Live data from Hacker News

Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

news.ycombinator.com

31–40 of 148 posts

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#32

What could a TLA do with this if it had time to plan ahead?

Serve malicious updates from a locally controlled machine, for one. Lord knows about auth.

Do most DNS forwarders not block addresses that resolve to a local IP these days? I know dnsmasq does, and NextDNS too I think.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#33
post #10

I'm trying to figure out how this could have happened, but I control so few IP addresses that many of my DNS entries are manually assigned. And you'd have to be incompetent if you have access to set DNS records and you set them to RFC 1918 addresses. Anyone have any theories on how this could happen?

* Copy/Paste * Copilot told me * Sabotage (internal or external)

Or hard to reason about IaC

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#34

I'm trying to figure out how this could have happened, but I control so few IP addresses that many of my DNS entries are manually assigned. And you'd have to be incompetent if you have access to set DNS records and you set them to RFC 1918 addresses. Anyone have any theories on how this could happen?

I'll go with Joseph Conrad on this one.

"It's only those who do nothing that make no mistakes, I suppose."

Now the persons that did it have some proof that they did something.

They will surely put some check in place because there should be another adage somewhere that says that you only learn to use the handrails after you fell in the stairs.

Re: Tell HN: Microsoft.com added 192.168.1.1 to their DNS record

#38
post #15

Through a series of connections I know a guy that knows a guy that works at Microsoft that was made aware and the changes have been reverted. Give 'er 30 minutes TTL ;)

This isn’t something that I think should be diluted.

If it’s that simple for a stray record to be included in the dns round robin it could have been bad if it was an external ip with a machine setup by a phisherman especially since control of a domain is all you need to get an ssl cert now.

Couple this with the fact that it’s Microsoft, one of the most relied on companies in our computer world, this is pretty darn horrible.

Post reply on HN