8 ms·
Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility
- unreal37 13y agoWhoa. Twitter, NYTimes, HuffPo... all had their DNS records hacked? This seems huge.
- icpmacdo 13y agoHow difficult of a thing is this to pull off?
- cheald 13y agoIf you can compromise a shared registrar, pretty trivial.
- eli 13y agoWell, the "attacking multiple sites at once" is trivial. The "compromising a major registry" is at least supposed to be kinda hard.
- 16s 13y agoYou'd have to have the ability to change DNS records for their domains. If you can point "whatever.com" to a NS that you control, it's game over until they take it back.
- aet 13y agoTwitter is up. I still can't get NYT - down for over a day? wow
- dimitar 13y agoWhy hasn't the SEA changed the nameservers?
- InclinedPlane 13y agoDNSSEC most likely.
- fotcorn 13y agoNameservers of nytimes.com and twimg.com are changed: Name Server.......... ns27.boxsecured.com Name Server.......... ns28.boxsecured.com
- jeremycole 13y agotwimg.com seems to be hijacked
- ikawe 13y agoA status update now that it's fixed. http://status.twitter.com/post/59528478030/twitter-service-issue http://status.twitter.com/post/59528478030/twitter-service-i.... Kind of dodgy that there was no status update until 1.5 hours after the issue surfaced.
- bluetidepro 13y agoAs someone asked in the comments of the article asked (no response yet), I'm curious myself... > "twimg.com is a domain used by Twitter which is an widget company that is part of a network of sites, cookies, and other technologies used to track you, what you do and what you click on, as you go from site to site, surfing the Web. Does that not mean that SEA will be intercepting this data?"
- fotcorn 13y agoThe tweet button/widget is served by http://platform.twitter.com http://platform.twitter.com so this shouldn't be a problem as long as the twitter.com nameservers are unchanged.
- emil10001 13y agoCouldn't they do this with any of the sites that they modify? That's what I am sort of wondering about, sure you could redirect the homepage to something dumb, and make it really obvious that the site has been attacked. But, it seems like they could have similarly done a man-in-the-middle and sucked up tons of data silently, without throwing up any big red flags.
- grumps 13y agoHow hard is this to do... I ask because I find it harder to believe that they are responsible for this. Just like I don't trust the YouTube videos either. I would find it more likely that three letter agencies are involved as PR.
- pseudometa 13y agoI don't buy it either. Seems fishy.
- mpyne 13y agoFishy enough that the SEA's own Twitter account is gloating about it?
- jacquesm 13y agoFortunately it's really hard to make a Twitter account, what with all the passport checks and ID verification that goes on there. Only real, verified SEA members would be able to create such an account. And only when directly logging in from a verified Syrian government IP.
- mpyne 13y agoGo check the account [1] for yourself, if it's fake it's a long-planted fake strung along with other tweets dating back to August 15th and earlier and describing other known SEA hacks. If it's not legit it would have to be because they let their own Twitter account get hacked at the same time Twitter was being hacked... which seems very noncompliant with Occam. [1] https://twitter.com/Official_SEA16 https://twitter.com/Official_SEA16
- deleted 13y ago[deleted]
- pain_perdu 13y agoDNS Records have been hijacked and point to Syrian Electronic Army http://i.imgur.com/RwH0mpI.png http://i.imgur.com/RwH0mpI.png
- ninjazee124 13y agoNYTimes seems to be down and Twitter is be loading all wrong because twimg.com is down. Whoa! This is some serious stuff.
- mhurron 13y agohttp://xkcd.com/932/ http://xkcd.com/932/ Ya, not so much.
- fotcorn 13y agoThe twitter frontpage is completly broken for me. Static assets like css and javascript are served by twimg.com, which are now missing. If SEA has access to a server which can take the load of twimg.com, they can inject their Javascript and possible exploits to ALL twitter users...
- bpicolo 13y agoSeems fine now
- signed0 13y agoWoah! Has Verisign been hacked? $ whois twitter.com Whois Server Version 2.0 Domain names in the .com and .net domains can now be registered with many different competing registrars. Go to http://www.internic.net http://www.internic.net for detailed information. TWITTER.COM.GET.ONE.MILLION.DOLLARS.AT.WWW.UNIMUNDI.COM TWITTER.COM And then: $ whois verisign.com Whois Server Version 2.0 Domain names in the .com and .net domains can now be registered with many different competing registrars. Go to http://www.internic.net http://www.internic.net for detailed information. VERISIGN.COM.MIGHT.SUCK.FYRAE.COM VERISIGN.COM I get really crazy responses like this for almost every major site I try (cnn.com, yahoo.com, google.com).
- lampooned 13y agoFacebook's whois result is pretty funny. $ whois facebook.com Whois Server Version 2.0 Server Name: FACEBOOK.COM.ZZZZZ.GET.LAID.AT.WWW.SWINGINGCOMMUNITY.COM IP Address: 69.41.185.229 Registrar: TUCOWS DOMAINS INC. Whois Server: whois.tucows.com Referral URL: http://domainhelp.opensrs.net
- dobbsbob 13y agoI never use CA's so didn't notice this, I only use the twitter app which Moxie Marlinspike and Charlie Miller hardened with pinned certs to avoid all authorities Also this: http://stackoverflow.com/questions/4415269/suspicious-results-internic-whois-query http://stackoverflow.com/questions/4415269/suspicious-result...
- arn 13y agono. VERISIGN.COM.MIGHT.SUCK.FYRAE.COM is a subdomain of FYRAE.com See this: https://news.ycombinator.com/item?id=6204867 https://news.ycombinator.com/item?id=6204867
- InclinedPlane 13y agowhois twitter.com => whois(".*twitter\.com.*")
- dobbsbob 13y agoUS is about to bomb Syrian military assets so this is Iran's response. The SEA is clearly Iranian. Email them something in Farsi or PM one of their propaganda accounts on youtube they usually answer. last time I checked ns1.syrianelectronicarmy.com was hosted out of Russia and includes " qatar-leaks.com" which seems to have disappeared
- 15charusername 13y agoWhy Iran? Surely Russia is a bigger suspect, but right now, my biggest suspect would be the NSA/CIA, the timing of the Syrian escalation is just too perfect.
- eshvk 13y agoWhy is Russia a bigger suspect? A study of foreign policy and defence would appear to suggest that Iran perceives that it is under threat of invasion from America.
- bandushrew 13y agoIf I seriously believed I was under actual threat of invasion from the US, I am not sure I would piss away my resources getting monkeys to deface a brochure.
- pseudometa 13y agoDusting off my tin foil hat, I would go with Israel in collusion with the NSA/CIA. They have the most to gain by turning the media against Syria and the technical capabilities as proven with their involvement in stuxnet. http://en.wikipedia.org/wiki/Stuxnet http://en.wikipedia.org/wiki/Stuxnet
- wavesounds 13y agoYou think that Israel wants a war with Syria? Syria could easily turn those chemical weapons across its border. I think Isreal is probably one of the big factors causing US restraint right now. But my tin-foil hat hasn't been working very well lately so the government radio signals may be blocking me from seeing something.
- InclinedPlane 13y agoLast update on status.twitter.com was August 6th. Get your shit together guys, this is serious business. Edit: looks like there's an update now: http://status.twitter.com/post/59528478030/twitter-service-issue http://status.twitter.com/post/59528478030/twitter-service-i...
- flaktrak 13y agothis is about all the Syrian govt can retaliate with. it's not like they can physically reach and stop the USA from attacking them.
