Re: anyone from netnames / ascio on list?

2011-09-05 Thread Andrew Kirch
On 9/4/2011 5:34 PM, Andrew Mulholland wrote:

I'm not seeing the problem here?
Registrant:
  Gateway, Inc. (GATEW95532)
  7565 Irvine Center Drive

  Irvine, CA, 92618-2930
  US

  Domain name: acer.com

Technical contact:
  Administrator, Domain (DA73355)
  NetNames Hostmaster
  3rd Floor Prospero House
  241 Borough High Street
  Borough, London, SE1 1GA
  GB
  corporate-servi...@netnames.com
  +44.2070159370 Fax: +44.2070159375

Administrative contact:
  Wagner, Michael (MW47730)
  Gateway, Inc.
  7565 Irvine Center Drive

  Irvine, CA, 92618-2930
  US
  hostad...@gateway.com
  +1.8008462042 Fax: +1.00

Record created:   2010-10-04 17:54:28
Record last updated:  2011-09-04 22:24:04
Record expires:   2019-05-17 01:00:00

Domain servers in listed order:
  ns1.acer.com (NS1ACERC38319)
  ns2.acer.com (NS2ACERC59089)
  ns3.acer.com (NS3ACERC70649)
  ns4.acer.com (NS4ACERC28541)
  ns5.acer.com (NS5ACERC49101)
  ns6.acer.com (NS6ACERC86343)




Re: anyone from netnames / ascio on list?

2011-09-05 Thread Andrew Mulholland
It was resolved last night.

http://www.guardian.co.uk/technology/2011/sep/05/dns-hackers-telegraph-interview

Andrew



On Mon, Sep 5, 2011 at 7:15 AM, Andrew Kirch trel...@trelane.net wrote:

 On 9/4/2011 5:34 PM, Andrew Mulholland wrote:

 I'm not seeing the problem here?
 Registrant:
  Gateway, Inc. (GATEW95532)
  7565 Irvine Center Drive

  Irvine, CA, 92618-2930
  US

  Domain name: acer.com

 Technical contact:
  Administrator, Domain (DA73355)
  NetNames Hostmaster
  3rd Floor Prospero House
  241 Borough High Street
  Borough, London, SE1 1GA
  GB
  corporate-servi...@netnames.com
  +44.2070159370 Fax: +44.2070159375

 Administrative contact:
  Wagner, Michael (MW47730)
  Gateway, Inc.
  7565 Irvine Center Drive

  Irvine, CA, 92618-2930
  US
  hostad...@gateway.com
  +1.8008462042 Fax: +1.00

 Record created:   2010-10-04 17:54:28
 Record last updated:  2011-09-04 22:24:04
 Record expires:   2019-05-17 01:00:00

 Domain servers in listed order:
  ns1.acer.com (NS1ACERC38319)
  ns2.acer.com (NS2ACERC59089)
  ns3.acer.com (NS3ACERC70649)
  ns4.acer.com (NS4ACERC28541)
  ns5.acer.com (NS5ACERC49101)
  ns6.acer.com (NS6ACERC86343)





anyone from netnames / ascio on list?

2011-09-04 Thread Andrew Mulholland
Hi

Seems Netnames / Ascio have been compromised, resulting in DNS servers  for
a number of their customers (telegraph.co.uk, acer.com, betfair.com ,
theregister.co.uk etc) being changed, and the sites being redirected to an
hacked page.

list of domains affected here:
http://zone-h.org/archive/notifier=turkguvenligi.info

Seems there's no 24/7 contact for them..

e.g.

   Domain Name: ACER.COM
   Registrar: ASCIO TECHNOLOGIES, INC.
   Whois Server: whois.ascio.com
   Referral URL: http://www.ascio.com
   Name Server: NS1.YUMURTAKABUGU.COM
   Name Server: NS2.YUMURTAKABUGU.COM
   Status: ok
   Updated Date: 04-sep-2011
   Creation Date: 07-sep-1994
   Expiration Date: 17-may-2019




If anyone on list works for them, please raise the alarm internally, and/or
start responding to your customers!


thanks



Andrew