republican-creole
site Search:


 
   
story category
Comcast Domain Hacked
Comcast Network Solutions Account Compromised?
by Karl Bode Thursday 29-May-2008 tags: business · trouble · Comcast
Starting late yesterday, Comcast users began noticing that Comcast.net had been hacked. More technically, early indications are that someone hacked Comcast's registrar account at Network Solutions, changing the authoritative DNS servers for Comcast.net -- rerouting portal visitors to IP addresses in Germany or elsewhere. Where once Comcast's portal sat, users were instead greeted with the following text (see screenshot):

KRYOGENICS Defiant and EBK RoXed Comcast
sHouTz to VIRUS Warlock elul21 coll1er seven

Click for full size
The problem is impacting user access to the Comcast portal, webmail (obviously) and the official Comcast forums. Though there's no indication that user privacy is jeopardized, you may want to avoid using Comcast webmail until things have been completely cleared up. Comcast tells us they're aware of the problem.

We believe that our registration information at the vendor that registers the Comcast.net domain address was altered, which redirected the site, and is the root cause of today's continued issues as well.
-Comcast Spokesman Charlie Douglas
"We are aware of the problem and working to get this resolved as quickly as possible," says one technician. "Our sincere apologies for any inconvenience this may be causing." According to the tech, Comcast DNS servers have been corrected, but it will take some time for the fix to propagate out to other servers.

"Depending on the TTL for those servers, this could take several hours and in rare cases, longer," he says. Several users tell me that when they called Comcast customer support, they were told that the outage was due to "routine maintenance."

I spoke with Comcast spokesman Charlie Douglas briefly about last night's events.

"Last night users attempting to access Comcast.net were temporarily redirected to another site by an unauthorized person," he says. "While that issue has been resolved and customers have continued to have access to the Internet and email through services like Outlook, some customers are currently not able to access Comcast.net or Webmail." Douglas says that network engineers continue to work on the issue.

"We believe that our registration information at the vendor that registers the Comcast.net domain address was altered, which redirected the site, and is the root cause of today's continued issues as well," he says. "We have alerted law enforcement authorities and are working in conjunction with them."

There's additional user discussion in our forums, where users have been talking about the hack overnight.

view: topics flat text 
Post a:
page: 1 · 2

Matt3
All noise, no signal.
Premium
join:2003-07-20
Jamestown, NC
kudos:12

NetSol Account Password?

I bet it was something easy to guess. My money is on p2psux0rz!

Tzale
Proud Libertarian Conservative
Premium
join:2004-01-06
NYC Metro

Re: NetSol Account Password?

said by Matt3:

I bet it was something easy to guess. My money is on p2psux0rz!
That is a hard password to crack.

spewak
R.I.P Dadkins
Premium
join:2001-08-07
Elk Grove, CA
kudos:1
Reviews:
·SureWest Internet

Hacker says what?

Well Johnny, you managed a pretty impressive hack at your young age. Now that's Comcastic!
Now if you could learn to spell, please?
sHouTz to VIRUS Warlock elul21 coll1er seven
--
The weekend is here, grab a can of beer!
BosstonesOwn

join:2002-12-15
Everett, MA

Re: Hacker says what?

said by spewak:

Well Johnny, you managed a pretty impressive hack at your young age. Now that's Comcastic!
Now if you could learn to spell, please?
sHouTz to VIRUS Warlock elul21 coll1er seven
Funny as your trying to be , think of all the folks who use that page as a default because comcast sets it during an install.

Now imagine had the folks been nasty and decided to throw a virii loaded page into the system instead of a simple message. You could have just had one of the biggest bot nets in history not to mention one with a huge network pipe.
--
"It's always funny until someone gets hurt......and then it's absolutely friggin' hysterical!"

FiL
Premium
join:2005-08-16
Silver Spring, MD

Re: Hacker says what?

I'm sure IF someone wanted to do that, it has already been done.

GilbertMark
Premium
join:2001-05-02
Gilbert, AZ
said by BosstonesOwn:

said by spewak:

Well Johnny, you managed a pretty impressive hack at your young age. Now that's Comcastic!
Now if you could learn to spell, please?
sHouTz to VIRUS Warlock elul21 coll1er seven
Funny as your trying to be , think of all the folks who use that page as a default because comcast sets it during an install.

