Login Register






Thread Rating:
  • 0 Vote(s) - 0 Average


Lenovo website hacked filter_list
Author
Message
Lenovo website hacked #1
Quote:The hacking collective took over the Lenovo site for several hours on Wednesday, redirecting users to a slideshow of bored teenagers

[Image: 5ee65e3c-d882-42dc-a366-ca8f9db41c92-bes...lable.jpeg]

Lenovo, the PC maker at the centre of the Superfish controversy, suffered its own security breach on Wednesday when its main website was defaced, redirecting users to a slideshow of pictures of bored-looking teens (apparently the hackers themselves) set to the song Breaking Free from High School Musical.

Clicking on the slideshow sends users to the Twitter account of hacking collective the Lizard Squad, while viewing the source of the page reveals a note reading “the new and improved rebranded Lenovo website featuring Ryan King and Rory Andrew Godfrey” – two people previously named by security reporter Brian Krebs as being members of the group.

Lizard Squad tweeted hours before the attack to expect “more mischief”.

The hack was apparently carried out through a “DNS hijack”, an increasingly common method whereby domain name system server, which translates a human-readable web address such as google.cominto a machine-readable IP address such as “8.8.8.8”, redirects visitors to another website – in this case, one controlled by Lizard Squad.

The hijack closely resembles another Lizard Squad attack, on Google’s Vietnamese website, which was carried out this week, according to Andrew Hay, director of security research at OpenDNS. Both sites used the same domain name registrar, Webnic.cc.

“Two defacements in a single week is normally nothing, but two extremely high-profile defacements from the same registrar in the same week is a definite trend,” Hay said. “We may see more redirections of domains that were registered with Webnic.cc in the coming days.”

Following the hack, Lizard Squad has been posting screenshots of emails allegedly sent to Lenovo.com addresses, including one discussing Superfish. A DNS hijack can potentially gain access to emails sent during the period the site is taken over, by redirecting the email in the same way as the website. But this would not grant access to the full database of emails.

In a statement, Lenovo said: “Unfortunately, Lenovo has been the victim of a cyber attack. One effect of this attack was to redirect traffic from the Lenovo website. We are also actively investigating other aspects. We are responding and have already restored certain functionality to our public facing website.

“We are actively reviewing our network security and will take appropriate steps to bolster our site and to protect the integrity of our users’ information and experience.

“We are also working proactively with 3rd parties to address this attack and we will provide additional information as it becomes available.”


Lenovo’s reputation in the information security community was already rock-bottom after it emerged that the company sold laptops infected with pre- installed malware named Superfish, which broke users’ encrypted connections in order deliver the firm’s own adverts into search pages.

The company initially denied the reports, saying that it was “satisfied” that user security was never at risk. A day later it recanted and apologised for its error.

Peter Hortensius, Lenovo’s chief technology officer, told the New York Times that “we did not do a thorough enough job understanding how Superfish would find and provide their info. That’s on us. That’s a mistake that we made.”

He added: “This week we begin the plan to make sure this never happens again. We’ll release that plan by the end of the week.”

[source]

Reply

RE: Lenovo website hacked #2
I remember a time when quotes from external sites pissed you off. Tongue

OT: Lizard Squad is gay. Lenevo's been under some heavy fire recently. First the super fish shit and now this...

Reply

RE: Lenovo website hacked #3
(02-26-2015, 10:00 PM)Eclipse Wrote: I remember a time when quotes from external sites pissed you off. Tongue

OT: Lizard Squad is gay. Lenevo's been under some heavy fire recently. First the super fish shit and now this...

I hate how IMO Lenovo makes the best laptops, ever.

And they do, but at least this shit is interesting, relevant to the forum, and has a source link. Tongue

Reply

RE: Lenovo website hacked #4
Lmao. That's great. Skids actually doing their own work. Shoutouts to Lenovo for trash security.

Reply

RE: Lenovo website hacked #5
That's me in that picture, lol

(02-26-2015, 10:28 PM)Losi Wrote: Lmao. That's great. Skids actually doing their own work. Shoutouts to Lenovo for trash security.

"Their own work"? Not quite. They used Scott's exploit and my rootkit.
(This post was last modified: 02-26-2015, 10:30 PM by Reiko.)
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: Lenovo website hacked #6
(02-26-2015, 10:28 PM)Reiko Wrote: That's me in that picture, lol


"Their own work"? Not quite. They used Scott's exploit and my rootkit.

Nvm. Skids just being skids.

Reply

RE: Lenovo website hacked #7
(02-26-2015, 10:28 PM)Reiko Wrote: That's me in that picture, lol


"Their own work"? Not quite. They used Scott's exploit and my rootkit.

qt3.14

Reply

RE: Lenovo website hacked #8
It seems that their website wasn't defaced at all then, traffic was simple redirected to a fake site with pretty much nothing Lenovo could possible have done to prevent it. Basically "Lenovo website hacked and defaced" is simply untrue.

Edit: You could say they deserved it after the superfish affair.
[Image: master645.png]

Life before death, strength before weakness, journey before destination.” ― The Way of Kings by Brandon Sanderson

[+] 1 user Likes Master's post
Reply

RE: Lenovo website hacked #9
(02-26-2015, 10:47 PM)Master Wrote: It seems that their website wasn't defaced at all then, traffic was simple redirected to a fake site with pretty much nothing Lenovo could possible have done to prevent it. Basically "Lenovo website hacked and defaced" is simply untrue.

Reasonable points, although the 'face' of the site was changed. Still counts for me.

Reply

RE: Lenovo website hacked #10
(02-26-2015, 10:28 PM)Reiko Wrote: That's me in that picture, lol


"Their own work"? Not quite. They used Scott's exploit and my rootkit.

nice! although you probs didnt want your face on a top site.
sucks using others work. what did the exploit target?

Reply







Users browsing this thread: 1 Guest(s)