15 ms·
Captcha.nsa.gov
- maxbaines 7y agoWhy Brazil?
- SubiculumCode 7y agoWhy is everyone talking about a captcha? All I get is a google search page (no recaptchas).
- FDSGSG 7y agoBecause google recaptcha is served from that domain (www.google.com).
- scarejunba 7y agoExamine the URL, especially the subdomain
- orisho 7y agoI'm guessing that the NSA website uses recaptcha, which is served by Google. Perhaps in order to comply with strict origin policy, they want everything on nsa.gov to be served from their domain. They seem to have a reverse proxy that proxies requests to google.com. That's one plausible explanation, but in any case, even if my explanation is wrong, I doubt the explanation is interesting.
- dessant 7y agoIf that's the case, they are being sloppy, considering that everything under www.google.com is proxied through their servers, not just specific reCAPTCHA assets. Gmail by NSA: https://captcha.nsa.gov/intl/us/gmail/about/ https://captcha.nsa.gov/intl/us/gmail/about/ They're inheriting a considerable part of Google's attack surface. For example, Google's open redirects could be used to bypass origin checks as part of an attack on nsa.gov, or to phish NSA employees.
- itcmcgrath 7y agoMy favorite so far: https://captcha.nsa.gov/logos/2019/loteria/rc2/loteria19.html?hl=en https://captcha.nsa.gov/logos/2019/loteria/rc2/loteria19.htm...
- bjornsing 7y agoFor me (in Sweden) that URL seems to just redirect to https://www.nsa.gov/?hl=en https://www.nsa.gov/?hl=en ...
- TimWolla 7y agoThey appear to have change something in the past few minutes. When I first opened this HN thread it showed me Google's homepage. Now I'm also seeing that redirect.
- dessant 7y agoNSA has just shut down the proxy. The link was a Google Doodles game.
- lkbm 7y agoYou can just replace captcha.nsa.gov with www.google.com to see what it used to serve up: https://www.google.com/logos/2019/loteria/rc2/loteria19.html?hl=en https://www.google.com/logos/2019/loteria/rc2/loteria19.html...
- Apofis 7y ago
- fredley 7y agoCan someone explain what's going on? Is this a domain hack to get Google's captcha working under an nsa.gov hostname, presumably so that it's usable on whitelist firewalls? I'm surprised Google serves a homepage to the domain, and that it doesn't only respond to requests to google.com (etc.)
- ryanlol 7y ago>I'm surprised Google serves a homepage to the domain Google doesn’t, the reverse proxy just rewrites the Host header.
- njetten 7y agoSeems to be on purpose, unless someone really misconfigured their Akamai setup. Your purpose sounds viable
- bndw 7y agoIs this more than a reverse proxy to google.com? Seems like the real question is _why_.
- captainmuon 7y agoMy guess: a custom version of Google that allows NSA analysts to do "Google dorking" - searching for vulnerable hosts with Google - without triggering a captcha. Somebody on twitter mentioned they could not get a captcha with strings that usually reliably cause one. Maybe this is just a fake front page that calls to the Google search API and pretends to be Google proper. Either it is for agents in the field to inconspicuously use google or they misconfigured it to be public?
- FDSGSG 7y agoYour guess is wrong. This isn't a custom version of google. It's just a regular akamai reverse proxy setup. > Either it is for agents in the field to inconspicuously use google By visiting a nsa.gov subdomain served by akamai? Yeah right. I feel like heading to www.google.com would be far less conspicuous.
- qubex 7y agoI am somewhat baffled. What was that?
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- ljd 7y agoI feel like the valid SSL cert is my biggest issue here.
- thedance 7y agoWhy wouldn't it be valid? Its for O=National Security Agency and it has alternate names matching this URL authority.
- chipperyman573 7y agoSSL just verifies that the NSA owns nsa.gov
- sdinsn 7y agoWhy is it in Portuguese?
- calibas 7y agoWhat's odd is that it came up in English at first, but now it's Portuguese for me. Another comment here mentioned it's the Brazilian version of Google's search page.
- FateOfNations 7y agodepends on where the traffic exits the Akamai network... they are likely using it to proxy Recaptcha, so they likely said "we don't care where it exits" and Akamai picks whatever is most convenient for them... in that case, Brazil.
- jaywalk 7y agoIt depends on the IP of the Akamai server that's hitting it. If you search "what is my ip" you'll see it.