Now imagine had the folks been nasty and decided to throw a virii loaded page into the system instead of a simple message. You could have just had one of the biggest bot nets in history not to mention one with a huge network pipe.
Assuming they are not using Macs...
Ulmo

join:2005-09-22
San Jose, CA
said by BosstonesOwn:

Now imagine had the folks been nasty and decided to throw a virii loaded page into the system instead of a simple message. You could have just had one of the biggest bot nets in history not to mention one with a huge network pipe.
In their charging and sentencing, it should well note what they did do and what they did not do. They did not do malicious things like the above. They did interrupt peoples' access to their telephone voicemails and email, as well as online billing system access for their accounts, which also could cause severe damage if their billing and payment timing was difficult.

nklb
Premium
join:2000-11-17
Ann Arbor, MI
kudos:2

Hack or Social Engineering?

I wonder if this is a true "hack" or just an example of good social engineering?
--
for all your Linux questions

elios

join:2005-11-15
Springfield, MO

Re: Hack or Social Engineering?

nether from the "message" posted
my bet is just hammered at it for days and brute forced the pass

ptrowski
Got Helix?
Premium
join:2005-03-14
Putnam, CT
kudos:4
Of course it was routine maintenance. That is the usual message that is put up, correct?

I also like how someone was told "the internet is down".

TraumaJunkie911

@comcast.net

Re: Hack or Social Engineering?

Could be that since most if not all maint. to a site/servers/etc. is performed at night, the employees were caught off guard like everyone else. They probably thought it was routine maint. and passed along the message.

Let's leave the black helicopters on the ground for now...

battleop

join:2005-09-28
00000
I would guess good social engineering combined with NetSol support drones that are in some call center on the other side of the world that does not know who Comcast is.

It's not that hard to get account information reset, it's most often a huge pain in the ass. I am sure someone will come up with more silly rules to make these changes.

One of the things I get stuck doing at work is helping move domains to our hosting. Some times the customer wants to move their domain registration as well. About 7 out of 10 domains I move the customer has no idea what the username/password is and the email address on the domain is very often an email address they have not had in years.

netsol tech

@ptd.net

Re: Hack or Social Engineering?

Bleh I doubt it was one of our people. Also i hate getting calls from people who don't have access to their account cause the info is old. It's a pain in the ass to tell them sorry but I can't modify your DNS cause your authorized. And please don't call us support drones. We work in a great place honestly for what we do but we get people who want to treat us like crap and well it just makes the rest of the day suck.

nc1165

join:2001-04-10
Delray Beach, FL
Any bets on disgruntled employee?

meister_sd
Premium
join:2006-01-29
La Mesa, CA
kudos:7

Re: Hack or Social Engineering?

That's my thought.

Hawken

@comcast.net
It was someone who hacked Comcast's email and got a change password request from NS, Comcast has admitted the fault.
axus

join:2001-06-18
Washington, DC

caught in a lie

It's no wonder that customer support is held in such low esteem. I wonder if this is what they were told to say, or they don't know so they made something up.

NetFixer
From my cold dead hands
Premium
join:2004-06-24
The Boro
Reviews:
·Comcast Business..
·Vonage
·Cingular Wireless
·Comcast

Re: caught in a lie

Denial of the existence of a problem and lying to a customer in general is and has always been the official Comcast policy.

It is not a surprise that this policy is still being practiced.
--
History does not long entrust the care of freedom to the weak or the timid.
-- Dwight D. Eisenhower
Test your firewall.
Smell the flowers.

CUBS_FAN
Next Year Again..

join:2005-04-28
Chicago, IL
kudos:1
Reviews:
·Vonage
·Comcast
·magicjack.com

AT&T don't work

At work on AT&T DSL I cant access anything from Comcast.net

»www.comcast.net is stuck in a constant flux of page reload... This is really messed up !

ztmike
Mark for moderation
Premium
join:2001-08-02
Michigan City, IN

Re: AT&T don't work

There is life outside of Comcast's web portal..
--
www.youtube.com/watch?v=mdYueIC1pjM

CUBS_FAN
Next Year Again..

join:2005-04-28
Chicago, IL
kudos:1

Re: AT&T don't work

But unfortunately all my personal info is stuck on their servers

33591094

join:2002-11-19
Canada

Re: AT&T don't work

said by CUBS_FAN:

But unfortunately all my personal info is stuck on their servers
It's on their servers, and you still think it's 'personal'?

lol

Remember, this is one of the worst ISP's ever we're talking about. It's THEIR data, now....

CUBS_FAN
Next Year Again..

join:2005-04-28
Chicago, IL
kudos:1

Re: AT&T don't work

It don't matter.. If there was any exposure it's all Comcast's fault. It's not like I was giving away my info and asking to be a victim of theft.
hottboiinnc
ME

join:2003-10-15
Cleveland, OH

Re: AT&T don't work

Nothing of that sort was done. The only thing that happened was the DNS for their Comcast.net domain was changed. If it would have been a hack on their customer service servers they would have known about it and been on top of it well before it was reported by a customer; or employee trying to check their email.

Linklist
Premium
join:2002-03-03
Longport, NJ
kudos:5
said by 33591094:

Remember, this is one of the worst ISP's ever we're talking about.
Not even close. Qwest ring any bells?

Cjaiceman
Premium,MVM
join:2004-10-12
Parker, CO
kudos:2

Re: AT&T don't work

said by Linklist:

said by 33591094:

Remember, this is one of the worst ISP's ever we're talking about.
Not even close. Qwest ring any bells?
I'll +1 to that! I'll take Comcast's BS over Qwest's any day.

LeftOfSanity
People Suck.

join:2005-11-06
Dover, DE
said by 33591094:

said by CUBS_FAN:

But unfortunately all my personal info is stuck on their servers
It's on their servers, and you still think it's 'personal'?

lol

Remember, this is one of the worst ISP's ever we're talking about. It's THEIR data, now....
Really?
--
Fighting on the Internet is like winning the Special Olympics. Win or lose, your still Retarted!

33591094

join:2002-11-19
Canada

Re: AT&T don't work

Yes.

Linklist
Premium
join:2002-03-03
Longport, NJ
kudos:5

Multipage thread on problem in BBR Comcast HSI forum

»Comcast hacked?

FicmanS
Premium
join:2005-01-11
Brownsburg, IN

"routine maintenance"

Right... Sure looks like it...lol

SolarPup
Hardware God
Premium
join:2002-03-07
Greeley, CO

Godaddy!

They should have gone with GoDaddy!

Hehe

@ssa.gov

"routine maintenance."?

I guess being hacked is routine for Comcast?

scrummie02
Bentley
Premium
join:2004-04-16
Arlington, VA

Something was happening yesterday

I was playing TF2 and my ping times were so high, like 365 on one server.

ztmike
Mark for moderation
Premium
join:2001-08-02
Michigan City, IN

Re: Something was happening yesterday

said by scrummie02:

I was playing TF2 and my ping times were so high, like 365 on one server.
This has nothing to do with your ping times.
--
www.youtube.com/watch?v=mdYueIC1pjM

Linklist
Premium
join:2002-03-03
Longport, NJ
kudos:5

1 edit

You can check Comcast email here

»m.comcast.net/signIn.jsp?redirec···List.jsp

Also, if you use a mail program like outlook express; Windows Mail; Thunderbird; Outlook; etc then Comcast email is working.

It is only the std web interface that isn't working.

Cabal
Premium
join:2007-01-21
Austin, TX
Reviews:
·Suddenlink

Re: You can check Comcast email here

No, this affected anything connecting to a *.comcast.net address via DNS. It has since been resolved, but DNS time-to-live adherence makes cleanup gradual.
--
Interested in open source engine management for your Subaru?

Linklist
Premium
join:2002-03-03
Longport, NJ
kudos:5

1 edit

Re: You can check Comcast email here

said by Cabal:

No, this affected anything connecting to a *.comcast.net address via DNS. It has since been resolved, but DNS time-to-live adherence makes cleanup gradual.
You are wrong. The above mobile interface does work. And the mail program interface also works.

Because the mobile DNS entry is different and doesn't end in comcast.net
05/29/08 10:21:38 dns m.comcast.net
Canonical name: portal.comcast.mobi
Aliases:
m.comcast.net
Addresses:
69.48.228.47
--
My BLOG .. .. Internet News .. .. My Web Page

espaeth
Digital Plumber
Premium,MVM
join:2001-04-21
Minneapolis, MN
kudos:2
Reviews:
·Vitelity VOIP

Re: You can check Comcast email here

said by Linklist:

said by Cabal:

No, this affected anything connecting to a *.comcast.net address via DNS. It has since been resolved, but DNS time-to-live adherence makes cleanup gradual.
You are wrong. The above mobile interface does work. And the mail program interface also works.
Actually, he's right.

The reason the main portal is having problems this morning is that it is getting more traffic right now than it's probably seen in the last 3 months combined. It's a separate "Digg Effect" occurring now which is different from the original issue last night.

Cjaiceman
Premium,MVM
join:2004-10-12
Parker, CO
kudos:2
said by Cabal:

No, this affected anything connecting to a *.comcast.net address via DNS. It has since been resolved, but DNS time-to-live adherence makes cleanup gradual.
Actually, I got to my businessclass.comcast.net just fine while the hack was going on. It never went down. Obviously though you couldn't check your regular mail from there, but *.comcast.net was not affected, from what I read and tried only www.comcast.net and mail.comcast.net domains were hurt by this. www6.comcast.net worked the whole time as well.

