug
  www.orange.ug
  www.toshiba.co.ug

The nameservers for google.co.ma were changed on 9th May.  The domain 
resolved to a different IP address.  That brought visitors to a web 
site which wasn't hosted by Google.  The .ug problem occurred between 
11 May and 13 May.  This is not a case of DNS cache 
poisoning.  DNSSEC does not offer any protection against SQL injection attacks.

Regards,
-sm 



More information about the AfrICANN mailing list