- kusha 7y agoFrom this twitter thread: https://twitter.com/mikko/status/1224349151384821762 https://twitter.com/mikko/status/1224349151384821762 You can't search traceroute. Weird.
- ryanlol 7y agoNot weird, just WAF.
- XMPPwocky 7y agoYou also can't search alert(1), so probably just a silly WAF.
- rahuldottech 7y agoOr for `<script>`
- batuhanicoz 7y agoPeople on that thread also noticed more keywords and think it might be Akamai WAF. I don't know enough about it be sure. You can't have some strings in the URL for the main NSA.gov domain as well. So https://nsa.gov/fakething?hey=traceroute https://nsa.gov/fakething?hey=traceroute will give you the same error.
- ehsankia 7y agoYeah it's clear that a system is just blindly grepping the request url for certain keywords and killing the query.
- deleted 7y ago[deleted]
- mythz 7y agoSo you can't search for `traceroute` or `tracert` directly but you can search for misspelling like `tracerout` and the results page just ends up showing the search results for `traceroute` so it's not exactly a very sophisticated filter.
- deleted 7y ago[deleted]
- DangerousPie 7y agoInteresting alt names on the SSL certificate: DNS Name=www.nsa.gov DNS Name=nsa.gov DNS Name=apps-test.nsa.gov DNS Name=stage.nsa.gov DNS Name=apps.nsa.gov DNS Name=www2.nsa.gov DNS Name=captcha.nsa.gov DNS Name=m.nsa.gov
- numpad0 7y agoEven NSA has mobile pages these days!?
- deleted 7y ago[deleted]
- kube-system 7y agoIt looks like it's actually required by law. https://www.congress.gov/bill/115th-congress/house-bill/2331 https://www.congress.gov/bill/115th-congress/house-bill/2331 >If, on or after the date that is 180 days after the date of the enactment of this section, an agency creates a website that is intended for use by the public or conducts a redesign of an existing legacy website that is intended for use by the public, the agency shall ensure to the greatest extent practicable that the website is mobile friendly.
- jcoffland 7y agoOne of those leads to this: https://apps.nsa.gov/eqip-applicant/showLogin.login https://apps.nsa.gov/eqip-applicant/showLogin.login
- Onawa 7y agoEqip is the government system for doing background checks. Just had to fill one out for NIH a few weeks ago.
- kyrra 7y agoLooks to be cname forwarding. > $ dig captcha.nsa.gov > ;; ANSWER SECTION: > captcha.nsa.gov. 13246 IN CNAME www.nsa.gov.edgekey.net. > www.nsa.gov.edgekey.net. 21528 IN CNAME e6655.dscna.akamaiedge.net. > e6655.dscna.akamaiedge.net. 19 IN A 23.213.xxx.xxx The IP addreses at the last one all seem to be Akamai IPs. So So that is fronting Google here it seems?
- snazz 7y agoCan anyone just do that to any domain? My website is hosted at GitHub Pages and requires a CNAME file in the repo root as well as the DNS entry at Cloudflare.
- milankragujevic 7y agoYes, they are not using a CNAME (whereby the original server serves the page, just on a different domain), they appear to be using a reverse proxy. You can find more info about how that works here: https://en.wikipedia.org/wiki/Reverse_proxy https://en.wikipedia.org/wiki/Reverse_proxy
- snazz 7y agoThat makes a lot more sense.
- tpmx 7y agoThat's copyright and trademark infringement.
- milankragujevic 7y agoThat is not a technical limitation but a legal one.
- tpmx 7y agoYes. The NSA is is breaking the law here.
- deleted 7y ago[deleted]
- pamicel 7y ago??????
- patorjk 7y agoMy first instinct is that this is some kind of puzzle. It'd be pretty disappointing if this was just a misconfiguration or oversight.
- fredley 7y agoThat's actually a really viable theory, especially given the "can't search for traceroute" thing - that spits out what seems to be a time-based error string.
- ryanlol 7y agoIt’s not, that’s just standard akamai WAF behaviour. E: sorry, HN is throttling me and I can’t reply below. This is just a silly web application firewall that blocks a list of “suspicious strings”. There’s not much else to be said about it.
- deleted 7y ago[deleted]
- ryanlol 7y agoNothing especially interesting happening here, someone just pointed captcha.nsa.gov at google.com in their akamai config. Perhaps they’re just using google.com like example.com, or they’re trying to serve recaptcha under nsa.gov.
