Bitdefender and ESET Domains Hijacked by KDMS Team

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
Pro-Palestinian hackers of KDMS Team have hijacked two more high-profile domains via DNS poisoning. Their latest targets are the websites of ESET (eset.com) and Bitdefender (bitdefender.com).

“We was thinking about quitting hacking and disappear again! But we said: there is some sites must be hacked. You are one of our targets. Therefore we are here,” the hackers wrote on the defaced sites.

“And there is another thing. Do you know Palestine? There is a land called Palestine on the earth. This land has been stolen by Zionist. Do you know it? Palestinian people has the right to live in peace. Deserve to liberate their land and release all prisoners from Israeli jails. We want peace,” they added.

Both Bitdefender and ESET have clarified that their systems haven’t been hacked.

“A group of pro-Palestinian activists were able to spoof a request to change the DNS settings for the ESET.com domain name servers, resulting in a defacement where visitors to the ESET.com website were redirected to one set up by the activist group,” ESET representatives stated.

“ESET responded immediately and the name server records were corrected minutes after the incident. The defacement site may have been visible for slightly longer due to the time taken for DNS changes to propagate. At the same time, we requested our registrar to bolster domain transfer security to ensure no similar incident will happen again,” they added.

“At no time was any ESET infrastructure component compromised, and no data or sensitive materials have been breached. ESET operations were not affected except for the visibility of the ESET.com website for a short period of time.”

Bitdefender has confirmed that their DNS records have been changed via an attack aimed at Register.com.

On Sunday, the hackers posted a message on Facebook to clarify that their attacks would continue.

“We have a list of targets, it’s not the end yet!” they said.



Source
 

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
If the website does not open properly, you can update your DNS-cache as follows: Win + X> Command Prompt (Administrator)> type ipconfig / flushdns and press Enter.
 

MrXidus

Super Moderator (Leave of absence)
Apr 17, 2011
2,503
Appears these kids tried to hit Avast aswell. :rolleyes:

mxsgBqh.png
 

jogs

Level 22
Verified
Top Poster
Well-known
Nov 19, 2012
1,113
If the top AV sites get hit like this, then how can we feel protected. There's nothing secure on the net. Every lock in the net has a key, one just needs a good locksmith.
 

MalwareVirus

Level 1
Oct 6, 2012
770
Soon they make a mistak i feel and got caught.After avira and Avg ,Other security companies should take hard step to make their website hard to fool but this is not really good news for users of these or other product users and defenetly it sends the wrong msg out there.
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Good for Avast for preventing the attack.

Avast (1) - KDMS (0)
 

Malware1

Level 76
Sep 28, 2011
6,545
Petrovic said:
If the website does not open properly, you can update your DNS-cache as follows: Win + X> Command Prompt (Administrator)> type ipconfig / flushdns and press Enter.

Not ipconfig / flushdns, should be ipconfig /flushdns (no space after "/").

Both websites work for me. :)
 

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
MalwareCenter said:
Not ipconfig / flushdns, should be ipconfig /flushdns (no space after "/").
It was a quote, I hope everyone knows how to type commands ;)
 
G

Guest28

Good to know avast never sleeps in protecting its self and the users. Not that I Encourage hacking at all. But it would have been funny if they hit comodo wonder if they have a default deny on that. L0L.......
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
They want everyone to be aware that "There is a land called Palestine on the earth", I think that's about it.

Could be another way to promote people to learn Geography?
 

BoraMurdar

Community Manager
Verified
Staff Member
Well-known
Aug 30, 2012
6,598
I think they just want people to know what's going on with their country as probably no one cares...
Now, let me see if they can hack Kaspersky or Symantec, it would be tough nuts to crack :D
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top