- deleted 13y ago[deleted]
- jacquesm 13y ago> reustle wrote: > Here's what I get for whois google.com > GOOGLE.COM.ZZZZZZZZZZZZZZZZZZZZZZZZZZ.HAVENDATA.COM > ... > GOOGLE.COM.AFRICANBATS.ORG GOOGLE.COM > And Microsoft > MICROSOFT.COM.ZZZZZZZZZZZZZZZZZZZZZZ.IS.A.GREAT.COMPANY.ITREBAL.COM > ... > MICROSOFT.COM.ARE.GODDAMN.PIGFUCKERS.NET.NS-NOT-IN-SERVICE.COM MICROSOFT.COM Don't be silly. You're simply getting everything that starts with microsoft.com. So for the first microsoft example that's itrebal.com, they can issue subdomains as many as they want or publish records for subdomains which in turn will cause the whois commands to cough up that information. It assumes that you are searching for some info and helpfully includes everything that it thinks might be applicable. This trick will give you results for almost any well known domain name and is not indicative of a hack, merely of a slight shortcoming in the way whois records are displayed / queries, the default is a non-exact match. They're not hacks, they are pranks. Try this: whois -h whois.tucows.com microsoft.com If you're not convinced by the above.
- eli 13y agoI believe the trick is to also register the subdomain as an NS server. But yeah, not a hack.
- eli 13y agoI'm pretty sure that's unrelated and not a problem. Look at those domain names carefully -- they're not actually at google or microsoft. It's just people exploiting how wildcard search feature works.
- Questionoor 13y agoSEA has a history of doing much more than attempting to offset perceived propaganda[1]. With in that site is dozens of gigabytes of logs from Bluecoat[2] proxy hardware that sat in datacenters for Syrian ISPs. A good amount of what is contained in the logs is things like porn searches, more porn, porn. But amongst the typical naughty bits things like religious queries for Christians, Catholics, Jews, Muslims were being recorded. Telecomix[3] helped to leak the log-set, and as it stands it is _the_ example of how state entities monitor peoples of 'interest.' Much of these people are long since dead, killed early on as they were the most public[4]. So while the SEA's most public facing events are hijacks, phising, and massive redirects. Please do focus on the end result of pervasive surveillance[5]. [1] http://bluesmote.com/ http://bluesmote.com/ [2] http://www.bluecoat.com/ http://www.bluecoat.com/ [3] http://en.wikipedia.org/wiki/Telecomix http://en.wikipedia.org/wiki/Telecomix [4] http://en.wikipedia.org/wiki/Ibrahim_Qashoush http://en.wikipedia.org/wiki/Ibrahim_Qashoush [5] http://imgur.com/gallery/qz7wm http://imgur.com/gallery/qz7wm
- ballard 13y agoMakes you wonder whom has access to Palantir.
- jval 13y agoOk, firstly whois Microsoft.com just returns all URLs with Microsoft.com in them, even as a subdomain, so they haven't been hacked and that result has been there for ages. Same goes for Verisign etc. TechCrunch is reporting that registrar MelbourneIT has been hacked.. This wouldn't surprise me but I'm puzzled as to why either site would register with such a bad registrar.
- joshfraser 13y agoWhat do you mean? MelbourneIT are huge and generally have a pretty decent reputation.
- devopstom 13y agoHad. Until now.
- jbarham 13y ago> MelbourneIT are huge and generally have a pretty decent reputation. Clearly you have never used their ticketing system.
- jussij 13y agoI can vouch for that. From my experience this is how it their tech support works. You raise and issue and they give you a ticket to track the issue. They then send you an e-mail asking for more details. You reply with the details and then they send you another e-mail saying the issue has been escalated. A little while later you get another e-mail asking for the exact same details as the first e-mail, so you send them the same details. You then get another e-mail saying this issue has been escalated. Guess what happens next. You guessed it, they send yet another e-mail asking for the exact same details you have now provided on two occasions. They bounce you around in an infinite loop with a continual stream of spam e-mails until you finally get fed up and close the ticket.
- jval 13y agoYeah, you're right that was probably a bit harsh given that I'm just running from what I've heard from others, and the fact that last year they were still charging $150 for registration. But who am I to know - I don't want to be one of those token HN trolls who pays out on people for the sake of it so I retract my initial comment.
- nfoz 13y agoDon't trust anything you read here, folks...... too many that don't know anything about WHOIS or DNS.....
- Helianthus 13y agoNow the truly paranoid are caught in the paradox of trusting you!
