In dimineata aceasta, DNS-urile GOOGLE (8.8.8.8 si 8.8.4.4), extrem de folosite in ultima vreme datorita stabilitatii si disponibilitatii excelente au fost .... hacked !
Ca sa spunem chiar adevarul nu au fost chiar hacked, adica nimeni nu a spart nici un server si nimeni nu a furat nici o informatie. Serverele au suferit un atac de tip DNS poisoning.
Astfel, cei care aveau setat DNS la Google sau la un provider care a apucat sa isi reimprospateze cache-ul de la Google, accesand www.google.ro obtineau:
Si asta fiindca nameserver-ele Google rezolvau www.google.ro la 95.128.3.172, un IP care evident nu are nici o legatura cu Google. Mai precis, folosind
Si se pare ca, cel putin acum, 29 Noiembrie 2012 ora 11:00 ora Romaniei, la ore bune de la atac, Google inca nu si-a revenit. Daca vreti sa urmariti starea, accesati
si uitati-va la ce rezolva. Daca e in continuare 95.128.3.172 atunci nu e bine, si cat timp nu se remediaza chiar DNS-urile Google, cele ale providerilor vor continua sa preia informatie falsa. Uite cum arata acum:
Server DNS local
(IP: 127.0.0.1)
95.128.3.172
(40.3 ms)
EUROWEB nsx.euroweb.ro
(IP: 193.230.183.201)
173.194.35.151
173.194.35.152
173.194.35.159
EUROWEB tag.euroweb.ro
(IP: 193.226.61.1)
173.194.35.184
173.194.35.191
173.194.35.183
GTS ns.gtstelecom.ro
(IP: 193.226.128.1)
NO ANSWER
GTS ns2.gtstelecom.ro
(IP: 193.226.128.129)
173.194.35.183
173.194.35.184
173.194.35.191
GOOGLE google-public-dns-a.google.com
(IP: 8.8.8.8)
95.128.3.172
(56.47 ms)
GOOGLE google-public-dns-b.google.com
(IP: 8.8.4.4)
95.128.3.172
(56.22 ms)
OPENDNS resolver1.opendns.com
(IP: 208.67.222.222)
173.194.35.184
173.194.35.183
173.194.35.191
OPENDNS resolver2.opendns.com
(IP: 208.67.220.220)
173.194.35.191
173.194.35.183
173.194.35.184
RDS ns1.rdsnet.ro
(IP: 193.231.236.17)
173.194.35.151
173.194.35.152
173.194.35.159
RDS ns2.rdsnet.ro
(IP: 193.231.236.10)
173.194.35.152
173.194.35.159
173.194.35.151
RDS dns1.rds-rcs.ro
(IP: 213.154.124.1)
TIME OUT
RDS dns2.rds-rcs.ro
(IP: 193.231.252.1)
173.194.35.191
173.194.35.183
173.194.35.184
RDS dns-cache-1.rdsnet.ro
(IP: 193.231.236.25)
173.194.35.183
173.194.35.184
173.194.35.191
RDS dns-cache-2.rdsnet.ro
(IP: 193.231.236.30)
62.231.91.98
62.231.91.99
62.231.91.103
62.231.91.94
(230.62 ms)
VODAFONE xnetdns.xnet.ro
(IP: 193.230.161.3)
95.128.3.172
VODAFONE xnetdns2.xnet.ro
(IP: 193.230.161.4)
173.194.35.159
173.194.35.151
173.194.35.152