Baidu: Registrar 'incredibly' changed our e-mail for hacker
IDG News Service - A hacker who took down top Chinese search engine Baidu.com last month broke into its account with a U.S. domain name registrar by pretending to be from Baidu in an online chat with the registrar's tech help, according to a lawsuit filed by Baidu.
Support staff at the registrar, Register.com, then refused to aid Baidu when first contacted about Baidu.com redirecting users to a Web page that declared, "This site has been hacked by the Iranian Cyber Army," the Baidu complaint alleges. The complaint was filed last month in U.S. District Court for the Southern District of New York, but the court only recently released an unredacted copy of the complaint.
The complaint says Baidu's service was disrupted for five hours by the hack and seeks millions of dollars allegedly lost in revenue and other costs.
The attack began on the afternoon of Jan. 11 when the hacker contacted Register.com tech help via online chat and claimed to be from Baidu, the complaint alleges. The attacker asked a support representative to change Baidu's e-mail address on file. The representative then sent a confirmation code to Baidu's e-mail account even though the hacker answered a security question incorrectly, the complaint alleges.
The attacker could not access Baidu's e-mail account, so instead made up a confirmation code and sent it to the support representative when asked, the complaint alleges. Without comparing the two codes, the support representative took the bogus answer to be correct and agreed to the attacker's request to change Baidu's e-mail address on file to "email@example.com", the complaint alleges.
"Incredibly," the complaint says, Register.com "thus changed the e-mail address on file from one that was clearly a business address and contained the name of the account owner, to an e-mail address that conveyed a highly politically charged message ('antiwahabi'), with the domain name ('gmail.com') of a competitor of Baidu, at the request of an individual who not only could not produce the correct security verification, but actually produced false information twice."
It's unclear exactly what 'antiwahabi' refers to, but the spelling matches that of the strict Wahabi Muslim religious sect. Baidu did not immediately reply to a request for comment.
The attacker then used the reset function for forgotten passwords to have Register.com send a new password for Baidu's account to the changed e-mail address, the complaint alleges. The attacker then changed the settings in Baidu's account to reroute visitors to a different Web page -- completing a process that took less than one hour, the complaint says.
Register.com did not immediately reply to a request for comment, but the company last month called the Baidu lawsuit "completely without merit" and said it was working with law enforcement officials investigating the crime.
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts