that's what happens when you buy address space from the back of a van in the parking lot ;)
https://theamazingworldofgumball.fandom.com/wiki/Awesome_Sto...
131–140 of 148 posts
that's what happens when you buy address space from the back of a van in the parking lot ;)
https://theamazingworldofgumball.fandom.com/wiki/Awesome_Sto...
Earlier quoted context omitted.
This isn’t something that I think should be diluted. If it’s that simple for a stray record to be included in the dns round robin it could have been bad if it was an external ip with a machine setup by a phisherman especially since control of a domain is all you need to get an ssl cert now. Couple this with the fact that it’s Microsoft, one of the most relied on companies in our computer world, this is pretty darn ho…
Microsoft also has some of the phishiest looking domains when you are redirected around the O365 cloud.
They use 1drv.ms as the domain in OneDrive emails, and sometimes it almost looks like the .ms ccTLD belongs to them - it very much doesn't, anyone can register a .ms domain.
windows.net being an Azure domain that third parties can have content under is fitting.
It sometimes looks like they want their users to be phished.
Microsoft is a smart company though, I really hope they can sort this out.
Earlier quoted context omitted.
This isn’t something that I think should be diluted. If it’s that simple for a stray record to be included in the dns round robin it could have been bad if it was an external ip with a machine setup by a phisherman especially since control of a domain is all you need to get an ssl cert now. Couple this with the fact that it’s Microsoft, one of the most relied on companies in our computer world, this is pretty darn ho…
Microsoft also has some of the phishiest looking domains when you are redirected around the O365 cloud.
Earlier quoted context omitted.
For all this to work you need to control the domain. Is that easier than simply breaking into their systems and owning their servers?
That's exactly what they're saying. > it could have been bad if it was an external ip with a machine setup by a phisherman I.e. one of the IPs for microsoft.com belongs to $phisher, which means they control (a subset of the traffic going to) the domain. They can't add CNAME records for certificate validation, but LetsEncrypt for example offers HTTP-based validation. Not sure how Microsoft sets up their certificate pi…
Through a series of connections I know a guy that knows a guy that works at Microsoft that was made aware and the changes have been reverted. Give 'er 30 minutes TTL ;)
They probably asked copilot to manage their DNS servers
Earlier quoted context omitted.
A few are dropping 192.168.1.0 now: as of 1703035296: ns1-39.azure-dns.com no longer has 192.168.1.0 for microsoft.com 1.1.1.1 still has 192.168.1.0 for microsoft.com 8.8.8.8 still has 192.168.1.0 for microsoft.com 76.76.2.0 no longer has 192.168.1.0 for microsoft.com 9.9.9.9 still has 192.168.1.0 for microsoft.com 208.67.222.222 still has 192.168.1.0 for microsoft.com 185.228.168.9 still has 192.168.1.0 for microsof…
Only one of those is authoritative. All of the authoritative servers have dropped it. Microsoft has fixed the issue.
Nope. This is still Microsoft's fault while non-auth servers update.