[afnog] Google blames DNS insecurity for Web site defacements

Stephane Bortzmeyer bortzmeyer at nic.fr
Mon May 18 12:31:30 UTC 2009


On Mon, May 18, 2009 at 02:15:34PM +0200,
 Calvin Browne <calvin at orange-tree.alt.za> wrote 
 a message of 29 lines which said:

> > MA (Morocco)

> are these registries running the same software?

For those I know, I can answer NO. And, in the case of Morocco,
according to information published in moroccan sites
<http://www.marocinfo.net/to/index.php/Sciences-et-Technologie/Google-Maroc-deface.cfm>,
the attack was against a registrAR.

> having a co-ordinated attack against different bespoke software would be
> way interesting.

Many registries and registrars use locally-developed PHP or VB.net Web
interfaces and it is not new that these interfaces are often very
vulnerable to SQL injections.



More information about the afnog mailing list