News: 1588744993

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Now we know what the P really stands for in PwC: X-rated ads plastered over derelict corner of accountants' website

(2020/05/06)


A forgotten subdomain on PricewaterhouseCoopers' dot-com has been hijacked to host ads for porno websites and apps, neatly demonstrating why you should not neglect your corporate DNS records.

Developer and security researcher Vitali Fedulov told The Register this week he has twice now found the pwc.com subdomain hosting a roster of X-rated adverts to lure netizens to online smut emporiums, X-rated apps, blogs, and adult-only chat rooms. The material also shows up in web searches.

The subdomain, amyca-devapi.pwc.com , has since been taken offline – it no longer resolves to an IP address – though its entries in Google remain for now:

[1]

Screenshot of the PwC subdomain showing up in Google hosting all kinds of over-18s material

Fedulov, who runs an [2]image search engine , said two times is too many for such a large accountancy firm serving government contracts.

"Since the company provides security services, including for governments, I believe it is time to share the incidents to the public," he said. "Also, because, from my communication with them, the company seems not interested in supporting the cyber-security community by, for example, offering a bug bounty rewards, the way other large companies do it."

While PwC declined to comment, both Fedulov and El Reg were able to figure out how the subdomain was commandeered and plastered with filthy ads.

The subdomain, when created by PwC, pointed to amyca-dev-node.azurewebsites.net , a custom Microsoft Azure subdomain created by the bean-counters to host some kind of API development system in the cloud. At some point, the accountancy goliath let its amyca-dev-node subdomain expire or lapse, allowing a miscreant to register it. When people, and search engine bots, visited amyca-devapi.pwc.com , they would be directed to the hacker-controlled amyca-dev-node.azurewebsites.net , which contained anything the miscreant wanted – in this case, a revolving set of risque ads.

In other words, there was no intrusion of the PwC network itself, or any other part of the dot-com site, just some DNS trickery and a forgotten Azure subdomain that someone swooped in and re-registered for themselves.

White-listing Azure cloud connections to grease your Office 365 wheels? About that... [3]READ MORE

To verify this, we turned to an infosec bod who [4]previously studied Azure subdomain takeovers, Numan Ozdemir of security firm Vullnerability. Ozdemir took a quick look at the situation, and confirmed that, indeed, the Azure namespace had been hijacked with what he referred to as "hacklinks."

In this case, Ozdemir explained, the miscreant was likely trying to use the reputation of PwC and its dot-com to game Google into ranking the linked-to smutty pages higher in search results, a particularly underhanded form of SEO.

"The subdomain tells Google, 'I am the PwC website,' which has a high domain authority for Google," Ozdemir told The Register . "So, Google will trust this hacklinked website and let you take a look."

Ozdemir also noted the miscreants had gone to some lengths to keep the caper under the radar, leaving a "coming soon" page by default on the Azure cloud subdomain, and only placing the naughty ads on separate pages – eg: amyca-dev-node.azurewebsites.net/my-example-awesome-adult-app.html . This allowed the miscreants to keep the naughty pages on the subdomain undetected for two or three months, a period of time needed to build credibility with Google.

"If you add a hacklink and if it just lives for two weeks on the website, Google will rate this as unexpected and it generally hurts your SEO score," he said.

Ozdemir added this is not a terribly uncommon occurrence. Other large entities, including major universities and government departments have similarly seen their forgotten subdomains and domains taken over and used to serve up pornography or worse.

It is, however, something that will put a dent in a company's prestige and trust.

Just as the smut-slinging hacker is benefiting from PwC's domain clout, the company could see its reputation suffer from being associated with these shady pages. The lesson here is: keep good DNS management records, assign people to maintaining them, and don't lose control of your subdomains. ®

Sponsored: [5]Choosing A Low-Code Vendor



[1] https://regmedia.co.uk/2020/05/06/screenshot_pwc_subdomain.jpg

[2] https://similar.pictures/about.html

[3] https://www.theregister.co.uk/2019/01/23/office_365_network_hole/

[4] https://www.theregister.co.uk/2020/03/04/microsoft_subdomain_takeover/

[5] https://go.theregister.co.uk/tl/1936/-8579/choosing-a-low-code-vendor?td=wptl1936

PwC

SuperGeek

Porn with Compromise?

Re: PwC

sanmigueelbeer

Porn, we come.

