Google and several others hacked in Pakistan!!!

Discussion in 'Google' started by saboor, Nov 24, 2012.

  1. #1
    Hi,

    Google-Pakistan (1).jpg
    Today, when i accessed google.com.pk, I was surprised to see the defacement page of turkish hackers, Later on i came to know that other websites such as Microsoft.com.pk were also defaced this morning. On checking the name servers with nslookup, the DNS servers were pointing towards another website, It was clear that the hacker compromised the DNS server and changed the DNS servers to their own, where they had their defacement page. The above image appeared on major .pk domains, when users were trying to access them.


    Some time later the page started pointing towards google.com instead of google.com.pk, However the name servers of all .pk domains are still pointing towards freehostia.


    By a quick whois search i came to know that the registrar that is responsible to PKNIC domains is MarkMonitor, The is a huge chance that the turkish hackers may have gained access to MarkMonitor and then would have changed the DNS servers. Another possibility is that the hackers may have used an attack called "DNS Cache Poisoning" in order to change the DNS servers. I will update this page as soon as i have more updates regarding this attack.


    Update: Here is the Full List Of Compromised Domains:

    google.com.pk
    microsoft.pk
    biofreeze.com.pk
    blackstone.pk
    blogspot.pk
    itunes.pk
    gmails.pk
    zynga.com.pk
    chrome.com.pk
    chrome.pk
    visa.com.pk
    bx.com.pk
    abbvie.com.pk
    abbvie.pk
    cgma.pk
    chacos.com.pk
    [U]cimacpa.pk[/U]
    [I][U]cisco.pk[/U]
    [I][U]ciscosystems.pk[/U]
    [I][U]blogspot.com.pk[/U]
    [I][U]cpacima.pk[/U]
    [I][U]cpaintl.pk[/U]
    [I][U]cpaldglobal.pk[/U]
    [I][U]cpalwglobal.pk[/U]
    [I][U]drivealliance.pk[/U]
    [I][U]eastman.biz.pk[/U]
    [I][U]eastman.net.pk[/U]
    [I][U]eastman.org.pk[/U]
    [I][U]ebay.pk[/U]
    [I][U]monatin.pk[/U]
    [I][U]everyblock.pk[/U]
    [I][U]youtube.pk[/U]
    [I][U]3com.web.pk[/U]
    [I][U]hp.web.pk[/U]
    [I][U]revlon.pk[/U]
    [I][U]streetwear.pk[/U]
    [I][U]windows7.pk[/U]
    [I][U]windows8.pk[/U]
    [I][U]windowsrt.pk[/U]
    [I][U]yahoo.pk[/U]
    [I][U]yahoomaktoob.pk[/U]
    [I][U]zynga.pk[/U]
    [I][U]firstdirect.com.pk[/U]
    [I][U]flickr.pk[/U]
    [I][U]fordgofurther.pk[/U]
    [I][U]gbuzz.pk[/U]
    [I][U]gmailbuzz.pk[/U]
    [I][U]gmail.pk[/U]
    [I][U]googlebrowser.com.pk[/U]
    [I][U]google.pk[/U]
    [I][U]googlebuzz.pk[/U]
    [I][U]googlechrome.com.pk[/U]
    [I][U]abbviepharmaceuticals.pk[/U]
    [I][U]abbviepharmaceuticals.com.pk[/U]
    [I][U]hewlettpackard.pk[/U]
    [I][U]hexagon.com.pk[/U]
    [I][U]hsbcamanah.biz.pk[/U]
    [I][U]hotmail.com.pk[/U]
    [I][U]hpcloud.com.pk[/U]
    [I][U]hp.com.pk[/U]
    [I][U]hpscalene.com.pk[/U]
    [I][U]hsbc.biz.pk[/U]
    [I][U]hsbcadvance.com.pk[/U]
    [I][U]hsbc.pk[/U]
    [I][U]hsbcpremier.com.pk[/U]
    [I][U]hsbcprivatebank.biz.pk[/U]
    [I][U]hsbcamanah.com.pk[/U]
    [I][U]hsbcdirect.com.pk[/U]
    [I][U]hsbcnet.com.pk[/U]
    [I][U]hsbcpremier.biz.pk[/U]
    [I][U]hsbcpremier.pk[/U]
    [I][U]hsbcprivatebank.com.pk[/U]
    [I][U]investdirect.biz.pk[/U]
    [I][U]investdirect.com.pk[/U]
    [I][U]ipod.pk[/U]
    [I][U]jaiku.pk[/U]
    [I][U]kellyservices.com.pk[/U]
    [I][U]maktoob.pk[/U]
    [I][U]markmonitor.pk[/U]
    [I][U]microsoftsmartglass.com.pk[/U]
    [I][U]microsoftsmartglass.pk[/U]
    [I][U]xboxsmartglass.com.pk[/U]
    [I][U]xboxsmartglass.pk[/U]
    [I][U]msn.org.pk[/U]
    [I][U]windowsstore.pk[/U]
    [I][U]windowsstore.com.pk[/U]
    [I][U]opteron.com.pk[/U]
    [I][U]parkplaza.pk[/U]
    [I][U]paypal.pk[/U]
    [I][U]postini.pk[/U]
    [I][U]scalene.com.pk[/U]
    [I][U]schwab.biz.pk[/U]
    [I][U]schwab.com.pk[/U]
    [I][U]sonystyle.com.pk[/U]
    [I][U]streetwear.com.pk[/U]
    [I][U]theworldslocalbank.com.pk[/U]
    [I][U]genapp.pk[/U]
    [I][U]genapp.com.pk[/U]
    [I][U]generationapp.pk[/U]
    [I][U]generationapp.com.pk[/U]
    [I][U]windows.com.pk[/U]
    [I][U]windows7.com.pk[/U]
    [I][U]windows8.com.pk[/U]
    [I][U]3com.biz.pk[/U]
    [I][U]3com.fam.pk[/U]
    [I][U]3com.net.pk[/U]
    [I][U]3com.org.pk[/U]
    [I][U]gchrome.com.pk[/U]
    [I][U]aicpacima.pk[/U][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I][/I]

