It looks like Google.ie has been hijacked
The current whois record shows:
whois google.ie
% Rights restricted by copyright; http://iedr.ie/index.php/mnudomregs/mnudnssearch/96
% Do not remove this noticedomain: google.ie
descr: Google, Inc
descr: Body Corporate (Ltd,PLC,Company)
descr: Registered Trade Mark Name
admin-c: KR59-IEDR
tech-c: CCA7-IEDR
registration: 21-March-2002
renewal: 21-March-2013
status: Active
nserver: ns1.farahatz.net
nserver: ns2.farahatz.net
source: IEDRperson: Kulpreet Rana
nic-hdl: KR59-IEDR
source: IEDRperson: eMarkmonitor Inc
nic-hdl: CCA7-IEDR
source: IEDR
So who is at fault here?
Google? IEDR? Or Mark Monitor?
What do you think?
UPDATE 14:15
Whois has reverted back to Google’s though it’ll probably take a while for people to see the change due to caching with their ISP’s resolvers etc.,
whois google.ie
% Rights restricted by copyright; http://iedr.ie/index.php/mnudomregs/mnudnssearch/96
% Do not remove this noticedomain: google.ie
descr: Google, Inc
descr: Body Corporate (Ltd,PLC,Company)
descr: Registered Trade Mark Name
admin-c: KR59-IEDR
tech-c: CCA7-IEDR
registration: 21-March-2002
renewal: 21-March-2013
status: Active
nserver: ns1.google.com
nserver: ns2.google.com
nserver: ns3.google.com
source: IEDRperson: Kulpreet Rana
nic-hdl: KR59-IEDR
source: IEDRperson: eMarkmonitor Inc
nic-hdl: CCA7-IEDR
source: IEDR
Update 1525:
Just to clarify. The DNS was not “hacked”. The DNS servers were changed away from Google to somewhere else. This is a “hijack” not a DNS hack
BUT, the change was not authorised by Google, so someone either hacked into or social engineered their way into either IEDR or Mark Monitor in order to get the change made.
Update 1739:
Seemingly yahoo.ie was also hijacked today and the nameservers changed to the farahatz.net ones. These changes *appear* to have been reverted before too many people noticed.
At this stage I am not aware of any official statements from either Google (they’re declining to comment), IEDR (they probably won’t say much today, if ever) or MarkMonitor.
Both domains (google.ie and yahoo.ie) were pointed to an IP in Indonesia (119.235.27.219)
While Google.ie obviously gets a very large amount of web traffic it isn’t actively used for email. Yahoo.ie on the other hand would be used by a lot of Irish Yahoo! email users, so email service for them would have been disrupted.
Update 2000:
Most Irish users are now able to access google.ie as normal, however at least some are still reporting issues:
@blacknight
Google.ie still down. .com & .co.uk can be accessed thankfully. Yahoo.ie seem to have sorted their problem— Joe Guinan (@JoeGuinan) October 9, 2012
Does anyone know why google.ie isn't working?
— Humphrey Jones 🔬🧬🥼🧪 (@humphreyjones) October 9, 2012
This may be down to their ISP’s DNS servers holding stale records from earlier this afternoon or it could be that their office or home router has cached the records.
Google has issued an apology for the disruption to Irish users which has been reported by several media sources.
Update 2125
Here’s the full statement from the IEDR (courtesy of The Sociable):
Statement by IE Domain Registry re unauthorised access to two high profile .ie web addresses
Tuesday, 9th October, 2012: The IEDR confirms that earlier this afternoon an unauthorised change was made to two .ie domains on an independent Registrar’s account which resulted in a change of DNS nameservers. The consequence of the change is that visitors to the two websites would be redirected to an allegedly fraudulent address. The IEDR worked with the Registrar to ensure that the nameserver records have been corrected.
It’s not particularly long, but it would seem to suggest that IEDR are blaming Mark Monitor. Wouldn’t it have been more prudent to work with the registrar before sending out something like this?
Seemingly Mark Monitor are blaming IEDR:
San Francisco-based MarkMonitor, the registrar responsible for both addresses, blamed lax security at the Irish registry level for the incident.
Surely this kind of “blame game” is counter-productive?
The IEDR suffered a massive outage last month with their public-facing websites, whois and other services unavailable for about 36 hours.
UPDATE 2310 IEDR have taken all their websites and whois offline. In an email to registrars IEDR state that they have been in contact with the Gardai (Irish police).
