China's Largest Search Engine Hacked by "Iranian Cyber Army"
Posted 01/12/10 at 10:56:58 AM by Paul Lilly
Sorry Baidu users, your search engine is down for the count (in parts of the world, anyway), at least for the time being. No, a late night watchman didn't trip over the power cord in a data center, and instead the outage appears to be the work of Iranian hackers.
Baidu, China's most popular search engine with a market share exceeding 77 percent, now shows a page saying "This site has been hacked by Iranian Cyber Army." These are the same dudes who also attacked and defaced Twitter just a few weeks ago using the same method: DSN cache poisoning.
Sounds toxic, but rest assured, no chemicals were used. DNS cache poisoning involves corrupting a DNS table by replacing an IP with a malicious address, which in this case is the Iranian Cyber Army page.
Why the hackers targeted Baidu is not yet known.

Image Credit: thenextweb.com
when I read this I almost
Submitted by jdfskitz on Fri, 01/15/2010 - 10:25pm
when I read this I almost fell out of my chair laughing xD
i'm 15 and I think its even stupid to hack something and replace the site with English saying the Iranian Cyber Army.
they obviously like mustaches o.o
Take your pride, for now
Submitted by Trooper_One on Tue, 01/12/2010 - 1:32pm
Nice one script kiddies; but I'm sure the Chinese (or anyone else for that matter) are planning something more sinister behind the scene - and we the public wouldn't even know it.
What is DSN cache poisoning?
Submitted by Gigabyte on Tue, 01/12/2010 - 1:34pm
DNS mabye! =)
Check your DNS.
https://www.grc.com/dns/dns.htm
Scroll to the bottom and select “Initiate Standard DNS Spoofability Test”
It might be time to switch to Google or OpenDNS
https://www.grc.com/dns/Benchmark.htm
Select the Nameservers tab > Add/Remove >
I remove everything. There’s way too much stuff in there. It’s a little
overwhelming for beginners. It’s easy to restore everything too.
Select Add System’s Nameservers and type in the desired IP addresses.Google DNS
8.8.8.8
8.8.4.4Open DNS
208.67.222.222
208.67.220.220
Go Iran
Submitted by ThunderBolt on Tue, 01/12/2010 - 11:54am
Iran > Commies
Hmm...
Submitted by habuza on Tue, 01/12/2010 - 10:22am
Everyone seems to have a "script kiddie" comment when hacks happen. Must make you one of those 1337 h4x0r5 hm? Point is this - it happened. Move on, don't even give them the satisfaction of acknowledgement. That's what they're after. Once China tracks down who did it, that's when the real fun will start.
Yes actually
Submitted by CentiZen on Tue, 01/12/2010 - 10:43am
Mabey not as a hacker in that sense, but I am a security specialist who does freelance work securing servers and pentesting for businesses. And I haven't had a succesful single break in on any of my work yet.
You should revise your text
Submitted by fnordfnord on Tue, 01/12/2010 - 2:04pm
You should revise your text and make sure everything is written properly, it would help make you look like you're not 15 years old.
I just don't see the purpose
Submitted by Who on Tue, 01/12/2010 - 10:19am
I just don't see the purpose behind these attacks. If they were actual talented hackers wouldn't they do something more useful, identity theft, or w/e. Ransom personal info like that virginia medical records debacle
This is why the hackers targeted baidu
Submitted by CentiZen on Tue, 01/12/2010 - 10:13am
This is how these stupid little script kiddies work, they find an public exploit, mass seach for vulnerable sites and hack them all. They don't care what site they are hacking, they just hack whatever they possibly can using the exploits they downloaded. For some reason they think it gains them respect, but the public hates them for inconvenienceing them and all the real hackers laugh at them because these skid's actually think what they are doing is hacking, when it's not.
I mean, you can tell they didn't do it for any reason in particular, because it's the same canned deface page they use on every other site. I bet they didn't even know what they were hacking.
-
Feature -
Feature -
How-To -
Feature -
Feature


