How Pakistan google hacked:
Yesterday I read an article about Pakistan
google hacked by Turkish hackers..
Here is the article.by RAFAY .when i accessed google.com.pk, I
was surprised to see the defacement page of turkish hackers, Later on i came to
know that other websites such as Microsoft.com.pk were also defaced this
morning. On checking the name servers with nslookup, the DNS servers were
pointing towards another website, It was clear that the hacker compromised the
DNS server and changed the DNS servers to their own, where they had their
defacement page. The above image appeared on major .pk domains,
when users were trying to access them.Some time later the page
started pointing towards google.com instead of google.com.pk, However the name
servers of all .pk domains are still pointing towards freehostia.
How was Google Pakistan Hacked?
So as i mentioned earlier
that it looks to me that the registrar that was responsible for Google's DNS records may have been compromised and the
records were changed, so when users went to google.com.pk they were redirected
to different website which was setup by Turkish hacker to make it look that
google.com.pk has been actually compromised.
By
a quick whois search i came to know that the registrar that is responsible to
PKNIC domains is MarkMonitor,
The is a huge chance that the turkish hackers may have gained access to
MarkMonitor and then would have changed the DNS servers.
Another possibility is that the hackers may have used an attack
called "DNS Cache Poisoning" in order to change the DNS servers. I
will update this page as soon as i have more updates regarding this attack.
Update: Here is the Full List Of Compromised Domains:
google.com.pk
microsoft.pk
biofreeze.com.pk
blackstone.pk
blogspot.pk
itunes.pk
gmails.pk
zynga.com.pk
chrome.com.pk
chrome.pk
visa.com.pk
bx.com.pk
abbvie.com.pk
abbvie.pk
cgma.pk
chacos.com.pk
cimacpa.pk
cisco.pk
ciscosystems.pk
blogspot.com.pk
cpacima.pk
cpaintl.pk
cpaldglobal.pk
cpalwglobal.pk
drivealliance.pk
eastman.biz.pk
eastman.net.pk
eastman.org.pk
ebay.pk
monatin.pk
everyblock.pk
youtube.pk
3com.web.pk
hp.web.pk
revlon.pk
streetwear.pk
Update: Here is the Full List Of Compromised Domains:
google.com.pk
microsoft.pk
biofreeze.com.pk
blackstone.pk
blogspot.pk
itunes.pk
gmails.pk
zynga.com.pk
chrome.com.pk
chrome.pk
visa.com.pk
bx.com.pk
abbvie.com.pk
abbvie.pk
cgma.pk
chacos.com.pk
cimacpa.pk
cisco.pk
ciscosystems.pk
blogspot.com.pk
cpacima.pk
cpaintl.pk
cpaldglobal.pk
cpalwglobal.pk
drivealliance.pk
eastman.biz.pk
eastman.net.pk
eastman.org.pk
ebay.pk
monatin.pk
everyblock.pk
youtube.pk
3com.web.pk
hp.web.pk
revlon.pk
streetwear.pk
Update 2: Due
to the Propogation of Google's name servers to Freehostia's nameservers, It
made attackers to create any non-existing subdomain under compromised websites, For
example rafaybaloch.google.com.pk. All the attacker would need to do is to
register the non-existing subdomain under freehostia and add an index.
Update 3: It seems that Google.com.pk has been finally restored and the nameservers are again pointing to dns.google.com.pk.
Update 3: It seems that Google.com.pk has been finally restored and the nameservers are again pointing to dns.google.com.pk.
REFERENCE:RAFAY ARTICLE