Next Question
It's the Peace Crew, formerly known as Terrorist Crew, a group of politically motivated hackers supporting the Palestinian cause, who recently defaced the Microsoft New Zealand sites. Earlier this year, they attacked a number of Nato and US military websites.
The principal Peace Crew character is a hacker known as Agd_Scorp, allegedly of Turkish origin. Others prominent members are rx5 and Cr@zy_King.
I don't know just how exactly did they go about this hack, but it seems to have something to do with modifying the DNS records of the hacked domains, which in effect re-directs prospect visitors to a site designed by the hackers. This particular exploit is known as "SQL Injection vulnerability".
Source(s):
Microsoft NZ Hack:
http://w0rm.us/tag/peace-crew
http://www.nzherald.co.nz/technology/news/article.cfm?c_id=5&objectid=1...
NATO Hack:
http://news.softpedia.com/news/Palestinian-Supporters-Hack-NATO-and-U-S-Arm...
DNS Record Types:
http://en.wikipedia.org/wiki/List_of_DNS_record_types
SQL Injection:
http://en.wikipedia.org/wiki/SQL_injection
Helpful Answer?
(6)
(0)
Permalink |
Report
Looks like it is back up (Google Puerto Rico).
It could very well have been a member of staff at Google Puerto Rico that had hacked Google - but hackings has happened before.
Often it is a DNS problem and would just redirect to a new website. For example the "SoGo" search incident.
http://gigaom.com/2005/05/07/google-hacked/
Permalink | Report
Permalink | Report
Here is the list of mirrors if you want to see the defaced pages:
google.com.pr
http://www.zone-h.org/mirror/id/8803153
yahoo.com.pr
http://www.zone-h.org/mirror/id/8803181
msn.pr
http://www.zone-h.org/mirror/id/8803172
microsoft.com.pr
http://www.zone-h.org/mirror/id/8803165
hotmail.com.pr
http://www.zone-h.org/mirror/id/8803166
Permalink | Report
Source(s):
http://en.wikipedia.org/wiki/Phishing
Permalink | Report
Steve Gibson's most Recent discussion of DNS Spoofability Transcript:
http://www.grc.com/sn/sn-157.htm
Steve Gibson's DNS Spoofability test site:
https://www.grc.com/dns/dns.htm
Source(s):
http://www.grc.com/sn/sn-157.htm
Permalink | Report
Answered Question
Best Answer Chosen by Asker
| April 26, 2009 12:11 PM |
The principal Peace Crew character is a hacker known as Agd_Scorp, allegedly of Turkish origin. Others prominent members are rx5 and Cr@zy_King.
I don't know just how exactly did they go about this hack, but it seems to have something to do with modifying the DNS records of the hacked domains, which in effect re-directs prospect visitors to a site designed by the hackers. This particular exploit is known as "SQL Injection vulnerability".
Source(s):
Microsoft NZ Hack:
http://w0rm.us/tag/peace-crew
http://www.nzherald.co.nz/technology/news/article.cfm?c_id=5&objectid=1...
NATO Hack:
http://news.softpedia.com/news/Palestinian-Supporters-Hack-NATO-and-U-S-Arm...
DNS Record Types:
http://en.wikipedia.org/wiki/List_of_DNS_record_types
SQL Injection:
http://en.wikipedia.org/wiki/SQL_injection
| Asker's Rating: |
Helpful Answer?
(6)
(0)
Helpful: phillipluther, dbspringer, hushnow, dumblonde, sysaaron, cypheron
Tip interzone for this answerOther Answers (5)
April 26, 2009 10:35 AM
Hi there, Looks like it is back up (Google Puerto Rico).
It could very well have been a member of staff at Google Puerto Rico that had hacked Google - but hackings has happened before.
Often it is a DNS problem and would just redirect to a new website. For example the "SoGo" search incident.
http://gigaom.com/2005/05/07/google-hacked/
Permalink | Report
April 26, 2009 03:47 PM
Well personally, I think that google has gotten a bit too confident with themselves in their internet security. They have not updated their server security recently and being a hacker myself, I can say that hacking technologies are evolving much faster than the internet giant, google. Once hackers get even the slightest bit of information on any servers, most of the hackers can hack them.
