Live data from Hacker News

Google.ps domain was hacked

google.ps

71–80 of 92 posts

Re: Google.ps domain was hacked

#72

Earlier quoted context omitted.

Really, it implies any attack or breach that is apparent to users. This is very apparent.

That is not what "hacked" means. If they had really hacked Google their servers and proxied all searches through a system of theirs without letting the users know it would not have been "apparent" yet Google was hacked in the correct sense of the definition. They were defaced which was directly apparent to users - not hacked. At all.

I'll repeat the crux of this discussion. There's no definition of 'hacked.' Welcome to the Internet.

Re: Google.ps domain was hacked

#73
post #56

Earlier quoted context omitted.

How is defacing a page not "malicious"?

I think they meant there was no malware being delivered from visiting the page.

The parent comment covered this very point:

>1. You're not subjecting HN readers to a site under the control of a malicious party who may have done more than just deface it. Even if you verify that you only receive plain boring text with no scripts, iframes, plugins, etc. it's impossible to verify that someone else won't get served different content. For example, malware that only gets served to people in Israel.

Re: Google.ps domain was hacked

#74

Earlier quoted context omitted.

That is not what "hacked" means. If they had really hacked Google their servers and proxied all searches through a system of theirs without letting the users know it would not have been "apparent" yet Google was hacked in the correct sense of the definition. They were defaced which was directly apparent to users - not hacked. At all.

I'll repeat the crux of this discussion. There's no definition of 'hacked.' Welcome to the Internet.

No definition of "hacked"? Really? You will go that meta to prove your point?

"a hacker is someone who seeks and exploits weaknesses in a computer system or computer network" ( http://en.wikipedia.org/wiki/Hacker_(computer_security) )

Being hacked means a hacker has found and exploited a weakness in a computer system or network. Saying that Google Palestine was hacked is false because no exploit in a computer system or computer network OF Google Palestine was found nor exploited.

Re: Google.ps domain was hacked

#75
post #60

Good job, butthurt nationalist losers ;-).

And if this were done by jews being oppressed somewhere, your reaction would be the same? Not that you'll take this advice, but I'd really recommend spending a little time thinking about what if you were born with a different last name. Would you be a butthurt loser then, by dint of that last name?

Hey kids, check this out! http://www.reddit.com/r/worldnews/

Re: Google.ps domain was hacked

#76
post #66

Earlier quoted context omitted.

Not all registries are created equal. I'm a heavy Internet user and I'd get along just fine without the .ps nameservers.

Still, it goes to show that even if you lock down your website, you could still be vulnerable if your registry is vulnerable.

That has been shown since the first day of DNS.

Re: Google.ps domain was hacked

#77
post #37
post #31

Aren't we seeing a lot of DNS based attacks in the recent past? I remember .pk TLD was hacked not too long ago. Considering that most of the big sites run local variants of their services using these TLDs is it fair to assume that one of these next ones could be of the phishing kind? What's the best thing to do - always use the .com hoping that it is safer?

This isn't a DNS issue, it's a SQL injection attack. ICANN needs to mandate stronger requirements for best practices with web based management UIs. Unfortunately they have little in the way of real control over ccTLDs. You'd be best served registering ccTLDs and redirecting them to your gTLD of choice (say, .com) and not trying to serve localized content from them.

Semantics. If it was an SQL injection attack, it was an SQL injection account that caused a DNS issue. No one cares about a specific SQL injection vulnerability, what matters is that a domain stopped being secure. Nothing bad happened here, but they could have made the fake page look like Google and collected a bunch of logins.

Re: Google.ps domain was hacked

#79
post #60

Good job, butthurt nationalist losers ;-).

And if this were done by jews being oppressed somewhere, your reaction would be the same? Not that you'll take this advice, but I'd really recommend spending a little time thinking about what if you were born with a different last name. Would you be a butthurt loser then, by dint of that last name?

I'm congratulating them; hence the winking smiley-face. What the hell?

This is an online prank. Have you actually decided to treat it as a serious political protest?

Re: Google.ps domain was hacked

#80
post #43
post #30

... and thousands of HN readers get infected by a zero-day exploit. Maybe. If you're thinking of submitting a known compromised site to HN, consider instead submitting a third-party site which explains/documents the compromise. Ideally from a respected security research company. This has several benefits: 1. You're not subjecting HN readers to a site under the control of a malicious party who may have done more than…

I agree with your point, but 0-day exploits aren't tossed around like candy corn. They're multi-million dollar munitions.

> 0-day exploits aren't tossed around like candy corn

They are if the zero-day isn't what you're after.

Something like this is like candy corn to a site like HN. You need an exploit and a reason to get your targets to visit your hacked site. When something like this hits HN's front page, if your target is in the tech world, odds are very good that you'll catch someone in the company/companies you're after. This is not theoretical. See, for instance, the Java exploits employed in those hacked iOS dev forums that successfully compromised computers at Facebook, Twitter, Apple, and Microsoft[1].

[1] http://arstechnica.com/security/2013/02/web-forum-for-iphone...

Post reply on HN