Live data from Hacker News

Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

thenextweb.com

21–30 of 105 posts

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#23
SEA has a history of doing much more than attempting to offset perceived propaganda[1]. With in that site is dozens of gigabytes of logs from Bluecoat[2] proxy hardware that sat in datacenters for Syrian ISPs.

A good amount of what is contained in the logs is things like porn searches, more porn, porn. But amongst the typical naughty bits things like religious queries for Christians, Catholics, Jews, Muslims were being recorded.

Telecomix[3] helped to leak the log-set, and as it stands it is _the_ example of how state entities monitor peoples of 'interest.' Much of these people are long since dead, killed early on as they were the most public[4].

So while the SEA's most public facing events are hijacks, phising, and massive redirects. Please do focus on the end result of pervasive surveillance[5].

[1] http://bluesmote.com/

[2] http://www.bluecoat.com/

[3] http://en.wikipedia.org/wiki/Telecomix

[4] http://en.wikipedia.org/wiki/Ibrahim_Qashoush

[5] http://imgur.com/gallery/qz7wm

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#24
post #22

[deleted]

> reustle wrote:

> Here's what I get for whois google.com

> GOOGLE.COM.ZZZZZZZZZZZZZZZZZZZZZZZZZZ.HAVENDATA.COM

> ...

> GOOGLE.COM.AFRICANBATS.ORG GOOGLE.COM

> And Microsoft

> MICROSOFT.COM.ZZZZZZZZZZZZZZZZZZZZZZ.IS.A.GREAT.COMPANY.ITREBAL.COM

> ...

> MICROSOFT.COM.ARE.GODDAMN.PIGFUCKERS.NET.NS-NOT-IN-SERVICE.COM MICROSOFT.COM

Don't be silly. You're simply getting everything that starts with microsoft.com.

So for the first microsoft example that's itrebal.com, they can issue subdomains as many as they want or publish records for subdomains which in turn will cause the whois commands to cough up that information. It assumes that you are searching for some info and helpfully includes everything that it thinks might be applicable.

This trick will give you results for almost any well known domain name and is not indicative of a hack, merely of a slight shortcoming in the way whois records are displayed / queries, the default is a non-exact match.

They're not hacks, they are pranks.

Try this:

whois -h whois.tucows.com microsoft.com

If you're not convinced by the above.

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#26
Ok, firstly whois Microsoft.com just returns all URLs with Microsoft.com in them, even as a subdomain, so they haven't been hacked and that result has been there for ages. Same goes for Verisign etc.

TechCrunch is reporting that registrar MelbourneIT has been hacked.. This wouldn't surprise me but I'm puzzled as to why either site would register with such a bad registrar.

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#27
post #22

[deleted]

> reustle wrote: > Here's what I get for whois google.com > GOOGLE.COM.ZZZZZZZZZZZZZZZZZZZZZZZZZZ.HAVENDATA.COM > ... > GOOGLE.COM.AFRICANBATS.ORG GOOGLE.COM > And Microsoft > MICROSOFT.COM.ZZZZZZZZZZZZZZZZZZZZZZ.IS.A.GREAT.COMPANY.ITREBAL.COM > ... > MICROSOFT.COM.ARE.GODDAMN.PIGFUCKERS.NET.NS-NOT-IN-SERVICE.COM MICROSOFT.COM Don't be silly. You're simply getting everything that starts with microsoft.com. So for the…

I believe the trick is to also register the subdomain as an NS server. But yeah, not a hack.
Post reply on HN