Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →In November 2012, visitors trying to reach Romanian Google and Yahoo sites were reportedly redirected to a defaced page because DNS resolution for several Romanian domains had been altered. The contemporary account said Google and Yahoo themselves had not been hacked. A later Infoblox retrospective attributed the redirection to suspected DNS cache poisoning, but the available accounts do not establish the attackers’ identity or a definitive initial access method.
What happened to the Romanian domains?
SecurityWeek reported on November 28, 2012, that unknown attackers had changed DNS entries for a group of Romanian .ro domains. DNS is the system that translates a domain name, such as google.ro, into the network address of a server. If that mapping is changed, someone can enter the correct name and still be sent somewhere else.
The contemporary report listed these affected domains:
google.royahoo.romicrosoft.ropaypal.rokaspersky.rowindows.rohotmail.ro
SecurityWeek said Kaspersky Lab researcher Stefan Tanase observed google.ro and yahoo.ro resolving to a Dutch IP address. The report described the destination as a defaced webpage. It also said the Google Romania problem was fixed at about 13:00 GMT. Those details were observations reported by SecurityWeek from Tanase’s SecureList post, not a complete independently documented forensic timeline.
#1 Best Overall
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Were Google or Yahoo hacked?
The contemporaneous account explicitly said the websites themselves had not been hacked. The reported compromise was in the DNS resolution path: altered records caused requests for the Romanian domains to be directed away from their intended destinations. This distinction matters because a user can be misdirected without the destination company’s own web servers being breached.
Infoblox’s March 31, 2014 technical retrospective says the redirected traffic reached a hacked server in the Netherlands, identifying it as 95.128.3.172 and server1.joomlapartner.nl. Infoblox also said that server appeared compromised. This is the retrospective’s account; it does not establish that Google’s or Yahoo’s own systems were infiltrated.
Rank #2
- NIGHTHAWK WIFI 6 ROUTER FOR YOUR WHOLE HOME: Delivers fast, reliable WiFi across every room of your apartment or small home for streaming, gaming, video calls, and smart home devices, all running at the same time without slowing each other down.
- WORKS WITH YOUR EXISTING INTERNET SERVICE: Pairs with your existing modem or gateway via ethernet. Compatible with most cable, fiber, DSL, and satellite providers. Some gateways and modem router combos may require bridge mode. No coax needed.
- SET UP AND MANAGE YOUR NETWORK WITH THE NIGHTHAWK APP: Download the free Nighthawk app on iOS or Android for guided setup. Manage WiFi, run speed tests, pause devices, and set up guest networks from anywhere. Active internet required.
- READY FOR THE DEVICES YOU ALREADY OWN: Your phones, laptops, and TVs work right out of the box. WiFi 6 delivers speeds up to 1.8 Gbps across 2.4 GHz and 5 GHz bands. Backward compatible with WiFi 5 and earlier.
- COVERAGE IN EVERY ROOM: Covers up to 1,500 sq. ft. for up to 20 connected devices. Walls, floors, and interference can reduce range. Larger or multi-story homes may benefit from a NETGEAR Orbi mesh WiFi system.
What is known about the DNS mechanism?
SecurityWeek reported that, after researchers scanned Romanian domains, the only hijacked DNS entries they found were on Google Public DNS, at 8.8.8.8 and 8.8.4.4. That is a reported observation about where the entries appeared, not proof of how they got there.
Infoblox later assessed DNS cache poisoning as the likely mechanism. In cache poisoning, false DNS data enters a resolver’s cache; the resolver may then return the bad mapping to clients until the record is replaced or expires. Infoblox described poisoned records being passed along to other caching resolvers that relied on the affected resolver. This remains a retrospective hypothesis rather than a proven final incident finding.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- BUSINESS CYBERSECURITY SOLUTION: SafeBiz is an advanced cybersecurity solution that protects your work network and safeguards your Business data and all internet connected devices in your business from cyber threats and hackers. SafeHome blocks phishing, malware, ransomware, online scams and dark web threats.
- ADVANCED THREAT PREVENTION: SafeBiz includes a Next-Gen Firewall, DNS Security, Web Filtering, Dark Web Protection, Geo-fencing and other AI Powered cybersecurity features protecting your Business and Sensitive Data from internet threats and hackers.
- BUSINESS DATA & IDENTITY SECURITY: Safeguards your Official and financial data, protecting them from online theft and unauthorized access.
- EASY SETUP: Connects effortlessly to any existing wireless router or internet connection, setting up in minutes without the need for any changes to your Business internet connection.
- HIGH SPEED CONNECTIVITY: Supports an aggregate throughput of up-to 4.3 Gbps, maintaining high-speed browsing and streaming performance for up to 128 devices.
What has not been established?
- Initial access: SecurityWeek said it was not known how access to the DNS entry was obtained. Weak or compromised credentials and a registrar website vulnerability were mentioned as common possibilities, not confirmed causes.
- Attacker identity: The available accounts do not identify who carried out the redirection.
- Credential theft: The report describes a defacement page, not confirmed collection of passwords or other customer data.
- Full duration or user count: The sources do not establish the complete duration of the incident or how many people were affected.
- Chronology discrepancy: SecurityWeek’s contemporary report is dated November 28, 2012 and frames the event as occurring then. Infoblox’s 2014 retrospective dates it to November 27, 2013. The accounts conflict; the contemporary report supports describing it as the 2012 incident, while the discrepancy prevents treating the exact chronology as fully settled from these accounts alone.
Infoblox says the affected sites were restored shortly afterward and that no customer information was compromised. That impact statement comes from its later retrospective, rather than independent verification in the contemporary report.
Could this kind of redirection steal passwords?
It could, depending on where the user was sent and what protections remained in place. Tanase warned that a phishing destination could have been more harmful than a defacement page: “All this could have been much worse if the attacker had other goals in his mind than just becoming famous by defacing famous websites. Imagine how many accounts could have been compromised this morning if these websites were redirected to a phishing page, instead of a defacement page.” SecurityWeek reproduced that warning. It describes a possible consequence, not confirmed credential theft in this incident.
Rank #4
- Watchguard T145 Firebox with 3 Year Basic Security Suite License (WGT145033) - The Firebox T145 delivers enterprise-grade protection for branch offices and retail sites. With a blend of 2.5Gb, 1Gb, and SFP/SFP+ ports, it supports high throughput, AI-driven malware protection, and DNS filtering for robust network defense.
- The Basic Security Suite activates core protections on your Firebox, including intrusion prevention, gateway antivirus, URL filtering, and spam blocking in WatchGuard Cloud. Upgrade to Total Security Suite to add AI-powered malware detection, cloud sandboxing, DNS filtering, and advanced correlation.
- The Basic Security Suite equips your WatchGuard Firebox with a robust set of foundational security tools. This bundle delivers intrusion prevention, gateway antivirus, URL filtering, and spam blocking, all managed through WatchGuard Cloud. It’s a cost-effective choice for organizations that need reliable, essential protection without unnecessary extras.
- Interfaces and deployment: 2.5Gb and 1Gb Ethernet with SFP or SFP+ fiber for clean aggregation and segmented backhaul at the edge.
- Performance and scale: UTM up to 710 Mbps with inspection on; flexible VPN topologies for hub and spoke or mesh designs.
How can operators reduce DNS redirection risks?
Infoblox’s retrospective recommends several controls. They operate at different layers and are not substitutes for one another; the historical accounts do not document which protections the affected parties had deployed.
Protect DNS data and resolver caches
- DNSSEC: Sign DNS data and use validating resolvers so they can check that signed records are authentic and have not been altered in transit. It helps verify DNS data, but does not secure an account or server that is legitimately authorized to change records.
- Resolver hardening: Use source-port randomization and cryptographically secure random values to make forged responses harder to predict. Avoid insecure port address translation that defeats source-port randomization.
- Limit trust in upstream data: Avoid accepting excessive unrelated DNS records from upstream resolvers; unnecessary data can create additional opportunities for incorrect information to enter a cache.
- Keep DNS software current: Apply updates to resolver software to address known weaknesses.
Check the endpoint separately
Validate TLS certificates and the hostname when connecting to a site. TLS certificate validation helps determine whether the endpoint presents a certificate valid for the intended hostname; it addresses endpoint identity, not the authenticity of DNS records themselves. A browser warning should not be bypassed simply because the domain name in the address bar looks right.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- Watchguard T145 Firebox with 1 Year Total Security Suite License (WGT145641) - The Firebox T145 delivers enterprise-grade protection for branch offices and retail sites. With a blend of 2.5Gb, 1Gb, and SFP/SFP+ ports, it supports high throughput, AI-driven malware protection, and DNS filtering for robust network defense.
- The Total Security Suite is WatchGuard’s most comprehensive security package, bundling every advanced service into one subscription. It delivers layered defense with AI-driven malware detection, DNS filtering, cloud sandboxing, and security correlation. Ideal for organizations that demand maximum protection and visibility across their network.
- The Total Security Suite equips your WatchGuard Firebox with the full set of advanced defenses. It adds AI powered malware detection, DNS filtering, cloud sandboxing, threat correlation, and automated response, all managed in WatchGuard Cloud. Ideal for organizations that need maximum protection, compliance ready reporting, and end to end visibility.
- Interfaces and deployment: 2.5Gb and 1Gb Ethernet with SFP or SFP+ fiber for clean aggregation and segmented backhaul at the edge.
- Performance and scale: UTM up to 710 Mbps with inspection on; flexible VPN topologies for hub and spoke or mesh designs.
These are general operator measures drawn from Infoblox’s vendor-authored retrospective, which also promotes its products. They illustrate different ways to reduce or detect risk; they do not prove that any one measure would have prevented this particular event.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

