Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

Email Email  Print  Share


Where In The World Is Twitter's DNS?

Tags: , ,

Channel: Data Center, Networking & Mgmt, Data Protection

Twitter lost control of its DNS records on Dec. 17 for about an hour, but the effects lasted a bit longer due to DNS caching. While neither Twitter nor their registrar DynDNS, is saying much other than that the DNS records were changed at around 10pm PST, there has been ample speculation that the perpetrators got control of administrative credentials for twitter.com.

According to Rod Rasmussen, president and CTO of Internet Identity, a start-up developing a DNS monitoring service, the attackers appeared to be setting up a fast flux style technique to quickly change 'A' records, which map domain names to IP addresses. For www.twitter.com and twitter.com. Internet Identity noticed the first IP address change at 10:01 PST to an IP that was owned by Internap. Thirteen minutes later, at 10:13 PST, the A record changed  to an address hosted at Carolina Internet, and 10:24 the assignment was hosted at Bluehost. All three companies offer collocation and hosting services. By 11:11 PST, Twitter's A records were corrected. The attackers didn't try to alter name server records or make other changes. The attackers were able to change the A records of a number of hosts such as help.twitter.com, dev.twitter.com, blog.twitter.com, apiwiki.twitter.com to the first address hosted at Internap. A number of other hostnames under twitter.com were changed as well.

Internet Identity, which also monitors DNS information in caching name servers, found that the takeover of twitter.com's DNS started affecting Internet users around 21:57 PST and lasted until just after mid-night, indicating the attackers used short time-to-live settings. Most likely they didn't change Twitter's existing TTL. At least one host that twitter.com and www.twitter.com were changed to, Bluehost.com, is a virtual hosting provider that aggregates multiple hosts on a single server. It is unlikely that they will be able to determine if any of the hosts on that server were compromised, had the credentials stolen, or how the attackers hosted the defacement.

The lesson is that DNS is simultaneously fragile and resilient. DNS is vital to a company's presence on the Internet, yet the DNS system, which encompasses everything from the registrars like DynDNS, GoDaddy and Network Solutions,  to name servers of every stripe, is very fragile. There are many, many ways to subvert DNS but the saving grace is that when a well known domain is taken over, it's not long before someone notices and take action. Of course, it would be better if the domain couldn't be hijacked in the first place.

Related Stories

Related Reading


More data-center Insights



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers