Live data from Hacker News

Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

news.ycombinator.com

101–110 of 148 posts

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#102

An entry-level admin is now unemployed, just before the holidays.

This is most likely a honest mistake. Smart managers don't fire employees for such mistakes unless their behavior regarding that mistake is inappropriate.

As the story goes, after a junior admin wiped a production database. The boss was asked if he should be fired. To what he answered: "Fire him? No way! Not after such an expensive training." Now, he knows.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#103

I'm trying to figure out how this could have happened, but I control so few IP addresses that many of my DNS entries are manually assigned. And you'd have to be incompetent if you have access to set DNS records and you set them to RFC 1918 addresses. Anyone have any theories on how this could happen?

My guess is that someone at MS was testing Windows Updates or other changes from a local source. They also had some other DNS updates in their config they were testing. They took all of their config and pushed it out, when they should only have taken the other changes.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#105

I'm trying to figure out how this could have happened, but I control so few IP addresses that many of my DNS entries are manually assigned. And you'd have to be incompetent if you have access to set DNS records and you set them to RFC 1918 addresses. Anyone have any theories on how this could happen?

>> And you'd have to be incompetent if you have access to set DNS records and you set them to RFC 1918 addresses.

Clearly the following is not in play for a root domain (Microsoft.com) but assigning a DNS entry to a class C address does have a purpose.

If you have an intranet server, giving it a DNS name allows for HTTPS serving, with an automatic, CA signed, certificate. (Using say LE with DNS challenge.)

I provide this simply as an example of how this might come about.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#106
post #90

Earlier quoted context omitted.

Microsoft also has some of the phishiest looking domains when you are redirected around the O365 cloud.

100%. Starting with "onmicrosoft.com". A phisher wouldn't really have to control Microsoft.com to take advantage of confusion.

There were several phishing attempts from that domain, onmicrosoft.com, to my personal email account this past week.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#108
post #94

Earlier quoted context omitted.

For all this to work you need to control the domain. Is that easier than simply breaking into their systems and owning their servers?

That's exactly what they're saying. > it could have been bad if it was an external ip with a machine setup by a phisherman I.e. one of the IPs for microsoft.com belongs to $phisher, which means they control (a subset of the traffic going to) the domain. They can't add CNAME records for certificate validation, but LetsEncrypt for example offers HTTP-based validation. Not sure how Microsoft sets up their certificate pi…

It might also be a highly targeted attack on someone with precious information wherein someone was able to hack a simple router and in order to get access to their actual microsoft.com account, they simply setup a phisherman's clone on the router and captured the login/password/2fa and got into the account.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#109

How the hell did that pass any sort of responsible review process at Microsoft? Now Microsoft owns all your home networks, only like the default address on every home router out there...

> Now Microsoft owns all your home networks Only if you’re slumming around 192.168.x.x

[flagged]

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#110
post #15

Through a series of connections I know a guy that knows a guy that works at Microsoft that was made aware and the changes have been reverted. Give 'er 30 minutes TTL ;)

I know myself through a series of connections as well. ;) ;)

If you know yourself through a series of connection then that's a false you.
Post reply on HN