AplusWebMaster
Topic Starter
FYI…
- http://www.theregister.co.uk/2008/12/03/checkfree_hijacked/
3 December 2008 - "Online payment service CheckFree lost control of at least two of its domains on Tuesday in an attack that sent customers to servers run by a notorious crime gang believed to be based in Eastern Europe… Security experts say the [removed] IP address has long served as a conduit for online crime. Spamhaus offers this laundry list* of alleged dirty deeds that includes running botnet command channels and various drive-by download sites. According to security researcher Paul Ferguson of anti-virus software provider Trend Micro, the IP address was recently observed handing off booby-trapped PDF files that infected those unfortunate enough to open them… It's unclear how long checkfree .com and mycheckfree .com were redirected to the rogue servers or whether customers have been warned they may have been compromised… It's also unclear how the culprits managed to hijack the domains. While security experts say DNS poisoning wasn't out of the question, the more likely explanation is malicious transfer of the domains through their registrar…"
* http://www.spamhaus.org/sbl/listings.lasso…uatelecom.co.ua

- http://www.theregister.co.uk/2008/12/03/checkfree_hijacked/
3 December 2008 - "Online payment service CheckFree lost control of at least two of its domains on Tuesday in an attack that sent customers to servers run by a notorious crime gang believed to be based in Eastern Europe… Security experts say the [removed] IP address has long served as a conduit for online crime. Spamhaus offers this laundry list* of alleged dirty deeds that includes running botnet command channels and various drive-by download sites. According to security researcher Paul Ferguson of anti-virus software provider Trend Micro, the IP address was recently observed handing off booby-trapped PDF files that infected those unfortunate enough to open them… It's unclear how long checkfree .com and mycheckfree .com were redirected to the rogue servers or whether customers have been warned they may have been compromised… It's also unclear how the culprits managed to hijack the domains. While security experts say DNS poisoning wasn't out of the question, the more likely explanation is malicious transfer of the domains through their registrar…"
* http://www.spamhaus.org/sbl/listings.lasso…uatelecom.co.ua