Permalink | Report
April 26, 2009 04:55 PM
I think they did it with a particular ISP (OneLink) in PR. I don't think that it has to do with google security itself as acamela said. Here is the list of mirrors if you want to see the defaced pages:
google.com.pr
http://www.zone-h.org/mirror/id/8803153
yahoo.com.pr
http://www.zone-h.org/mirror/id/8803181
msn.pr
http://www.zone-h.org/mirror/id/8803172
microsoft.com.pr
http://www.zone-h.org/mirror/id/8803165
hotmail.com.pr
http://www.zone-h.org/mirror/id/8803166
Permalink | Report
April 26, 2009 06:20 PM
Well, the hack complexity is technically the same for impersonating one record or a bunch of them. To put in perspective their (hackers) workaround, we can make a security-guard analogous to DNS; and a person to a google visitor. The person asks the guard for directions to get to a specific building. Now some of the possible scenarios:
A. The hacker changed the security guard list with the building addresses.
B. There is another security guardian providing incorrect directions racing with the legitimate guard.
Report
A. The hacker changed the security guard list with the building addresses.
B. There is another security guardian providing incorrect directions racing with the legitimate guard.
April 26, 2009 11:05 PM
It appears to be that the hackers got into the administration panel of a big registrar company (Domainz.net) by SQL Injection and were able to change the records to point to another web server.
Here is the list of the sites they defaced in PR (source: zone-h)
blogsearch.google.com.pr
live.com.pr
translate.google.com.pr
nokia.pr
dell.com.pr
hsbc.com.pr
pcworld.com.pr
www.coca-cola.com.pr
nike.com.pr
nike.pr
norton.com.pr
www.norton.pr
www.paypal.com.pr
www.fanta.net.pr
www.fanta.com.pr
www.coca-cola.pr
www.yahoo.com.pr
adwords.google.com.pr
images.google.com.pr
groups.google.com.pr
www.google.pr
msn.pr
adsense.google.com.pr
hotmail.com.pr
microsoft.com.pr
news.google.com.pr
www.gmail.pr
www.google.com.pr
Report
Here is the list of the sites they defaced in PR (source: zone-h)
blogsearch.google.com.pr
live.com.pr
translate.google.com.pr
nokia.pr
dell.com.pr
hsbc.com.pr
pcworld.com.pr
www.coca-cola.com.pr
nike.com.pr
nike.pr
norton.com.pr
www.norton.pr
www.paypal.com.pr
www.fanta.net.pr
www.fanta.com.pr
www.coca-cola.pr
www.yahoo.com.pr
adwords.google.com.pr
images.google.com.pr
groups.google.com.pr
www.google.pr
msn.pr
adsense.google.com.pr
hotmail.com.pr
microsoft.com.pr
news.google.com.pr
www.gmail.pr
www.google.com.pr
April 27, 2009 07:31 AM
This is a serious issue. The phishing possibilities of an attack like this are insane.
Source(s):
http://en.wikipedia.org/wiki/Phishing
Permalink | Report
April 29, 2009 01:48 PM
If a DNS attack here's likely what was used. Which somehow replicated to other DNS servers. Steve Gibson's most Recent discussion of DNS Spoofability Transcript:
http://www.grc.com/sn/sn-157.htm
Steve Gibson's DNS Spoofability test site:
https://www.grc.com/dns/dns.htm
Source(s):
http://www.grc.com/sn/sn-157.htm
Permalink | Report
Answer this Question
Related Questions
Ask a Question
Buy Mahalo Dollars with Credit Card or PayPal
Top Members
Most Popular Tags
Categories
- Anonymous
- Arts & Design
- Beauty & Style
- Books & Authors
- Business
- Cars & Transportation
- Consumer Electronics
- Coupons Deals
- Education
- Entertainment
- Environment
- Fitness
- Food & Drink
- From Email
- From Iphone
- From Twitter
- Health
- History
- Hobbies
- Home & Garden
- How Tos
- Humor
- Jobs
- Legal
- Local
- Love & Relationships
- Mahalo Answers Community
- Money
- Music
- News
- NSFW
- Parenting
- Pets
- Science & Mathematics
- Services
- Shopping
- Social Science
- Society & Culture
- Sports
- Technology & Internet
- Travel
- Video Games
Welcome New Members
- krisgutzke, December 01, 2009 08:27 PM
- sparkinn_it_up4..., December 01, 2009 08:23 PM
- choosetulsajobs, December 01, 2009 08:18 PM
- eebabe, December 01, 2009 08:16 PM
- mms2010, December 01, 2009 08:12 PM
Mahalo Dollars are the currency of Mahalo Answers.
Each Mahalo Dollar costs $1.
Once you earn more than 40 Mahalo Dollars, you can request to be paid via PayPal. Each Mahalo Dollar is currently worth $0.75 when paid out via PayPal. Learn More


The same goes for their Microsoft New Zealand hack: the actual servers hacked were not Microsoft's, but belonged to an external "handler".