Linklist
Premium
join:2002-03-03
Longport, NJ
kudos:5

2 edits

You can access comcast.net main page this way

»login.comcast.net/login?s=portal···t.net/a/

Edit: Sometimes it works and sometimes it doesn't. Comcast system under stress.

This is also working sometimes:
»www6.comcast.net/a/

Harriet

@pacbell.net

Re: You can access comcast.net main page this way

Thanks so much for sharing your knowledge. What would the rest of us do without enlightened folks like you.
Mr Matt

join:2008-01-29
Eustis, FL
kudos:1
Reviews:
·CenturyLink
·Comcast
·Embarq Now Centu..

Kings of the Alibis

Every Cable company has a catalog of alibis.

1) I lost my broadband access and the modem would not connect. I called for service and the representative told me that my splitter had failed. When I stated that there nothing had changed since I installed the modem the representative said that sometimes happens. I decided to amuse myself while the representative delivered her speech. I replaced the splitter while I was talking to her. I advised her that the I had replaced the splitter and that did not solve the problem. She said that she would schedule a service call the next day. The problem fixed itself in about two hours.

2) I lost all of my cable services. I placed a service call and was advised that the problem was probably a cut drop. I had contacted some of my neighbors before placing the call and already knew that they had also lost cable service. When I brought that to the rep's attention I was advised that they did not have a report of an area outage. They would set up a service call for the next day. Within One Hour the problem fixed itself.

3) I lost all of my cable services and called for service. The representative indicated that the problem was probably a cut drop. I happened to look out the front window and saw a technician working a terminal on the other side of the street. When I brought that fact to their attention they seemed to be embarrassed. Within about ten minutes service was restored. I guess I have a self repairing drop.

The bottom line is that most cable companies will not roll a truck unless the problem affects a lot of customers. That is why I will not use their telephone service.

Anon459

@208.17.34.x

Re: Kings of the Alibis

Call center representatives are not technicians. They can't see the way your equipment is set up, they can't see your drop outside, they can't see the technician across the street. They can try to ping your modem or your cable box and go over general connections with you and that's about it. If pinging the equipment and double checking wires doesn't fix it, they need to send a truck. They can guess what the problem is, but it usually makes them look dumb...

And if you have no dial tone, the cable company sends a truck either that day or the next day. How are you going to say they only send a truck if it affects a lot of customers when, in 2/3 examples you used, an appointment was going to be setup for you the next day? The only reason they didn't setup an appointment in the last one is because you explained a tech was working on the wires... obviously if the wire is down for a tech to work on it you'll lose service until he restores the wire.
Mr Matt

join:2008-01-29
Eustis, FL
kudos:1
Reviews:
·CenturyLink
·Comcast
·Embarq Now Centu..

Re: Kings of the Alibis

I brought this situation up because even when I have confirmed that several other people in my neighborhood called and complained about losing service we were all advised that it was not an area outage. Everyone I called was given the same story. We would have to wait a day or two until our drop was repaired. I agree that the representative cannot see the connections in my home, but I have never had a splitter fail. I would much rather be advised that the problem is an area outage and the trouble should be cleared shortly if that is the case. I find it offensive to be told that I will have to wait one to two days for a technician to repair the drop serving my home when there is no problem with the drop.

La Luna
Survived Ashraful
Premium
join:2001-07-12
Warwick, NY
kudos:3
said by Mr Matt:

Every Cable company has a catalog of alibis.

1)....The problem fixed itself in about two hours.

2)....Within One Hour the problem fixed itself.

3)....Within about ten minutes service was restored....

All fixed in two hours, one hour and ten minutes, respectively....why would you even call that soon?
--
11,160 DEADLY TERROR ATTACKS SINCE 9/11~~TEAM DISCOVERY
Can't feel you anymore, don't need you anymore, don't believe you anymore, I don't need you anymore

XXcaLibeR

@starpt.org

Mess With The Best Die Like The Rest

Hackers Unite!

ptrowski
Got Helix?
Premium
join:2005-03-14
Putnam, CT
kudos:4

Re: Mess With The Best Die Like The Rest

said by XXcaLibeR :

Hackers Unite!
Oh yes, they were quite dead.
yaw

join:2004-05-19
Morgantown, WV

Nothing to see here...

It's an upgrape!

person852

@k12.il.us

Re: Nothing to see here...

said by yaw:

It's an upgrape!
It is Comcastic.

