Twitter Hacked by Iranian Cyber Army

105 44
Yes, it's true all you twitterers out there had nowhere to tweet today, when the site was inaccessible. Now although I say Twitter was hacked it wasn't really, in fact the Iranian Cyber Army didn't actually touch their servers. The attack was more subtle and used one of the weak spots of many web sites, their DNS records.

Now DNS stands for the Domain name system and is a fundamental building block of how the internet works. When you type in a web address into your browse, DNS is responsible for locating the correct web site and directing you there. It actually maps the IP address to the web address and controls which site you end up in.

It looks highly likely that the Iranian Cyber Army changed Twitters DNS records to send twitterers to a different site (where they put up a political message). The Twitter servers would have been highly secure especially as they were attacked earlier in the year, yet it appears their DNS records where not.

So although the Iranian cyber Army may have had limited resources, they had the most important - technical knowledge. DNS is the weak spot of most web sites, Google have been there too and many other web sites will follow. Super Secure servers are no defense when your users never actually reach your site. But we should be thankful that the only effect was a little political ranting and a few lost tweets, it could have been much worse.

Imagine if the redirected web site had been a copy of the Twitter logon page, designed to purely steal logon credentials. How many accounts would have been compromised? How many of these accounts are also logons to banks and other financial sites? The cyber crime and identity theft possibilities could have been huge. As it is we are simply left wondering who exactly are the Iranian Cyber Army, I'd still change my passwords quickly if I was a Twitter user though!
Source...
Subscribe to our newsletter
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
You can unsubscribe at any time

Leave A Reply

Your email address will not be published.