Re: PwC

Anonymous Coward

Problems with Clients might be more apt for PwC, given how many they have lost in the past year.

Re: PwC

JimboSmith

E&Y were my accountants for years then they did something dumb and pissed me off. They invoiced me after the VAT rate had gone back up to 20% despite having completed all the work well before that. When I was looking for another firm to replace them a mate warned me off PWC. Subsequently owing to a change in circumstances I didn't need such a large firm and a much smaller one deals with everything now.

Dave 126

In other news, theregister.co.uk served up ads for a scam company two days ago - one claiming that £800 iPhones are surplus stock and must be sold for £89.

This isn't the Reg's usual policy, so assuming it slipped through the net at this time when people's minds may understandably be on other things.

Joe Drunk

El Reg most likely don't serve the ads themselves but, as is the case with practically every website that serves ads, relies on a third party and therefore have little to no control over what ads are shown on this site.

As I block all content I deem of no use to me I never saw the £89 iPhones or any other exciting offers from anywhere else on the internet.

Franklin

The domain amyca-dev-node.azurewebsites.net now has a Web page that says "Comming Soon." Not sure if it was placed there by the miscreants or by PwC, but somebody certainly can't spell!

"somebody certainly can't spell!"

Jedit

Indeed. It's supposed to be "cumming".

(Mine's the dirty rainmac.)

Really?

tiggity

"something that will put a dent in a company's prestige and trust."

In what universe do people regard PWC as trustworthy & prestigious?

All the big bean counters have plenty of past history of being asleep at the wheel / turning a blind eye (depending if you regard it as a mistake or deliberate to keep the money rolling in) and missing major issues when auditing companies

Re: Really?

IGotOut

In what universe do people regard PWC as "trustworthy & prestigious?"

The same one where Gartner's "Magic Quadrant" is seen as guide to who you should spend your money with.

Re: Really?

Fred Dibnah

"...the company could see its reputation suffer from being associated with these shady pages..."

I agree, if I ran a porn company I wouldn't want to have anything to do with PWC.

Re: missing major issues when auditing companies

Anonymous Coward

"missing major issues" is a bit of an understatement. But hey, great tactic, applied across the financial sector: if major crime is uncovered (unlikely, but we're all humans, eh), this or that reputable business blames a "rogue employee", strikes a deal with a gov, denies liability, pays a nominal fine, carries on merrily. Quietly making sure new leaks are that much likely.

I don’t understand...

Anonymous Coward

...how this was actually done. I’ve registered many domains and all the sub-domains belong to me, as far as I am aware.

It’s up to me if I activate any sub-domains. How can any other entity go to a registrar and register one of my sub-domains, ergo at whatever.pwc.com ?

Thanks for any enlightenment!

Re: I don’t understand...

JimboSmith

Thanks for any enlightenment!

That answer is in the article

The subdomain, when created by PwC, pointed to amyca-dev-node.azurewebsites.net, a custom Microsoft Azure subdomain created by the bean-counters to host some kind of API development system in the cloud. At some point, the accountancy goliath let its amyca-dev-node subdomain expire or lapse, allowing a miscreant to register it. When people, and search engine bots, visited amyca-devapi.pwc.com, they would be directed to the hacker-controlled amyca-dev-node.azurewebsites.net, which contained anything the miscreant wanted – in this case, a revolving set of risque ads.

In other words, there was no intrusion of the PwC network itself, or any other part of the dot-com site, just some DNS trickery and a forgotten Azure subdomain that someone swooped in and re-registered for themselves.

Hope that clears things up for you.

Re: I don’t understand...

Alister

Hope that clears things up for you.

Not really. You don't, as a rule, "register" subdomains in any way, and therefore they can't expire or lapse unless the root domain does.

You register a domain with a Registrar, and then you create subdomains by adding A (or AAAA) records in the DNS.

the accountancy goliath let its amyca-dev-node subdomain expire or lapse, allowing a miscreant to register it

This bit is total bollocks.

I've seen similar..

Anonymous Coward

With AWS buckets, got more fun as it was serving JavaScript files for an analytics company.. Including to login pages. Oh the fun to be had with that one. Small mercies that they just stuck with nerferious smut rather than more insidious scripting.

Anon because I'm not saying "who's" website was compromised (fnar, fnar) like this...

If there is a wrong way to do something, then someone will do it.
-- Edward A. Murphy Jr.