CUBS_FAN
Next Year Again..

join:2005-04-28
Chicago, IL
kudos:1
Reviews:
·Vonage
·Comcast
·magicjack.com

Still no official word..

I find it irritating that after all this time we STILL can't get any confirmation on our email accounts and if they were breached also. Do you have to change your email password from within Outook?

AnonProxy
Premium
join:2001-05-12

Re: Still no official word..

They did put an official statement in the e-mail they sent you...ohhh wait you are the guy that uses their webmail...wait a few days.

espaeth
Digital Plumber
Premium,MVM
join:2001-04-21
Minneapolis, MN
kudos:2
Reviews:
·Vitelity VOIP
said by CUBS_FAN:

I find it irritating that after all this time we STILL can't get any confirmation on our email accounts and if they were breached also. Do you have to change your email password from within Outook?
Have you ever received a phishing email that claimed it was from a bank, you click on the link and you end up at a site that looks very much like the bank site except the URL is wrong?

This was a similar deal here, only they didn't replicate the Comcast site on the new destination server -- they just put up a simple "This site has been hacked" announcement. As such, passwords for account management should not be compromised, nor would exclusive users of webmail have any problems. The only folks who would be at risk are those who keep a mail client running continuously that logs into the server to grab the mail. In that instance the hacked server could potentially have captured your pop3 login information as your client tried to log into the non-comcast mail server to retrieve your mail.

No to ESPN

@sbcglobal.net

Reality

Anyone who thinks that electronic systems are secure is either naive or stupid. What the hackers can not get to the guys who monitor the backdoors do. This is Reality 2008.

The answer is to stop using technology that can be hacked or monitored.

CUBS_FAN
Next Year Again..

join:2005-04-28
Chicago, IL
kudos:1

Re: Reality

said by No to ESPN :

The answer is to stop using technology that can be hacked or monitored.
This is the main reason why I won't touch internet banking and online bill payments with a 10 foot pole

anony101

@comcast.net

Re: Reality

said by CUBS_FAN:

said by No to ESPN :

The answer is to stop using technology that can be hacked or monitored.
This is the main reason why I won't touch internet banking and online bill payments with a 10 foot pole
Your house can be broken into. Does that mean you stopped living in one? Your wallet can be stolen along with your cash and credit cards. Does that mean you don't carry cash and credit cards? On-line services such as banking or bill pay are safe as long as you keep informed and follow basic precautions. Remember knowledge is power. The more you read the more informed you get the more you're able to protect yourself.

grapevine

@comcast.net

Re: Reality

Applied knowledge is power. Take what you know and put it to work.

fatmanskinny
Premium
join:2004-01-04
Wandering
Reviews:
·Comcast
·Comcast Digital ..

Comcast is Hacktastic

No system is immune. As long as your system is connected to the internet or let alone any network, it is potentially going to get hacked.

Even if your system is not connected to any other system, it may be hacked desk side by someone. Comcast just got their turn this go around.
--
The only place where Success comes before Work is in the dictionary.

tip

@comcast.net

comcast snafu

I thought little george had stuck his finger in the light socket again.

CallMeSilly

@comcast.net

approval from:
fruhead See Profile

Comcast Criminal Hack

I am not at all surpised to see only two or three intelligent posts and the rest all whiney anti-Comcast rubbish.

Regardless of how anyone feels about any ISP, let's see some true outrage against the hackers.

NotGonnaRegister

@comcast.net

Re: Comcast Criminal Hack

Outrage against the hackers?? For what??? Slapping comcast like they deserve to be?? The only time they admit anything is when they got, i.e p2p throttling....The rest of the time they are just lazy liars.

Jovi

join:2000-02-24
Mount Joy, PA
said by CallMeSilly :

I am not at all surpised to see only two or three intelligent posts and the rest all whiney anti-Comcast rubbish.

Regardless of how anyone feels about any ISP, let's see some true outrage against the hackers.
Do we truly know the hackers intentions? Could they be just pointing out an obvious flaw that was oblivious to Comcast? The incident could show Comcast a loophole that could be exploited and do real damage. Then the l33t h4ck3rz could be called h3r0z.
--
"Where's my coffee? Oh. I guess it's my turn to make it."
blackhat420

join:2008-05-24
Why would we outrage at the hackers???
Would you rather instead of some kids hacking it to get some notoriety a full blown hack was pulled off jacking comcast NOC /DATABASE information???

You should be thanking them that they did it first so it can be fixed.

Anyways they tried to warn the Comcast site admin once they got axx and he was all like stfu nubs. So yeah he had it coming. Blame the Douchebag admin who was too proud to listen to some kids.

Monday, 20-May 11:23:20 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.