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- N0RMAN 13y agothe traceroute for twimg.com end's in russia, I'm right? (141.105.64.37)
- mehmehshoe 13y agoYup. The biggest fallout from this won't be that those big sites were down for hours, it will be the millions of computers that redirected to that IP. http://blog.opendns.com/2013/08/27/high-profile-domains-under-siege/ http://blog.opendns.com/2013/08/27/high-profile-domains-unde...
- Questionoor 13y agoFor those want to take a look at the more internal efforts of the SEA, here are some logs[1] obtained from a leaked set thanks to Telecomix[2]. The snippet of logs is from a voluminous set. A mere sample[3]: BlueCoat Helps Assad/SEA Track Homosexuals: 2011-07-22 20:34:53 14 dee58fa2188103d6 - - - OBSERVED "unavailable" videogayz.com/ 200 TCP_HIT 6 Jul from web BlueCoat Logs from Assad/SEA Hardware Tracks MSN: 2011-07-22 20:34:53 35850 0cb611eeb0ef8c6e - - - PROXIED "unavailable" by2msg4030114.gateway.messenger.liv… 6 Jul from web BlueCoat Logs Show Assad/SEA Is Totally Secular, Tracks Religious Followers: 2011-07-22 20:34:52 166 7cc423995fff7f92 - - - OBSERVED "unavailable" www.syrianoz.com/news/kamishly/chur… 6 Jul from web [1] http://bluesmote.com/ http://bluesmote.com/ [2] http://en.wikipedia.org/wiki/Telecomix http://en.wikipedia.org/wiki/Telecomix [3] http://pastie.org/private/mxgzj4u6y52dsgzudtsg http://pastie.org/private/mxgzj4u6y52dsgzudtsg
- Shank 13y agoWhile they may have fixed twimg.com on the DNS level, changes are still taking forver to propogate back out. Right now I'm still getting no data from it. To add to the matter, SEA is certainly aware of this: "So, do we host http://twimg.com http://twimg.com with Javascript code so all Twitter users will be redirect to our website? #SEA" https://twitter.com/Official_SEA16/status/372496956020379648 https://twitter.com/Official_SEA16/status/372496956020379648
- cpursley 13y ago"We are protecting you from the hacker-terrorists" Is this not obvious to everyone else as it is to me? People, think about what is happening here and the timing of it all. This is a false flag operation to turn the public opinion against "hackers" so these crazy internet regulations bills can start passing and so that they can get away with spying scandal. If these "hackers" taking down social media sites and NYT times were actually the Syrian government, they'd be going after US government targets in an effort to undermine the bombing that's about to begin. Their regime is about to get bombed. Taking down twitter is low on their priority list. But it's quite good timing for a propaganda campaign against "hackers" and now allows the US government to label hackers as terrorists. Scary stuff.
- jacquesm 13y ago> This is a false flag operation to turn the public opinion against "hackers" so these crazy internet regulations bills can start passing and so that they can get away with spying scandal. You can't know for sure it is a false flag operation, but you can't easily rule it out either.
- mpyne 13y agoIt sounds like a religion to me, then.
- jlgreco 13y agoExcept unlike gods, we are quite sure that false flag incidents can happen. Nobody doubts that. The very concept isn't what is questioned, only particular incidents.
- mpyne 13y agoI wasn't questioning the concept though, especially as the Nazis used it to kick off WWII in Europe. But on the other hand, we at least had proof of the false flag attack by Germany. In this case we have, to this point, faith and educated guesses, but it's faith nonetheless.
- mpchlets 13y agoSo not sure what to say, but this is the email I received from DynEct the other day: subject: Webinar Wednesday: Are You Prepared For DNS Disaster? sender: Dyn hello@dyn.com via dynect-mailer.net and some info from my old whois: $ whois twitter.com Whois Server Version 2.0 Domain names in the .com and .net domains can now be registered with many different competing registrars. Go to http://www.internic.net http://www.internic.net for detailed information. Server Name: TWITTER.COM.GET.ONE.MILLION.DOLLARS.AT.WWW.UNIMUNDI.COM IP Address: 209.126.190.71 Registrar: PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM Whois Server: whois.PublicDomainRegistry.com Referral URL: http://www.PublicDomainRegistry.com Domain Name: TWITTER.COM Registrar: MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Whois Server: whois.melbourneit.com Referral URL: http://www.melbourneit.com Name Server: NS1.P34.DYNECT.NET Name Server: NS2.P34.DYNECT.NET Name Server: NS3.P34.DYNECT.NET Name Server: NS4.P34.DYNECT.NET
- mpchlets 13y agoSeems to me that melbourneit.com was the cause of these problems - that is the related link between all these different problems - basically poisoning the DNS of any popular company that uses them.
