Baidu: Registrar 'incredibly' changed our e-mail for hacker
IDG News Service - A hacker who took down top Chinese search engine Baidu.com last month broke into its account with a U.S. domain name registrar by pretending to be from Baidu in an online chat with the registrar's tech help, according to a lawsuit filed by Baidu.
Support staff at the registrar, Register.com, then refused to aid Baidu when first contacted about Baidu.com redirecting users to a Web page that declared, "This site has been hacked by the Iranian Cyber Army," the Baidu complaint alleges. The complaint was filed last month in U.S. District Court for the Southern District of New York, but the court only recently released an unredacted copy of the complaint.
The complaint says Baidu's service was disrupted for five hours by the hack and seeks millions of dollars allegedly lost in revenue and other costs.
The attack began on the afternoon of Jan. 11 when the hacker contacted Register.com tech help via online chat and claimed to be from Baidu, the complaint alleges. The attacker asked a support representative to change Baidu's e-mail address on file. The representative then sent a confirmation code to Baidu's e-mail account even though the hacker answered a security question incorrectly, the complaint alleges.
The attacker could not access Baidu's e-mail account, so instead made up a confirmation code and sent it to the support representative when asked, the complaint alleges. Without comparing the two codes, the support representative took the bogus answer to be correct and agreed to the attacker's request to change Baidu's e-mail address on file to "email@example.com", the complaint alleges.
"Incredibly," the complaint says, Register.com "thus changed the e-mail address on file from one that was clearly a business address and contained the name of the account owner, to an e-mail address that conveyed a highly politically charged message ('antiwahabi'), with the domain name ('gmail.com') of a competitor of Baidu, at the request of an individual who not only could not produce the correct security verification, but actually produced false information twice."
It's unclear exactly what 'antiwahabi' refers to, but the spelling matches that of the strict Wahabi Muslim religious sect. Baidu did not immediately reply to a request for comment.
The attacker then used the reset function for forgotten passwords to have Register.com send a new password for Baidu's account to the changed e-mail address, the complaint alleges. The attacker then changed the settings in Baidu's account to reroute visitors to a different Web page -- completing a process that took less than one hour, the complaint says.
Register.com did not immediately reply to a request for comment, but the company last month called the Baidu lawsuit "completely without merit" and said it was working with law enforcement officials investigating the crime.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Defense Throughout the Vulnerability Life Cycle This whitepaper provides insight into how to leverage threat and log management technologies to protect your IT assets throughout their vulnerability life cycle.
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts