Telkom Mail Site

I got this yesterday for other tekomsa.net sites (e.g. customerportal.telkomsa.net).

It looks like someone had hijacked the NS records for telkomsa.net.

I also received an SMS about a phishing attempt, and I wonder if the DNS hijacking was related.

I am in the middle of DSL to Fibre migration, and this seems to have contributed to breaking my account.

Currently, DNS lookups for webmail.telkomsa.net return the current records for me:
$ dig +noall +answer webmail.telkomsa.net
webmail.telkomsa.net. 442 IN A 105.224.1.14
$ dig +noall +answer telkomsa.net NS
telkomsa.net. 32924 IN NS ns2.telkomsa.net.
telkomsa.net. 32924 IN NS ns1.telkomsa.net.

Yesterday, the NS records were wrong.

It may be that some caching DNS servers still have stale records from yesterday.
 
^^ Got the phishing warning SMS today. Just logged into webmail site now - couldn't reach server earlier.
 
Top
Sign up to the MyBroadband newsletter
X