Categories: HackingSecurity

Syrian Electronic Army hacks into Facebook’s domain

The Syrian Electronic Army claimed Wednesday that it managed to hack into Facebook violating an administrator account of the Facebook’s Domain Registrar.

Syrian Electronic Army hit again, 2014 has started with the exploits of the popular group hackers that hit the giants of IT industry. Microsoft, PayPal, Ebay and also the CNN were hacked in the last month. This time the group has targeted Facebook website, also in this case the member of the Syrian Electronic Army claimed that they hacked an administrator account of the MarkMonitor, the Facebook’s Domain Registrar.

MarkMonitor Inc. is an American software company which develops software to protect corporate brands from illicit activities including fraud, piracy, counterfeiting and cybersquatting, it is the same domain registrar of Ebay/PayPal. MarkMonitor acquired AllDomains in 2001 and DtecNet in 2010, and it was itself acquired by Thomson-Reuters in 2012.

 

 

The Syrian Electronic Army modified the contact information for the Facebook Domain, referring to a Syrian email address on the company’s WHOIS domain information page. Fortunately the hackers failed to hijack the entire Facebook domain, in this case, the attack could have had very serious consequences, the hackers anyway claimed that they have tried to update the nameserver information, but the process had to be abandoned because it was “taking too much time…“.

Probably there are in place, I hope so, procedures to validate any changes to the records, for example, requesting a two-factor authentication to unlock the domain anyway requesting that any change to DNS settings have to be manually verified and authenticated.

If Syrian Electronic Army had succeeded in updating the nameserver record for Facebook, then the millions of users could have been impacted, they could have been redirected to a malicious website serving a malware or to a fake authentication page to capture the users’ credentials.

The Syrian Electronic Army has attacked Facebook because the company removed from its social network the pages managed by dissidents because they violate standards for permitted content, the decision of the company has caused the loss of important information about the conflict.

The deletion of Syrian opposition pages by Facebook removes important information regarding the evolution of the Syrian internal conflict. News regarding the revolution, detailed reportage and also information about the use of chemical weapons in the country.

Facebook has confirmed that no user has been impacted and that it hasn’t observed traffic hijacking.  At the time of writing  the registrar contact details were restored and the situation is normal.

Pierluigi Paganini

(Security Affairs –  Facebook, Syrian Electronic Army)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Silent Ransom Group targeting law firms, the FBI warns

FBI warns Silent Ransom Group has targeted U.S. law firms for 2 years using callback…

14 hours ago

Leader of Qakbot cybercrime network indicted in U.S. crackdown

The U.S. indicted Russian Rustam Gallyamov for leading the Qakbot botnet, which infected 700K+ devices…

19 hours ago

Operation RapTor led to the arrest of 270 dark web vendors and buyers

Law enforcement operation codenamed 'Operation RapTor' led to the arrest of 270 dark web vendors…

2 days ago

Chinese threat actors exploited Trimble Cityworks flaw to breach U.S. local government networks

A Chinese threat actor, tracked as UAT-6382, exploited a patched Trimble Cityworks flaw to deploy…

2 days ago

U.S. CISA adds a Samsung MagicINFO 9 Server flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Samsung MagicINFO 9 Server vulnerability to its…

2 days ago

New Signal update stops Windows from capturing user chats

Signal implements new screen security on Windows 11, blocking screenshots by default to protect user…

3 days ago