- Aissen 7y agoI've seen this on Twitter all day. My guess is that they wanted recaptcha, but serving the resources themselves. The easiest route was probably to reverse proxy google.com, which is what recaptcha is hosted on: https://developers.google.com/recaptcha/docs/v3#frontend_integration https://developers.google.com/recaptcha/docs/v3#frontend_int...
- ehsankia 7y agoCould this backfire in any way and create some sort of exploit on nsa.gov? What if someone happened to somehow have access to google.com?
- skizm 7y agoHow has no one used this for ads yet? You could make any third party site appear as a first party site. As blockers usually aren’t set up to block first party ads.
- ZoF 7y agoThis isn't particularly new, sure it's interesting though, as others have mentioned it's akamai with google as the endpoint, I'd be surprised if Google wasn't aware and allowing this. The localization defaulting to Brasil is interesting to me, you can force english just like google though[0] Here's a crawl from 2018[1] [0]-http://captcha.nsa.gov/?hl=en http://captcha.nsa.gov/?hl=en [1]-https://web.archive.org/web/20181206224407/http://captcha.nsa.gov/ https://web.archive.org/web/20181206224407/http://captcha.ns...
- romaaeterna 7y agoThis looks really really dumb. I wonder if you can get personal sites to display through nsa.gov somehow through this.
- 867-5309 7y agoit's all a ploy to finger HN users. imagine how many uniques they'll harvest!
- annoyingnoob 7y agoYeah, no way I'm clicking that link. I'll let others do that and read the reports here.
- aloknnikhil 7y agoAmong other things, it's weird that it shows up with a different GeoIP triangulation for different users. Someone commented here about seeing this in Portuguese. I'm seeing this in Japanese. Does anyone what's going on? EDIT: And now it's showing up in English.
- OrgNet 7y agoIt gives me Brasil's Google
- ghostoftiber 7y agoyeah I am on brazil also.
- jcoffland 7y agoI believe this has to do with which Akamai server ends up handling the page request.
- greatjack613 7y agoCan anyone from mainland china try this? I am curious to see if it is blocked.
- j_koreth 7y agoAccording to this website [0] it appears to do so which is interesting. https://www.comparitech.com/privacy-security-tools/blockedinchina/ https://www.comparitech.com/privacy-security-tools/blockedin...
- Gaelan 7y agoGreatFire says it’s unblocked. https://en.greatfire.org/captcha.nsa.gov https://en.greatfire.org/captcha.nsa.gov
- codeful 7y agoNo ads. Nice! :D
- deleted 7y ago[deleted]
- alpb 7y agoIt's likely this is set up to collect data by impersonating Google Search in an iframe etc. Consider reporting this to Safe Browsing complaint form as phishing attempt: https://www.google.com/safebrowsing/report_phish/ https://www.google.com/safebrowsing/report_phish/
- cmcd 7y agoYou think the NSA is phishing from a nsa domain?
- freeflight 7y agoWhy assume that was served on the link, and how it was served, is working as intended? It could have been part of a phishing setup that got accidentally pushed out with obfuscation components still missing. It's not like everybody working at NSA is a flawless human being, mistakes happen everywhere, sometimes even rather big ones. Also kinda weird how everybody seems to be giving the NSA the benefit of the doubt of this having some kind of supposedly totally benign purpose, completely ignoring the NSA's history and purpose.
- parliament32 7y agoIt's just a CNAME to an akamai IP: $ host captcha.nsa.gov captcha.nsa.gov is an alias for www.nsa.gov.edgekey.net. www.nsa.gov.edgekey.net is an alias for e6655.dscna.akamaiedge.net. e6655.dscna.akamaiedge.net has address 104.75.125.118 e6655.dscna.akamaiedge.net has IPv6 address 2600:1406:5800:7b5::19ff e6655.dscna.akamaiedge.net has IPv6 address 2600:1406:5800:792::19ff edgekey.net is an akamai thingy, all of nsa.gov seems to go through it $ host www.nsa.gov www.nsa.gov is an alias for nsa.gov.edgekey.net. nsa.gov.edgekey.net is an alias for e16248.dscb.akamaiedge.net.
