Jump to content
Aerosol

Tesla Twitter account and website hijacked, Elon Musk pwned

Recommended Posts

Posted

Schizophrenic crims send Tesla claim calls to home of allegedly unconnected individual

peepee_1.jpg?x=648&y=429&crop=1

The website and Twitter account of carmaker Tesla were hacked over the weekend, as part of what looks like a prank between rival hackers.

Elon Musk’s personal Twitter account was also hijacked on Saturday night (US time) by miscreants who at one point claimed to be from the infamous Lizard Squad hacking crew. The name Autismsquad was also used in some of the captured website defacements, a crudely done collage.

Hackers were able to temporarily seize control after Tesla had its DNS hacked and MX (mail) and other records changed. Twitter passwords were then reset, with instructions on how to change login credentials sent to accounts under the control of hackers. It isn't clear how the DNS records were changed in the first place, but use of social engineering trickery to trick third parties into changing website names to IP address records has been a feature of similar hacks in the past.

@chf060 and @RooTworx, denied any connection with the breach, and said that miscreants had offered his home phone number as the number to call for the mythical free Tesla.

A good write-up of the attack as it unfolded can be found on the Transport Evolved blog here.

Lizard Squad are infamous for taking out XBox Live last Christmas in what turned out to be a promo for a short-lived DDoS-for-hire (AKA booter) cybercrime service. Taking over a website put up by any organisation is the equivalent of scrawling graffiti on a poster put up by a firm. Websites are commonly hosted by third parties and breaking into them, while undesirable, ought not be confused to hacking into a corporate network.

Redirecting surfers to a website under hacker control is rather more serious, because this sort of thing can easily be used to spread malware. There's no evidence as yet of this taking place in the case of the Tesla Motors hack.

Losing control of email accounts is serious, however, because it can allow hackers to get their hands on confidential information. Such data can be either leaked with the idea of causing maximum embarrassment for the pwned organisation, or used as collateral for attempted extortion.

Security commentary on the implications of the attack can be found in a post on BitDefenders' Hot for Security blog.

Source

Posted

Eu tot urlu în stânga ?i dreapta ce rol critic are un DNS într-o infrastructur? securizat?. Este la mâna unui copil s? fac? un phishing spre exemplu dac? î?i pui tu record-urile potrivite.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...