UPDATE 0745 IEDR have published a statement on their website explaining (briefly) why their websites and other services are offline:
IEDR systems are currently unavailable. We apologise for the inconvenience to our customers.
As you may be aware, there was a security incident on Tuesday 9th October, involving two high profile .ie domains.
There was an unauthorised access to one Registrar’s account which resulted in the change to the DNS nameserver records for the two .ie domains.
The IEDR worked with the Registrar to ensure that the nameserver records were reset and corrected promptly.
Simultaneously, IEDR commenced an investigation and analysis, with the assistance of external security experts.Based on the results of the investigation and the recommendation of security experts,
IEDR are bringing its external web-based systems off-line, commencing at 22:00 hours, in order to perform additional analysis.Gardai have been notified and IEDR has requested that the Garda Bureau of Fraud Investigation conduct an investigation into this external attack on the .ie namespace.
IEDR will provide further updates on this web page as additional information becomes available.
IEDR Team
And here’s a screenshot of their main site as of 8am this morning:
Their WHOIS service is currently available so people will be able to access information related to currently registered .ie domain names.
Update 1645
While many Irish internet users yesterday were unable to reach google.ie some apparently were sent to a site on an Indonesian IP.
Here’s a screenshot of what they saw:
Via @athomeitwex on Twitter
The “defacement” or “hack” page is signed by a “Hmei7” who is apparently an Indonesian hacker whose “signature” has appeared on thousands of websites defacements including attacks against Asus and Siemens.
Related articles
- IEDR Suffers Major Outage (internetnews.me)
- IEDR Data Dump (internetnews.me)
- IEDR Suffers Another Outage (internetnews.me)
- IEDR To Offer More Frequent Zone Reloads (internetnews.me)
- IEDR To Go Offline Again This Evening (internetnews.me)
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
“@blacknight: Google.ie Hijacked?: http://t.co/9V2gMpPu”
@blacknight It’s the IEDR that are in trouble. Telling me “You have issued 1001 queries today” Yeah, right
O dear! RT @blacknight: Google.ie Hijacked?: http://t.co/OVYh6QsY
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
i was just wondering what the hell happened
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
Is it for sale? :)
“@blacknight: Google.ie Hijacked?: http://t.co/GUoOMez6” @Extratimenews FYI
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
Google.ie Hijacked? http://t.co/4RjiPfUJ
It also seems that IEDR.ie is down as well or under heavy traffic.
https://technology.ie/google-ie-hijacked/
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
woah :) secure much? :D RT @blacknight: Google.ie Hijacked?: http://t.co/S1Xcz1iU
@seidodge Dodge – http://t.co/glqOTk36
That might explain my Google issues: http://t.co/EzsdfdHB #security
@JoeCarlyle Nope… apparently… THIS: http://t.co/5Zl64Swc
IEDR site is loading fine for me here ..
loads fine now.
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
Google.ie Hijacked?: http://t.co/sk5i50hn
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
Has google.ie been hi-jacked? http://t.co/tzKtIpMR #hacked
@darraghdoyle you’d not seen http://t.co/ue4b6xDx ? :)
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
RT @mneylon: Google DNS reverted – post updated: http://t.co/WNUbIRwK
@UnaMullally @SeanTynan should be ok now see http://t.co/Z3s8Ey8V
@LockhartGav DNS was hacked http://t.co/XjXOGzmJ
Ireland – Google.ie Hijacked? Not confirmed yet but we are experiencing problems loading website – latest – http://t.co/C6RlgRVc
@SeanMoncrieff Seems google.ie been hijacked? – http://t.co/05qIj7mW No access to it. Most think I/Net fault as it der homepage @NewsTalkfm
Google.ie domain hijack – post updated with some more details / clarification http://t.co/vYEE54O2
RT @blacknight: Google.ie domain hijack – post updated with some more details / clarification http://t.co/vYEE54O2
was Google.ie Hijacked today ? http://t.co/K0k1CLBM via @blacknight
Has the Google.ie domain been hijacked? http://t.co/W7tyN19f
@KrishnaDe @wsionline related to http://t.co/ue4b6xDx ? :) so probably a DNS issue
google.ie – hacked ????? http://t.co/L6psYdrw
If like me you had issues accessing Google.ie today this may expain why “Google.ie Hijacked?” http://t.co/oByM0khY < ht @forbairt
If you had problems accessing Google.ie this afternoon this may explain why “Google.ie Hijacked?”