- fudyy 13y agoSorry to be cynical and bring politics into this, but I hope that U.S. liberals respond the way they did to Bush to Obama with this strike. Comedians, the media, etc. accused Bush of an adjust war for someone that used a chemical attack on his own people because there were no found WMD's even though there was evidence of a chemical attack. Now we are going in again to try to save things. Will Obama come out as a hero? Probably. Should he? Well if he should, Bush needs to get some slack finally. Don't get me wrong- I think we should do something. But when I hear we are going to do another 3 day bombing run, it's just like Iraq all over again, except this time it's who the Democrats want to bomb. Isn't there an answer that doesn't involve bombing? What are we, Germany in WWII?
- Niten 13y agoThat comparison is quite the stretch, though. The currently debated reaction to Syria's chemical weapons attack is a limited response intended to punish the Assad regime, to attempt to reduce its ability to launch more such attacks in the future and to provide it with a disincentive to do so. It would not be an attempt to topple the regime or to take over Syria for American interests. Further, the use of chemical weapons in the Iran-Iraq war as a pretext for invading Iraq in 2004 is, as we all know, extremely disingenuous, given that these attacks happened more than a decade prior – and with the support of the U.S. at the time: http://america.aljazeera.com/articles/2013/8/26/new-documents-proveussupportofiraqichemicalweaponsattacks.html http://america.aljazeera.com/articles/2013/8/26/new-document... [EDIT: I'm not arguing in favor of the U.S. intervening in Syria, though, least of all without proper congressional authorization.]
- InclinedPlane 13y agoI think the core problem is that military adventurism in this region shouldn't be predicated solely on, say, chemical weapons. Realistically chemical weapons don't tip the balance scales very much in the realm of America's narrow/selfish geopolitical interests, in the interests of humaneness, or in the more broad interests of attempting to do whatever is best for the people of the region on a long-term basis (specifically in regards to peaceful co-existence and consensual governance). We've attempted low touch "tomahawk diplomacy" before. We bombed Saddam's Iraq for their intransigence and aggression in the late '90s, we bombed Afghanistan and the Suddan in 1998 in retaliation for the bombings of our embassies, and so on. For the most part such things are utter wastes of effort. Retaliatory strikes are almost always bullshit. "Proportionate response" is just a fancy word for retaliation or revenge. Low touch warfare is almost always a mistake (see also: drone campaigns). We need to have clear geopolitical objectives, we need to be even clearer how we plan to achieve those objectives, and we need to follow through with as much effort (in whatever form) is required to achieve those objectives. Anything else is like some sort of macabre lottery. Attempting to see if killing a few people will magically result in a desired outcome even though the chances are low. Granted, one should be under no illusions, there are some very serious "bad guys" in the region, and in Syria specifically. Bad guys who few people on Earth should object to being killed. However, the situation is also much more complex than that and it's never the case that military action only kills or injures the exact people you want and no one else. There is a 3 (ish) side sectarian war in progress in Syria which has now spread to Lebanon. Taking out the al-Assad regime could perhaps be a good thing but it won't bring an end to the sectarian war. Whether or not chemical weapons are used as long as that war continues tens of thousands of people are going to be killed each year it goes on, if not more. I don't think the Obama administration has a very strong understanding of the complex dynamics on the ground in Syria nor do they have a firm plan on how to end the war there. Moreover, I think the lessons the administration has taken from what happened in Libya (even taking into account the later attack on the US embassy) are likely to lead them to believe that the situation is far less complex than it actually is.
- unhammer 13y agoIs this what DNSSEC is supposed to protect you from? (Or could they just change your dnssec records as well?)