The Sony Pictures hack is getting all of the attention right about now, but it turns out that another prominent organization recently was victim to a security breach as well. Last month, ICANN, the outfit that regulates the internet’s domain names and IP addresses, fell prey to a phishing attack that tricked employees into giving out email login info. What’d the ne’er-do-wells get a hold of? Administrative access to all the files in the Centralized Zone Data System. Which, as The Register points out, granted the hackers access to unalterable generic zone files (what’re needed to resolve domain names to IP addresses), and gifted them with contact information for, among others, some of the world’s registry administrators. Passwords were stored as “salted cryptographic hashes,” but ICANN deactivated them as a precaution anyway. The firm’s wiki was breached too, but aside from public information, a members-only index page and one user’s profile, no other private data was viewed.
A few other areas were breached as well, like the organization’s blog and WHOIS page, but the company doesn’t seem too worried about those, saying neither…….
See full story on engadget.com
Image credit: AFP/Getty Images