SlideShare a Scribd company logo
1 of 10
Download to read offline
akamai.com
[Q1 2015] Website Defacement & Domain Hijacking
Many attacks observed in Q1 2015 revolved around
defacement and hijacking – controlling the content a user sees
when accessing a website
• Attacks can be carried out for notoriety, or to spread a
message, or to phish for user information
• Threats are not new but the tactics remain popular
= emerging threat: website defacement
2 / [The State of the Internet] / Security (Q1 2015)
= mass web defacement
3 / [The State of the Internet] / Security (Q1 2015)
• In Q1 2015, a group of malicious actors claimed to have
hacked hundreds or thousands of websites in a single night
• Many of these websites had the same IP address
• The attackers had exploited automation to attack many sites
hosted on the same servers
= mass web defacement: methods
4 / [The State of the Internet] / Security (Q1 2015)
• Hosting services may host hundreds of websites on a single
server
• Mass defacement attacks exploit improper security settings
to access files outside assigned directories
• A single vulnerable website can allow attackers to view files
elsewhere on the server
• Attackers then search for user account names and
passwords to gain write access to those accounts
• Using a script, these credentials are used to automatically
login to each account and replace the valid files with the
attacker’s desired content
= website defacement: protection and mitigation
If you have been attacked:
• Move to a new hosting provider with better security
To prevent attacks and judge risk:
• Check if other websites on the same IP show hallmarks of
compromise
• If your provider allows, test if your server is vulnerable by
attempting to view the web space of other accounts hosted
by the provider
= domain hijacking
5 / [The State of the Internet] / Security (Q1 2015)
Domain hijacking attacks alter a domain’s DNS records to
redirect web and mail traffic to an IP of the attacker’s choice
• Bypasses even the best server security if registrar level is not
properly controlled
• Requires attackers to gain access to a domain registrar
account
• Name server changes can take 24 to 48 hours to go through,
allowing the malicious changes to remain for a long period
• Targeted spear-phishing of personnel likely to have registrar
access
• Email credentials often obtained from domain administrator
• Email can be used to request a password reset, getting full credentials
• Registrar account used to make changes to name server
records, redirecting web traffic to attacker’s IP
• Entire zone file, including mail exchange, may be changed
• Intercepted mail can be used to obtain credentials for other accounts and to
intercept password reset attempts
• Attackers could maintain control over all administrative accounts for a
domain name
= domain hijacking: methods
6 / [The State of the Internet] / Security (Q1 2015)
= domain hijacking: protection and mitigation
7 / [The State of the Internet] / Security (Q1 2015)
Protection against domain hijacking attacks takes two forms:
• Prevent access to domain registrar credentials
• Use two-factor authentication for email services to protect against phishing
• Do not reuse the password on a site’s registrar account
• Use registrar locks to prevent unauthorized changes
• Confirms changes with previously agreed-upon contact
• Response may be slow, so keep in mind if you may need rush changes
Download the Q1 2015 State of the Internet Security Report
• The Q1 2015 report covers:
⁄ Analysis of DDoS and web application attack trends
⁄ Bandwidth (Gbps) and volume (Mpps) statistics
⁄ Year-over-year and quarter-by-quarter analysis
⁄ Attack frequency, size, types and sources
⁄ Security implications of the transition to IPv6
⁄ Mitigating the risk of website defacement and domain hijacking
⁄ DDoS techniques that maximize bandwidth, including booter/stresser
sites
⁄ Analysis of SQL injection attacks as a persistent and emerging threat
= Q1 2015 State of the Internet –Security Report
9 / [The State of the Internet] / Security (Q1 2015)
• StateoftheInternet.com, brought to you by Akamai,
serves as the home for content and information intended to
provide an informed view into online connectivity and
cybersecurity trends as well as related metrics, including
Internet connection speeds, broadband adoption, mobile
usage, outages, and cyber-attacks and threats.
• Visitors to www.stateoftheinternet.com can find current and
archived versions of Akamai’s State of the Internet
(Connectivity and Security) reports, the company’s data
visualizations, and other resources designed to put context
around the ever-changing Internet landscape.
= about stateoftheinternet.com
10 / [The State of the Internet] / Security (Q1 2015)

More Related Content

Viewers also liked

Viewers also liked (6)

13.1
13.113.1
13.1
 
Bleach
BleachBleach
Bleach
 
8.1
8.18.1
8.1
 
Jowel Bodden Professional Persona Project
Jowel Bodden Professional Persona ProjectJowel Bodden Professional Persona Project
Jowel Bodden Professional Persona Project
 
8.2
8.28.2
8.2
 
JeffRosenplotResume
JeffRosenplotResumeJeffRosenplotResume
JeffRosenplotResume
 

Recently uploaded

2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis UsageNeil Kimberley
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadAyesha Khan
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...lizamodels9
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCRashishs7044
 
Organizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessOrganizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessSeta Wicaksana
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menzaictsugar
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdfKhaled Al Awadi
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCRashishs7044
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Future Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted VersionFuture Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted VersionMintel Group
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfRbc Rbcua
 
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607dollysharma2066
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...lizamodels9
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesKeppelCorporation
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Riya Pathan
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailAriel592675
 

Recently uploaded (20)

2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
 
Organizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessOrganizational Structure Running A Successful Business
Organizational Structure Running A Successful Business
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Future Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted VersionFuture Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted Version
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdf
 
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation Slides
 
Corporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information TechnologyCorporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information Technology
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737
 
Japan IT Week 2024 Brochure by 47Billion (English)
Japan IT Week 2024 Brochure by 47Billion (English)Japan IT Week 2024 Brochure by 47Billion (English)
Japan IT Week 2024 Brochure by 47Billion (English)
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detail
 

Website Defacement & Domain Hijacking on the Rise: Cloud Security Threat – State of the Internet

  • 1. akamai.com [Q1 2015] Website Defacement & Domain Hijacking
  • 2. Many attacks observed in Q1 2015 revolved around defacement and hijacking – controlling the content a user sees when accessing a website • Attacks can be carried out for notoriety, or to spread a message, or to phish for user information • Threats are not new but the tactics remain popular = emerging threat: website defacement 2 / [The State of the Internet] / Security (Q1 2015)
  • 3. = mass web defacement 3 / [The State of the Internet] / Security (Q1 2015) • In Q1 2015, a group of malicious actors claimed to have hacked hundreds or thousands of websites in a single night • Many of these websites had the same IP address • The attackers had exploited automation to attack many sites hosted on the same servers
  • 4. = mass web defacement: methods 4 / [The State of the Internet] / Security (Q1 2015) • Hosting services may host hundreds of websites on a single server • Mass defacement attacks exploit improper security settings to access files outside assigned directories • A single vulnerable website can allow attackers to view files elsewhere on the server • Attackers then search for user account names and passwords to gain write access to those accounts • Using a script, these credentials are used to automatically login to each account and replace the valid files with the attacker’s desired content
  • 5. = website defacement: protection and mitigation If you have been attacked: • Move to a new hosting provider with better security To prevent attacks and judge risk: • Check if other websites on the same IP show hallmarks of compromise • If your provider allows, test if your server is vulnerable by attempting to view the web space of other accounts hosted by the provider
  • 6. = domain hijacking 5 / [The State of the Internet] / Security (Q1 2015) Domain hijacking attacks alter a domain’s DNS records to redirect web and mail traffic to an IP of the attacker’s choice • Bypasses even the best server security if registrar level is not properly controlled • Requires attackers to gain access to a domain registrar account • Name server changes can take 24 to 48 hours to go through, allowing the malicious changes to remain for a long period
  • 7. • Targeted spear-phishing of personnel likely to have registrar access • Email credentials often obtained from domain administrator • Email can be used to request a password reset, getting full credentials • Registrar account used to make changes to name server records, redirecting web traffic to attacker’s IP • Entire zone file, including mail exchange, may be changed • Intercepted mail can be used to obtain credentials for other accounts and to intercept password reset attempts • Attackers could maintain control over all administrative accounts for a domain name = domain hijacking: methods 6 / [The State of the Internet] / Security (Q1 2015)
  • 8. = domain hijacking: protection and mitigation 7 / [The State of the Internet] / Security (Q1 2015) Protection against domain hijacking attacks takes two forms: • Prevent access to domain registrar credentials • Use two-factor authentication for email services to protect against phishing • Do not reuse the password on a site’s registrar account • Use registrar locks to prevent unauthorized changes • Confirms changes with previously agreed-upon contact • Response may be slow, so keep in mind if you may need rush changes
  • 9. Download the Q1 2015 State of the Internet Security Report • The Q1 2015 report covers: ⁄ Analysis of DDoS and web application attack trends ⁄ Bandwidth (Gbps) and volume (Mpps) statistics ⁄ Year-over-year and quarter-by-quarter analysis ⁄ Attack frequency, size, types and sources ⁄ Security implications of the transition to IPv6 ⁄ Mitigating the risk of website defacement and domain hijacking ⁄ DDoS techniques that maximize bandwidth, including booter/stresser sites ⁄ Analysis of SQL injection attacks as a persistent and emerging threat = Q1 2015 State of the Internet –Security Report 9 / [The State of the Internet] / Security (Q1 2015)
  • 10. • StateoftheInternet.com, brought to you by Akamai, serves as the home for content and information intended to provide an informed view into online connectivity and cybersecurity trends as well as related metrics, including Internet connection speeds, broadband adoption, mobile usage, outages, and cyber-attacks and threats. • Visitors to www.stateoftheinternet.com can find current and archived versions of Akamai’s State of the Internet (Connectivity and Security) reports, the company’s data visualizations, and other resources designed to put context around the ever-changing Internet landscape. = about stateoftheinternet.com 10 / [The State of the Internet] / Security (Q1 2015)