     
    saboor, Nov 24, 2012 IP
  2. linksolution

    linksolution Member

    Messages:
    361
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    35
    #2
    It is really very serious matter to think of ad a popular search engine is being hacked.
     
    linksolution, Nov 24, 2012 IP
  3. Karen May Jones

    Karen May Jones Prominent Member

    Messages:
    3,469
    Likes Received:
    290
    Best Answers:
    1
    Trophy Points:
    380
    #3
    That's crazy! What is cache poisoning? How could anyone get into Google and Microsoft at the same time? Don't they have their own servers?
     
    Karen May Jones, Nov 24, 2012 IP
  4. FPForum

    FPForum Notable Member

    Messages:
    4,172
    Likes Received:
    102
    Best Answers:
    0
    Trophy Points:
    225
    Digital Goods:
    2
    #4
    As the original owner stated..All of the .pk domains may have been registered through MarkMonitor..If the hackers gained access into MarkMonitor then changing the nameservers for all these domains would be fairly easy.
     
    FPForum, Nov 24, 2012 IP
  5. Karen May Jones

    Karen May Jones Prominent Member

    Messages:
    3,469
    Likes Received:
    290
    Best Answers:
    1
    Trophy Points:
    380
    #5
    Okay, I read that, sort of, as I didn't really know what this meant...
     
    Karen May Jones, Nov 24, 2012 IP
  6. haier

    haier Active Member

    Messages:
    342
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    78
    #6
    It means they didnt hack the websites but just redirected their domains.Sounds strange
     
    haier, Nov 24, 2012 IP
  7. Oly

    Oly Greenhorn

    Messages:
    48
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    6
    #7
    Interesting read.
     
    Oly, Nov 25, 2012 IP
  8. zoritey87

    zoritey87 Greenhorn

    Messages:
    83
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    18
    #8
    hm... I can access to that page! I take the same index I get on any other Google page!
     
    zoritey87, Nov 25, 2012 IP
  9. The Webmaster

    The Webmaster IdeasOfOne

    Messages:
    9,516
    Likes Received:
    718
    Best Answers:
    0
    Trophy Points:
    360
    #9
    So this is what happened, in the nutshell :

    google_hacked.jpg
     
    The Webmaster, Nov 26, 2012 IP
  10. tentwenty

    tentwenty Well-Known Member

    Messages:
    1,030
    Likes Received:
    35
    Best Answers:
    0
    Trophy Points:
    110
    #10
    HAHA Great attachment!

    Yeah unlucky:)
     
    tentwenty, Nov 26, 2012 IP