- mnx 7y agoIt seems like we broke it -- it now refuses to do any searches for me (due to suspicious activity from 'my' ip)
- coekie 7y agoYou can see what IP it uses to send requests to google using https://captcha.nsa.gov/search?q=what+is+my+ip https://captcha.nsa.gov/search?q=what+is+my+ip
- fnord77 7y agoNSA's cert, too. All your are TLS belong to us.
- cjjuice 7y agoA potential vector would be to potentially load images/content through google image/AMP and make it appear as legitimate NSA content
- alistairSH 7y agoI don't get it - I'm seeing a Brazilian version of Google?
- aray 7y agoI'm curious if this is a (temporary, unsecure) way to use google if you're in a place that google is currently blocked. Small chance, but in case anyone on HN is in a place google is blocked, would be an interesting test to run.
- 2T1Qka0rEiPr 7y agoIf you're in a country which bans Google, I'd suspect a high chance having nsa.gov wouldn't be too favourable on your DNS lookup records!
- dpwm 7y agoGenuinely curious: are there places that block google but don't block the NSA?
- chillydawg 7y agoSo someone with control of a .google.com address can get a certificate for the equivalent .nsa.gov subdomain ?
- iod 7y agohttps://captcha.nsa.gov/intl/en/about.html https://captcha.nsa.gov/intl/en/about.html There is some truth to this.
- phlhar 7y agoOh wow, they just disabled it while I was reading some comments. It's no longer working, I'm now getting redirected to nsa.gov Edit: This seems to have been online since 2018, see https://web.archive.org/web/20181206224407/http://captcha.nsa.gov/ https://web.archive.org/web/20181206224407/http://captcha.ns....
- basilamer 7y agoAs someone very confused as to what people are commenting about, thank you. I'm clearly just seeing the post-patch version
- casefields 7y agoBefore they fixed it, it redirected to Googles homepage in Portuguese.
- dahfizz 7y agoIt wasn't a redirect. They served a Google homepage, but it was still an nsa.gov url
- mirimir 7y agoHere: https://web.archive.org/web/20200203154312/https://captcha.nsa.gov/ https://web.archive.org/web/20200203154312/https://captcha.n...
- a012 7y agoI still see a Google homepage
- dannyw 7y agoThat's what it was. The NSA was reverse proxying Google. The legit explanation (given the domain name) is probably they wanted to use reCAPTCHA, but block all non-NSA hosts with a firewall or something. This is not great, because the NSA expanded its attack surface to all of google.com. The more conspiracy explanation is that this is actually a phishing page set up, and due to a misconfiguration it's exposed under captcha.nsa.gov, but Occam's Razor should apply here.
- milankragujevic 7y agoAnd it's gone (redirects to nsa.gov)...
- colejhudson 7y agoJust went down, now redirects to www.nsa.gov.
- Groxx 7y agoI assume that the archive.org mirror is showing what was visible? https://web.archive.org/web/20200203154312/http://captcha.nsa.gov/ https://web.archive.org/web/20200203154312/http://captcha.ns... I see a google search page (google.com equivalent). Which fits with the reverse proxy that does ~any google url.
- 1970-01-01 7y agoNSA thanks you for you participation in this experiment. Please terminate all knowledge with the purple pill at this time.
- nurettin 7y agoAssume the party escort submission position or you will miss the party.
- preillyme 7y agoLooks like the good folks over at the NSA are reading Hacker News. And fix issues quickly. I’m proud of them.
- cm2187 7y agoor monitoring their traffic
- alexfromapex 7y agoThey probably have alerts set up for anyone on the internet talking about NSA lol
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- Paraesthetic 7y agoDoh, I was hoping for a captcha made by the NSA, for catching bots, and terrorists and such.
- johnmarcus 7y agoThe creapiest thing to me is that this post is 7 hours old, and the comment states it's disabled. It was fixed within 2 hours. Ergo, the NSA is actively monitoring HackerNews and taking quick actions when needed. I wonder what other sites the nsa has active alerting on?
- outworlder 7y agoOr maybe the domain admins have active alerts on their own domains. Which would be good practice.
- KindOne 7y agoNSA's official statement on twitter: https://twitter.com/NSAGov/status/1224456957622472706 https://twitter.com/NSAGov/status/1224456957622472706 (1/2) https://twitter.com/NSAGov/status/1224456959618945024 https://twitter.com/NSAGov/status/1224456959618945024 (2/2)
- aussieguy1234 7y agoA test version of a MITM proxy that captures data?