https://technology.ie/google-ie-hijacked
RT @blacknight: Google.ie domain hijack – post updated with some more details / clarification http://t.co/vYEE54O2
How could Google.ie have been hijacked? The IEDR are really strict about domain ownership. http://t.co/DJY8gF7R
RT @blacknight: Google.ie domain hijack – post updated with some more details / clarification http://t.co/vYEE54O2
RT @KrishnaDe: If like me you had issues accessing Google.ie today this may expain why “Google.ie Hijacked?” http://t.co/oByM0khY < h …
@MichealDeery Someone dropped something http://t.co/BJZLCTOW
RT @blacknight: Google.ie Hijacked?: http://t.co/LQ8ajXr1
RT @garrettmurphy: @MichealDeery Someone dropped something http://t.co/BJZLCTOW
This demonstrates a good reason for Google to get the .google TLD – that way they control ie.google more directly than google.ie
Seems that the change was already reversed though
Yahoo.ie and Google.ie were hijacked. Post updated: http://t.co/PCHv5iKj
RT @blacknight: Yahoo.ie and Google.ie were hijacked. Post updated: http://t.co/PCHv5iKj
RT @blacknight: Yahoo.ie and Google.ie were hijacked. Post updated: http://t.co/PCHv5iKj
Google.ie Hijacked? http://t.co/nvGgLReS via @blacknight
RT @blacknight: Yahoo.ie and Google.ie were hijacked. Post updated: http://t.co/PCHv5iKj
Very incisive comment on google.ie vs ie.google #icann #newtlds http://t.co/2Uj2oqre
RT @blacknight: Yahoo.ie and Google.ie were hijacked. Post updated: http://t.co/PCHv5iKj
RT @blacknight: Google.ie domain hijack – post updated with some more details / clarification http://t.co/vYEE54O2
Google.ie hijack article updated with latest info http://t.co/uhqlewTT
RT @blacknight: Google.ie hijack article updated with latest info http://t.co/uhqlewTT
RT @blacknight: Google.ie domain hijack – post updated with some more details / clarification http://t.co/vYEE54O2
RT @blacknight: Google.ie hijack article updated with latest info http://t.co/uhqlewTT
@blacknight Interesting http://t.co/5STKkLmn “MarkMonitor blamed lax security at the Irish registry level for the incident” #google.ie
Another update on the Google.ie hijack – Mark Monitor blaming IEDR’s security for incident: http://t.co/W2pI7Mxu
RT @blacknight: Another update on the Google.ie hijack – Mark Monitor blaming IEDR’s security for incident: http://t.co/W2pI7Mxu
RT @blacknight: Another update on the Google.ie hijack – Mark Monitor blaming IEDR’s security for incident: http://t.co/W2pI7Mxu
RT @blacknight: Another update on the Google.ie hijack – Mark Monitor blaming IEDR’s security for incident: http://t.co/W2pI7Mxu
@primaryposition @Redfly @searchbrat no it wasn’t – http://t.co/bEcwuxTs
@blacknight @Redfly @searchbrat oops I meant hijacked :'(
IEDR have taken all their websites offline following today’s security issue: http://t.co/lTRjlMZP
RT @blacknight: IEDR have taken all their websites offline following today’s security issue: http://t.co/lTRjlMZP
RT @blacknight: IEDR have taken all their websites offline following today’s security issue: http://t.co/lTRjlMZP
@blacknight Your name is in lights :D http://t.co/1ZHPDRRO .. End of article!
My favourite bit – the culprit’s name, Kulpreet.
Great stuff! In a nefarious, Dr Evil kind of way.
That name is actually legit :)
David Kirwan liked this on Facebook.
