NEWS
Hushmail.com defaced by means of DNS redirection UPDATED
Siegfried, SyS64738 Zone-H Admins
04/24/2005
The web site hushmail.com of Hush Communications, providing secure email services, was defaced over the week-end, visitors being redirected to a different server after an attacker got access to Hushmail DNS maintenance panel.
It was first noticed very early this morning, when the domain
www.hushmail.com began to redirect users to a page containing the following message: "The Secret Service is watching. -Agent Leth and Clown Jeet 3k Inc". The DNS were changed to DNS1.EVONEXUS.NET DNS2.EVONEXUS.NET while hushmail are using their own servers (NS*.HUSHMAIL.COM) and the information on the whois was hijacked:
Administrative Contact, Technical Contact:
Smith, Brian
[email protected]
Hush Communications
Maybe the attacker got somehow this contact's password, whose email address was
[email protected] (according to the data on the whois of hush.com) and modified the data of the domain on the Network Solutions web site, their registry.
On sunday 4am GMT the page was removed, probably by burst.net, which was hosting it, the emails sent to the hushmail.com users were bounced back to the sender at the time of writing.
The attacker didn't use the web site for a malicious purpose, but it is indeed a bad news for Hush Communications, whose credibility was seriously damaged.
A mirror of the "defacement" is available here:
http://www.zone-h.org/defacements/mirror/id=2309823/
UPDATE
Currently at 08:35 AM GMT+1 the site Hushmail.com is reachable in Europe only by its IP address 65.39.178.11 while the query through DNS doesn't resolve.
Click here to view the current status of Hushmail Whois
http://www.zone-h.org/files/77/hushwhois.htm
UPDATE 25/04 3am GMT
Hushmail released a news confirming the attack, explaining that the attacker broke the Network Solutions security, no more details are available. If it's really the truth, then we are waiting for a comment from Network Solutions, because any other customer could have been attacked.
https://www.hushmail.com/login-status?
Original article:
http://www.zone-h.org/en/news/read/id=4467/
Click here to post Your comments on this article...
This work is licensed under a Creative Commons License.