Live data from Hacker News

Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

thenextweb.com

31–40 of 105 posts

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#31

twimg.com seems to be hijacked

A status update now that it's fixed.

http://status.twitter.com/post/59528478030/twitter-service-i....

Kind of dodgy that there was no status update until 1.5 hours after the issue surfaced.

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#33
post #26

Ok, firstly whois Microsoft.com just returns all URLs with Microsoft.com in them, even as a subdomain, so they haven't been hacked and that result has been there for ages. Same goes for Verisign etc. TechCrunch is reporting that registrar MelbourneIT has been hacked.. This wouldn't surprise me but I'm puzzled as to why either site would register with such a bad registrar.

What do you mean? MelbourneIT are huge and generally have a pretty decent reputation.

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#34
post #26

Ok, firstly whois Microsoft.com just returns all URLs with Microsoft.com in them, even as a subdomain, so they haven't been hacked and that result has been there for ages. Same goes for Verisign etc. TechCrunch is reporting that registrar MelbourneIT has been hacked.. This wouldn't surprise me but I'm puzzled as to why either site would register with such a bad registrar.

I think the important question here is "Why on earth did they choose that registrar, for something so crucial?"

I bet they'll put in for a transfer ASAFP now!

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#35
post #26

Ok, firstly whois Microsoft.com just returns all URLs with Microsoft.com in them, even as a subdomain, so they haven't been hacked and that result has been there for ages. Same goes for Verisign etc. TechCrunch is reporting that registrar MelbourneIT has been hacked.. This wouldn't surprise me but I'm puzzled as to why either site would register with such a bad registrar.

What do you mean? MelbourneIT are huge and generally have a pretty decent reputation.

Had. Until now.

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#36
post #26

Ok, firstly whois Microsoft.com just returns all URLs with Microsoft.com in them, even as a subdomain, so they haven't been hacked and that result has been there for ages. Same goes for Verisign etc. TechCrunch is reporting that registrar MelbourneIT has been hacked.. This wouldn't surprise me but I'm puzzled as to why either site would register with such a bad registrar.

What do you mean? MelbourneIT are huge and generally have a pretty decent reputation.

> MelbourneIT are huge and generally have a pretty decent reputation.

Clearly you have never used their ticketing system.

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#37
post #26

Ok, firstly whois Microsoft.com just returns all URLs with Microsoft.com in them, even as a subdomain, so they haven't been hacked and that result has been there for ages. Same goes for Verisign etc. TechCrunch is reporting that registrar MelbourneIT has been hacked.. This wouldn't surprise me but I'm puzzled as to why either site would register with such a bad registrar.

What do you mean? MelbourneIT are huge and generally have a pretty decent reputation.

Yeah, you're right that was probably a bit harsh given that I'm just running from what I've heard from others, and the fact that last year they were still charging $150 for registration. But who am I to know - I don't want to be one of those token HN trolls who pays out on people for the sake of it so I retract my initial comment.

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#38
For those want to take a look at the more internal efforts of the SEA, here are some logs[1] obtained from a leaked set thanks to Telecomix[2].

The snippet of logs is from a voluminous set. A mere sample[3]:

BlueCoat Helps Assad/SEA Track Homosexuals: 2011-07-22 20:34:53 14 dee58fa2188103d6 - - - OBSERVED "unavailable" videogayz.com/ 200 TCP_HIT 6 Jul from web

BlueCoat Logs from Assad/SEA Hardware Tracks MSN: 2011-07-22 20:34:53 35850 0cb611eeb0ef8c6e - - - PROXIED "unavailable" by2msg4030114.gateway.messenger.liv… 6 Jul from web

BlueCoat Logs Show Assad/SEA Is Totally Secular, Tracks Religious Followers: 2011-07-22 20:34:52 166 7cc423995fff7f92 - - - OBSERVED "unavailable" www.syrianoz.com/news/kamishly/chur… 6 Jul from web

[1] http://bluesmote.com/

[2] http://en.wikipedia.org/wiki/Telecomix

[3] http://pastie.org/private/mxgzj4u6y52dsgzudtsg

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#39
post #2

Whoa. Twitter, NYTimes, HuffPo... all had their DNS records hacked? This seems huge.

How difficult of a thing is this to pull off?

If you can compromise a shared registrar, pretty trivial.

Re: Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

#40
post #20

Earlier quoted context omitted.

I don't buy it either. Seems fishy.

Fishy enough that the SEA's own Twitter account is gloating about it?

Fortunately it's really hard to make a Twitter account, what with all the passport checks and ID verification that goes on there. Only real, verified SEA members would be able to create such an account. And only when directly logging in from a verified Syrian government IP.
Post reply on HN