Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC InfoSec Handlers Diary Blog

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Several Sites Defaced

Published: 2011-09-04
Last Updated: 2011-09-05 08:40:22 UTC
by Lorna Hutcheson (Version: 4)
8 comment(s)

3rd Update: Update with more details of the incident from The Register itself: (thanks Alex)

2nd Update: The root problem appears to be mitigated now. However, many DNS servers now have bad results cached. Please flush the cache of your recursive DNS servers.

Host names and IP addresses to watch: or or or or

IP Address used as A record for affected domains:

In particular IP addresses may change at any time. Please keep watching them and remove from blacklist as appropriate.


There have been several widespread defacements reported to us today.  It appears their DNS name server entries all point to the same thing as seen below:  85621 IN NS  85621 IN NS  85621 IN NS  85621 IN NS

Here are a few examples of the sites so far:

The one commonality is they all appear to be all registered via

More details as we learn more.


UPDATE:  This IP is hosted by BlueMile.  We have contacted them and they are aware of the situation and working on it.

8 comment(s)
Diary Archives