Live data from Hacker News

LinkedIn suffers DNS hijack

alpha.app.net

11–20 of 95 posts

Re: LinkedIn suffers DNS hijack

#12
The DNS was not exactly hijacked, there were issues inside of LinkedIn's top level DNS provider whom were delegating www.linkedin.com authorization to unauthorized nameservers, namely NS[SOMETHING].ztomy.com. The ztomy DNS replaces its delegated domains to point to a domain parking page if there is no record exiting. These changes were then propagated to other nameservers and thus to the end user. End result, dns doesn't point where you think it does.

Re: LinkedIn suffers DNS hijack

#13
post #7

I guess they didn't mark their cookies as 'Secure'. Oh well, the real story here is an app.net link at #1 on HN.

> Oh well, the real story here is an app.net link at #1 on HN. I can't tell if this is sarcasm or a serious comment. Could you elaborate on this comment? I don't get why a link by app.net would be news worthy.

My understanding is app.net is trying to be a paid version of twitter. There was/is much debate whether it could ever take off. This is the first time I've ever seen someone link to it. Although now I realize that the link is to the app.net cofounder so that doesn't really say much.

Re: LinkedIn suffers DNS hijack

#15
Was api.linkedin.com compromised/hijacked? If so, that means they'll need to reset a lot of OAuth token/secrets which will be very painful indeed (worse than just a site-wide session reset).

Re: LinkedIn suffers DNS hijack

#17
My traceroute is going thru prolexic.com so there might be something else at play here. "Prolexic is the world’s largest and most trusted distributed denial of service (DDoS) mitigation service provider"

Re: LinkedIn suffers DNS hijack

#19
post #12

The DNS was not exactly hijacked, there were issues inside of LinkedIn's top level DNS provider whom were delegating www.linkedin.com authorization to unauthorized nameservers, namely NS[SOMETHING].ztomy.com. The ztomy DNS replaces its delegated domains to point to a domain parking page if there is no record exiting. These changes were then propagated to other nameservers and thus to the end user. End result, dns doe…

That makes sense since we just saw the same problem with USPS realtime shipping rates via production.shippingapis.com, which seems like an odd attack target.

edit: and I mean the exact same issue, it was resolving to a confluence owned IP that was serving a squatter page for the domain.

Re: LinkedIn suffers DNS hijack

#20
post #3

Seeing 204.11.56.17 for their A record which is OrgName: Confluence Networks Inc OrgId: CN Address: 3rd Floor, Omar Hodge Building, Wickhams Address: Cay I, P.O. Box 362 City: Road Town StateProv: Tortola PostalCode: VG1110 Country: VG RegDate: 2011-04-07 Updated: 2011-07-05

Doing an nslookup here in Vancouver, Canada got me this:

Non-authoritative answer: Name: linkedin.com Address: 216.52.242.86

Does that mean I'm still pointing to the legitimate server?

Post reply on HN