Interesting twist with todays google.ie hijack“@blacknight: IEDR have taken all their sites offline following security:http://t.co/pG8oxjML”
We’ve been updating this post about what happened re: Google.ie + IEDR http://t.co/bEcwuxTs
After seeming to blame a registrar for the google/yahoo.ie hijacks, IEDR takes its own sites offline. WTF is going on? http://t.co/v3ZKj8KH
RT @blacknight: We’ve been updating this post about what happened re: Google.ie + IEDR http://t.co/bEcwuxTs
IEDR website unavailable. API + WHOIS available. More info here: https://technology.ie/google-ie-hijacked/
Irish DNS registry has taken itself offline, is in contact with Irish police about the matter! http://t.co/vpIxiiRY
RT @PowerDNS_Bert: Irish DNS registry has taken itself offline, is in contact with Irish police about the matter! http://t.co/vpIxiiRY
RT @PowerDNS_Bert: Irish DNS registry has taken itself offline is in contact with Irish police about the matter http://t.co/IrvV9iYj ->leest
RT @PowerDNS_Bert: Irish DNS registry has taken itself offline, is in contact with Irish police about the matter! http://t.co/vpIxiiRY
Zou dit ook in NL kunnen? RT @PowerDNS_Bert: Irish DNS registry has taken itself offline, in contact with police! http://t.co/hTXeYxJg
RT @PowerDNS_Bert: Irish DNS registry has taken itself offline, is in contact with Irish police about the matter! http://t.co/vpIxiiRY
@luisgolmedo hay mas detalles aqui (en ingles) http://t.co/i7rExP78
IEDR Hijacked? http://t.co/deNVcO0l
Google.ie &Yahoo.ie domains hijacked, diverted to Indonesian DNS. IEDR and @MarkMonitor play blame-game http://t.co/xdbuyqIL via @blacknight
Interesting, Google & Yahoo .ie domains hijacked yesterday http://t.co/7j6V01q3 via @gerrymulvenna
RT @blacknight: Another update on the Google.ie hijack – Mark Monitor blaming IEDR’s security for incident: http://t.co/W2pI7Mxu
RT @blacknight: Another update on the Google.ie hijack – Mark Monitor blaming IEDR’s security for incident: http://t.co/W2pI7Mxu
RT @PowerDNS_Bert: Irish DNS registry has taken itself offline, is in contact with Irish police about the matter! http://t.co/vpIxiiRY
Our post about the google.ie hijack is getting quite a bit of traffic :) http://t.co/H6zHn17U
RT @blacknight: Our post about the google.ie hijack is getting quite a bit of traffic :) http://t.co/rn9ERU0S @regvulture
If you want a more “blow by blow” of the Google.ie hijack check http://t.co/bEcwuxTs
RT @blacknight: If you want a more “blow by blow” of the Google.ie hijack check http://t.co/bEcwuxTs
RT @blacknight: If you want a more “blow by blow” of the Google.ie hijack check http://t.co/bEcwuxTs
RT @PowerDNS_Bert: Irish DNS registry has taken itself offline, is in contact with Irish police about the matter! http://t.co/vpIxiiRY
RT @alanbourke: RT @blacknight: Our post about the google.ie hijack is getting quite a bit of traffic :) http://t.co/rn9ERU0S @regvulture
google.ie und yahoo.ie wurden gestern gehacked. Die Nameserver der Domains wurden anscheinend verändert: http://t.co/w8mtyBfd
RT @alanbourke: RT @blacknight: Our post about the google.ie hijack is getting quite a bit of traffic :) http://t.co/rn9ERU0S @regvulture
RT @alanbourke: RT @blacknight: Our post about the google.ie hijack is getting quite a bit of traffic :) http://t.co/rn9ERU0S @regvulture
RT @blacknight: If you want a more “blow by blow” of the Google.ie hijack check http://t.co/bEcwuxTs
@blacknight google.ie last night. http://t.co/bSFqOk8K
RT @alanbourke: RT @blacknight: Our post about the google.ie hijack is getting quite a bit of traffic :) http://t.co/rn9ERU0S @regvulture
Google.ie hijack – updated with screenshot of “defacement” http://t.co/OGJUMgwk
RT @blacknight: Google.ie hijack – updated with screenshot of “defacement” http://t.co/OGJUMgwk
defacer indonesia yg kreatif -> Hmei7
ba hack irlandia domain registry, trus ba ganti DNS situs google + yahoo
http://t.co/MxPrg6JD
What a mess: Google.ie Hijacked? http://t.co/DuwB0I4C via @blacknight
RT @blacknight: Another update on the Google.ie hijack – Mark Monitor blaming IEDR’s security for incident: http://t.co/W2pI7Mxu
Looks like microsoft.ie was hacked as well, which makes it 3 instead of 2.
http://www.zone-h.org/mirror/id/18445815
Google.ie Hijacked? http://t.co/InnnLY5w
RT @owenderby: Google.ie Hijacked? http://t.co/InnnLY5w
ah, the week’s that’s in it for site hacks, http://t.co/laeasssT
Google.ie Hijacked? http://t.co/WbrFyMU0 przez @blacknight