• United States



by IDG News Service (San Francisco Bureau)

Domain Name Record Altered to Hack

May 30, 20082 mins
CybercrimeNetwork SecurityPhishing

Hackers gained access to the domain-name registration record for, knocking the company's Web portal offline.

Hackers knocked offline late Wednesday night, preventing customers from getting to their Comcast Web mail and account records on the company’s Internet portal.

The criminals somehow got their hands on passwords used to alter domain-name registration information with Comcast’s registrar, Network Solutions, said Susan Wade, a Network Solutions spokeswoman. With access to the record, the hackers were able to switch the DNS (Domain Name System) servers associated with and redirect Internet traffic to their own server. They also added offensive comments to the record.

Visitors who went to Comcast’s portal between approximately 11 p.m. Eastern time Wednesday and 12:30 a.m. Thursday were greeted with either a “Site under construction” message or a cryptic note reading: “KRYOGENIKS EBK and DEFIANT RoXed COMCAST sHouTz To VIRUS Warlock elul21 coll1er seven,” an apparent reference to the hackers who had compromised the site and to their friends.

This attack is connected to recent defacement of the profiles of Justin Timberlake, Hilary Duff and Tila Tequila, said security researcher Dancho Danchev.

No one knows how the hackers gained access to Comcast’s Network Solutions account. In the past, registrars have been tricked into handing over control of Internet domains. But Danchev said that lately, criminals have also been using phishing attacks to try to take control of Web domains.

Throughout Thursday, the Web page continued to experience problems. For many visitors, the page was missing graphics and had the look and feel of an early 1990s Web site.

“We believe that our registration information at the vendor that registers the domain address was altered, which redirected the site, and is the root cause of today’s continued issues as well,” Comcast said Tuesday in a statement. “We have alerted law enforcement authorities and are working in conjunction with them.”

Neither Comcast nor Network Solutions can say how the hackers got their hands on the Comcast password, but this type of problem is not unheard of, Wade said. “It’s not frequent, but it does happen,” she said.

There are steps that companies can take to secure their domain name registration accounts, Wade said. “We tell folks, especially big companies, to consolidate domains so you have someone in charge of all the domains,” she said. “We encourage people to update their passwords on a regular basis and make sure the passwords are complicated.”