DNS URL Redirect Attack

Nifty

Printer VIP
Administrator
Joined
Nov 3, 2004
Messages
3,065
Reaction score
1,429
Points
337
Location
Bay Area CA
Printer Model
CR-10, i560 ,MFC-7440N
Over the past day or two the site has been attacked by spammers. They were able to redirect our URL to various spam sites.

I've been working tirelessly with the tech team to find the cause and then a solution to the problem. The internet routing of the site's domain name (the DNS) and the URL routing got hijacked.We've since fixed the problem on our end, but it sometimes takes hours and even days for "propagation" of the fix to all the servers around the world to get the info that the change has been made.

It sucks that there are so many people around the world doing all they can to maliciously attack sites and servers. We've been lucky over the years that we've been able to keep most spammers and hackers at bay (even the big companies with all their money and experts have a hard time fighting the scourge), but we're working hard to ensure it doesn't happen again!
 

ThrillaMozilla

Printer Master
Joined
Jan 18, 2011
Messages
1,189
Reaction score
341
Points
253
Possibly something to do with this?
https://nakedsecurity.sophos.com/2016/02/22/worlds-biggest-linux-distro-infected-with-malware/
http://blog.linuxmint.com/?p=3001
Maybe coincidence, but something was going around.

http://arstechnica.com/security/201...cks-silently-delivers-ransomware-to-visitors/

It may not have anything to do with either, actually. As Nifty said, this appears to be the fault of DNS. Still, the attack looks rather similar. I tried to visit this site, and got redirected to some other site that presented what looked like search results. I don't understand this stuff, but NO WAY would I click on any of those links.
 
Last edited:

The Hat

Printer VIP
Platinum Printer Member
Joined
Jan 18, 2010
Messages
15,790
Reaction score
8,821
Points
453
Location
Residing in Wicklow Ireland
Printer Model
Canon/3D, CR-10, CR-10S, KP-3
All I know is, that this bug is a new kid on the block and that’s why it’s been more successful that others, most of the Anti-virus company’s had no idea it was there till yesterday, we check with 58 different anti-malware companies and none of them had no record of it, they do now.

It managed got past my Symantec into a temp folder without detection but was then blocked when it tried to launch, it got quarantined..;)
 

turbguy

Printer Master
Platinum Printer Member
Joined
Sep 10, 2007
Messages
1,561
Reaction score
1,437
Points
293
Location
Laramie, Wyoming
Printer Model
Canon i960, Canon i9900
I am still getting redirected at home using windows 7, Google chome, even after clearing the cache. But, if I use an android tablet from home (same DNS server?), no problems getting to the site.

Go figure...
 

Nifty

Printer VIP
Administrator
Joined
Nov 3, 2004
Messages
3,065
Reaction score
1,429
Points
337
Location
Bay Area CA
Printer Model
CR-10, i560 ,MFC-7440N
Ya, DNS propagation is a weird thing. Throughout the whole experience I was having very inconsistent results using my phone (cell network) desktop, etc. Some people didn't have any problems and others are still having problems even today.

It's so frustrating that there are so many people out there trying to do harm. We've updated all the software, beefed up security, and increased our daily backup procedures. Nothing guarantees 100% safety from this junk, but we're doing all we can!

Thanks to all you guys for your patience and understanding!
 

ThrillaMozilla

Printer Master
Joined
Jan 18, 2011
Messages
1,189
Reaction score
341
Points
253
For what it's worth, I changed my DNS server right away to Google (8.8.8.8), and I've had no trouble since. I have no idea whether that's what fixed it, however.
 

websnail

Printer VIP
Platinum Printer Member
Joined
Oct 27, 2005
Messages
3,665
Reaction score
1,349
Points
337
Location
South Yorks, UK
Printer Model
Epson, Canon, HP... A "few"
The joys of DNS propogation are just endless... As a rule you're looking at 24 hours for any changes to propogate but some DNS servers have TTL (Time to Live) settings that wait closer to a week which just makes this sort of thing all the more "interesting".

Good catch though Rob...
 
Top