Article 4CGDY Ongoing DNS hijackings target Gmail, PayPal, Netflix, banks and more [Updated]

Ongoing DNS hijackings target Gmail, PayPal, Netflix, banks and more [Updated]

by
Dan Goodin
from Ars Technica - All content on (#4CGDY)
2640B-800x519.jpg

Enlarge (credit: D-Link)

Stefan Tanase, principal security researcher at Ixia, told Ars that the DNS servers described in this article were taken down and that the attackers have replaced them with new DNS servers. Ixia analyzed the rogue DNS server and found it targets the following domains: GMail.com, PayPal.com, Netflix.com, Uber.com, caix.gov.br, itau.com.br, bb.com.br, bancobrasil.com.br, sandander.com.br, pagseguro.uol.com.br, sandandernet.com.br, cetelem.com.br, and possibly other sites. People trying to reach one of these domains from an infected router will be connected to a server that serves phishing pages over plain HTTP.

Below is how cetelem.com.br appeared in Firefox on a machine configured to use one of the malicious DNS servers.

dns-hijacking-640x264.jpg

(credit: Stefan Tanase)

On Friday afternoon, a Google representative emailed the following statement:

Read 11 remaining paragraphs | Comments

index?i=htqAUttlcuE:ThjNyHd5nf4:V_sGLiPB index?i=htqAUttlcuE:ThjNyHd5nf4:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments