<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: TCS official website hacked</title>
	<atom:link href="http://devilsworkshop.org/tcs-official-website-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://devilsworkshop.org/tcs-official-website-hacked/</link>
	<description></description>
	<lastBuildDate>Sat, 11 Feb 2012 09:22:05 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: GuJJu</title>
		<link>http://devilsworkshop.org/tcs-official-website-hacked/#comment-200081</link>
		<dc:creator>GuJJu</dc:creator>
		<pubDate>Sat, 23 Oct 2010 04:12:06 +0000</pubDate>
		<guid isPermaLink="false">http://devilsworkshop.org/?p=19941#comment-200081</guid>
		<description>The site is back on its road i think so friend.</description>
		<content:encoded><![CDATA[<p>The site is back on its road i think so friend.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sitaram Chamarty</title>
		<link>http://devilsworkshop.org/tcs-official-website-hacked/#comment-140084</link>
		<dc:creator>Sitaram Chamarty</dc:creator>
		<pubDate>Tue, 09 Feb 2010 10:40:31 +0000</pubDate>
		<guid isPermaLink="false">http://devilsworkshop.org/?p=19941#comment-140084</guid>
		<description>@mary:

try this google search http://www.google.co.in/search?q=but+the+reverse+is+vm2k3-web5.mgt.hosting.dc2.netsol.com&amp;hl=en&amp;filter=0

you&#039;ll get about 160 hits, each containing some domain that was discovered to point to the same IP that tcs.com was directed to at that time.

Now add in the fact that this is only for vm2k3-web5 (whatever that means!) under dc2 (presumably some cluster in the DC area) and speculate how many more will turn up if you try other combinations of numbers, locations (ny, la, etc).

Count all of those and you&#039;ve got your answer...

my 2 cents... :)</description>
		<content:encoded><![CDATA[<p>@mary:</p>
<p>try this google search <a href="http://www.google.co.in/search?q=but+the+reverse+is+vm2k3-web5.mgt.hosting.dc2.netsol.com&#038;hl=en&#038;filter=0" rel="nofollow">http://www.google.co.in/search?q=but+the+reverse+is+vm2k3-web5.mgt.hosting.dc2.netsol.com&#038;hl=en&#038;filter=0</a></p>
<p>you&#8217;ll get about 160 hits, each containing some domain that was discovered to point to the same IP that tcs.com was directed to at that time.</p>
<p>Now add in the fact that this is only for vm2k3-web5 (whatever that means!) under dc2 (presumably some cluster in the DC area) and speculate how many more will turn up if you try other combinations of numbers, locations (ny, la, etc).</p>
<p>Count all of those and you&#8217;ve got your answer&#8230;</p>
<p>my 2 cents&#8230; <img src='http://devilsworkshop.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mary</title>
		<link>http://devilsworkshop.org/tcs-official-website-hacked/#comment-140053</link>
		<dc:creator>mary</dc:creator>
		<pubDate>Tue, 09 Feb 2010 05:52:33 +0000</pubDate>
		<guid isPermaLink="false">http://devilsworkshop.org/?p=19941#comment-140053</guid>
		<description>While it is obvious that this was a DNS redirect and not a website hack per se, what is not clear is why was TCS singled out for this attack. After all, whoever hacked NetSol&#039;s DNS server could have wreaked havoc on many more domain names.</description>
		<content:encoded><![CDATA[<p>While it is obvious that this was a DNS redirect and not a website hack per se, what is not clear is why was TCS singled out for this attack. After all, whoever hacked NetSol&#8217;s DNS server could have wreaked havoc on many more domain names.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: akshay</title>
		<link>http://devilsworkshop.org/tcs-official-website-hacked/#comment-140007</link>
		<dc:creator>akshay</dc:creator>
		<pubDate>Mon, 08 Feb 2010 20:59:33 +0000</pubDate>
		<guid isPermaLink="false">http://devilsworkshop.org/?p=19941#comment-140007</guid>
		<description>whatever may be the reason , this should not have happened for the india&#039;s largest IT company</description>
		<content:encoded><![CDATA[<p>whatever may be the reason , this should not have happened for the india&#8217;s largest IT company</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tata Consultancy Services (TCS) Site Hacked</title>
		<link>http://devilsworkshop.org/tcs-official-website-hacked/#comment-139992</link>
		<dc:creator>Tata Consultancy Services (TCS) Site Hacked</dc:creator>
		<pubDate>Mon, 08 Feb 2010 18:15:45 +0000</pubDate>
		<guid isPermaLink="false">http://devilsworkshop.org/?p=19941#comment-139992</guid>
		<description>[...] then an TCS employee commented on his blog that tcs.com was not hacked. What did happen was that the DNS records that supply the [...]</description>
		<content:encoded><![CDATA[<p>[...] then an TCS employee commented on his blog that tcs.com was not hacked. What did happen was that the DNS records that supply the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bggopal</title>
		<link>http://devilsworkshop.org/tcs-official-website-hacked/#comment-139983</link>
		<dc:creator>bggopal</dc:creator>
		<pubDate>Mon, 08 Feb 2010 16:54:38 +0000</pubDate>
		<guid isPermaLink="false">http://devilsworkshop.org/?p=19941#comment-139983</guid>
		<description>The site is back and running now.. I wonder what would be the next Target..</description>
		<content:encoded><![CDATA[<p>The site is back and running now.. I wonder what would be the next Target..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Srini K</title>
		<link>http://devilsworkshop.org/tcs-official-website-hacked/#comment-139959</link>
		<dc:creator>Srini K</dc:creator>
		<pubDate>Mon, 08 Feb 2010 12:49:59 +0000</pubDate>
		<guid isPermaLink="false">http://devilsworkshop.org/?p=19941#comment-139959</guid>
		<description>Thanks 4 d info. We were really confused about it. Now pretty clear :)</description>
		<content:encoded><![CDATA[<p>Thanks 4 d info. We were really confused about it. Now pretty clear <img src='http://devilsworkshop.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aditya Kane</title>
		<link>http://devilsworkshop.org/tcs-official-website-hacked/#comment-139946</link>
		<dc:creator>Aditya Kane</dc:creator>
		<pubDate>Mon, 08 Feb 2010 11:06:24 +0000</pubDate>
		<guid isPermaLink="false">http://devilsworkshop.org/?p=19941#comment-139946</guid>
		<description>&lt;strong&gt;@Sitaram:&lt;/strong&gt; Thanks for the input and great insights. As vivek said, makes the post complete.</description>
		<content:encoded><![CDATA[<p><strong>@Sitaram:</strong> Thanks for the input and great insights. As vivek said, makes the post complete.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vivek jain</title>
		<link>http://devilsworkshop.org/tcs-official-website-hacked/#comment-139915</link>
		<dc:creator>vivek jain</dc:creator>
		<pubDate>Mon, 08 Feb 2010 07:28:14 +0000</pubDate>
		<guid isPermaLink="false">http://devilsworkshop.org/?p=19941#comment-139915</guid>
		<description>@sitaram
Thanks Sitaram. This detailed info has completed the post now :-)</description>
		<content:encoded><![CDATA[<p>@sitaram<br />
Thanks Sitaram. This detailed info has completed the post now <img src='http://devilsworkshop.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sitaram Chamarty</title>
		<link>http://devilsworkshop.org/tcs-official-website-hacked/#comment-139886</link>
		<dc:creator>Sitaram Chamarty</dc:creator>
		<pubDate>Mon, 08 Feb 2010 04:04:05 +0000</pubDate>
		<guid isPermaLink="false">http://devilsworkshop.org/?p=19941#comment-139886</guid>
		<description>[Disclaimer: I&#039;m an employee of TCS, though I&#039;m posting this in my personal capacity]

tcs.com was not hacked.  What did happen was that the DNS records that supply the IP were reset to some other IP.

Whether that was done by actually hacking tracom/netsol or by social engineering a valid change request I do not know.

I know the site was fine because going through the internal DNS got me the correct IP address and the correct content.

I believe the problem started sometime before 1am IST [this is a wild guess, from other symptoms], and was resolved around noon or so [this guess is more accurate because I was semi-actively monitoring it].

In both instances, it would have taken a few hours for the bad data to expire from DNS caches.  Depending on who your DNS provider is, you may have seen it &quot;come back&quot; at different times.  If you were running your own DNS, you could have purged your DNS cache manually and would know more accurately when it came back (or just run a &quot;dig +trace&quot; at 10-minute intervals looking for the right IP to come back)

Regards,

Sitaram</description>
		<content:encoded><![CDATA[<p>[Disclaimer: I'm an employee of TCS, though I'm posting this in my personal capacity]</p>
<p>tcs.com was not hacked.  What did happen was that the DNS records that supply the IP were reset to some other IP.</p>
<p>Whether that was done by actually hacking tracom/netsol or by social engineering a valid change request I do not know.</p>
<p>I know the site was fine because going through the internal DNS got me the correct IP address and the correct content.</p>
<p>I believe the problem started sometime before 1am IST [this is a wild guess, from other symptoms], and was resolved around noon or so [this guess is more accurate because I was semi-actively monitoring it].</p>
<p>In both instances, it would have taken a few hours for the bad data to expire from DNS caches.  Depending on who your DNS provider is, you may have seen it &#8220;come back&#8221; at different times.  If you were running your own DNS, you could have purged your DNS cache manually and would know more accurately when it came back (or just run a &#8220;dig +trace&#8221; at 10-minute intervals looking for the right IP to come back)</p>
<p>Regards,</p>
<p>Sitaram</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced
Database Caching 7/14 queries in 0.007 seconds using apc
Object Caching 409/415 objects using apc

Served from: devilsworkshop.org @ 2012-02-12 00:43:52 -->
