Does anyone have any corroboration of this?
LinkedIn suffers DNS hijack
11–20 of 95 posts
Re: LinkedIn suffers DNS hijack
#12Re: LinkedIn suffers DNS hijack
#13I guess they didn't mark their cookies as 'Secure'. Oh well, the real story here is an app.net link at #1 on HN.
> Oh well, the real story here is an app.net link at #1 on HN. I can't tell if this is sarcasm or a serious comment. Could you elaborate on this comment? I don't get why a link by app.net would be news worthy.
Re: LinkedIn suffers DNS hijack
#14http://en.wikipedia.org/wiki/HTTP_cookie#Secure_and_HttpOnly
Re: LinkedIn suffers DNS hijack
#15Re: LinkedIn suffers DNS hijack
#16Re: LinkedIn suffers DNS hijack
#17Re: LinkedIn suffers DNS hijack
#18www.ztomy.com
Re: LinkedIn suffers DNS hijack
#19The DNS was not exactly hijacked, there were issues inside of LinkedIn's top level DNS provider whom were delegating www.linkedin.com authorization to unauthorized nameservers, namely NS[SOMETHING].ztomy.com. The ztomy DNS replaces its delegated domains to point to a domain parking page if there is no record exiting. These changes were then propagated to other nameservers and thus to the end user. End result, dns doe…
edit: and I mean the exact same issue, it was resolving to a confluence owned IP that was serving a squatter page for the domain.
Re: LinkedIn suffers DNS hijack
#20Seeing 204.11.56.17 for their A record which is OrgName: Confluence Networks Inc OrgId: CN Address: 3rd Floor, Omar Hodge Building, Wickhams Address: Cay I, P.O. Box 362 City: Road Town StateProv: Tortola PostalCode: VG1110 Country: VG RegDate: 2011-04-07 Updated: 2011-07-05
Non-authoritative answer: Name: linkedin.com Address: 216.52.242.86
Does that mean I'm still pointing to the legitimate server?