25 ms·
Tell HN: Microsoft.com added 192.168.1.1 to their DNS record
Is this bad?
$ nslookup microsoft.com
Non-authoritative answer:
Name: microsoft.com
Address: 192.168.1.0
Name: microsoft.com
Address: 20.112.250.133
Name: microsoft.com
Address: 20.231.239.246
Name: microsoft.com
Address: 20.76.201.171
Name: microsoft.com
Address: 20.70.246.20
Name: microsoft.com
Address: 20.236.44.162
Name: microsoft.com
Address: 192.168.1.1
- deadlinermusic 3y agoThis seems the opposite of good.
- b112 3y agoConfirmed here.
- h2odragon 3y agoI get it too, with .1.0 as well Name: microsoft.com Address: 192.168.1.1 Name: microsoft.com Address: 192.168.1.0 "ooopsie!"
- bewaretheirs 3y ago1.1 is gone but I'm still seeing the 1.0 entry.
- donkers 3y agoSame here with 1.0
- beezle 3y agoLooks like somebody made a booboo
- jay-barronville 3y agoAnother confirmation here. Whoops!
- WallyFunk 3y agoInteresting https://who.is/dns/microsoft.com https://who.is/dns/microsoft.com What are the potential ramifications of this?
- bennysaurus 3y agoPotential timeouts for clients/workstations trying to reach microsoft.com. Which entry is picked for use is generally random depending on the client. Most systems will retry using another entry though on issues connecting through. That said, if you are on a network that is 192.168 based, trying to get to Microsoft.com may just send you to your local router!
- efortis 3y ago29% traffic lost
- justin_oaks 3y agoI'm trying to figure out how this could have happened, but I control so few IP addresses that many of my DNS entries are manually assigned. And you'd have to be incompetent if you have access to set DNS records and you set them to RFC 1918 addresses. Anyone have any theories on how this could happen?
- efortis 3y ago* Copy/Paste * Copilot told me * Sabotage (internal or external)
- quickthrower2 3y agoOr hard to reason about IaC
- fomine3 3y agomy wild idea: counterattack for DDoS
- efortis 3y ago[flagged]
- deleted 3y ago[deleted]
- milkshakes 3y agoabout ten years ago, apple added a stray record to the apple.com zone .... a DNAME[1] record ....... that pointed to apple.com 1: https://en.wikipedia.org/wiki/DNAME_record https://en.wikipedia.org/wiki/DNAME_record this had some pretty disastrous results[2] 2: https://mashable.com/archive/apple-tunes-app-store-icloud-problems https://mashable.com/archive/apple-tunes-app-store-icloud-pr... bad things happen everywhere
- ericpauley 3y agoIt continually astounds me that DNAME got standardized. Scary stuff.
- mac3n 3y agothat's what happens when you buy address space from the back of a van in the parking lot ;)
- kraussvonespy 3y agoHow dare you besmirch the reputation of The Awesome Store! https://theamazingworldofgumball.fandom.com/wiki/Awesome_Store https://theamazingworldofgumball.fandom.com/wiki/Awesome_Sto...
- anenefan 3y agoI imagine it has something to do with how MS creates bypasses for host files for systems xpsp2 onwards ... by [1] it suggests Win10 still does. [1] https://superuser.com/questions/1111582/does-microsoft-prevent-hosts-file-redirection-for-its-websites https://superuser.com/questions/1111582/does-microsoft-preve...
- kotaKat 3y agoThrough a series of connections I know a guy that knows a guy that works at Microsoft that was made aware and the changes have been reverted. Give 'er 30 minutes TTL ;)
- workfromspace 3y agoDo we need to restart our Windows machines? :)
- awill 3y agothat's the solution to all Windows problems, so yes :)
- Krutonium 3y agoGG, Gone for me now.
- rubyfan 3y agoThis is my favorite HN comment of 2023.
- jgoodknight 3y agoThis is my second favorite HN comment of 2023
- rand1239 3y agoHN is a wormhole through which you can connect pretty much anyone in tech industry.
- jaza 3y ago30 minutes minutes or 30 Windows minutes? :P
- wkjagt 3y agoActually, it’s looking more like 6 days. No wait, 30 seconds.
- mi_lk 3y agofor uninitiated (me), why is it bad?
- xenophonf 3y agoIt's an IP address reserved for private networks: https://tools.ietf.org/html/rfc1918 https://tools.ietf.org/html/rfc1918
- Racing0461 3y agoSince 2 out of the 7 IPs are 192.168 (private ips), 2/7 visitors to microsoft.com will load the private ones assumign equal weight and not get the page to load.
- ajb 3y agoWell in my case (and a lot of other people), 192.168.1.1 is the local address of my home router. So if I go to microsoft.com I have a 1 in 7 chance of getting my home router instead (if I ignore the certificate warning). Other random breakage will happen depending on what that local address is assigned to for you. In theory this could be leveraged for hacking, but I think that would require setup in advance.
- Zuiii 3y agoyep. If a hacker can somehow control 192.168.1.1 or 192.168.0.1 they get access to your microsoft.com cookies at least. I'm sure there are more microsoft specific ways to leverage this too (e.g. data/updates hosted on microsoft.com that misuse HTTPS as a poor man's authentication. The curl | sh crowd are especially susceptible to this problem.)
- marshray 3y agoThey would still need the private key to a https cert that your browser considers valid.
- Iwan-Zotow 3y agoSo if you go to microsoft.com with probability 1/7 you'll hit 1.1 on your private network of 192.168 - likely router, and with probability 1/7 you'll hit 1.0 maybe printer
- labster 3y agoI don’t know man, putting microsoft.com on your router sounds like a massive reduction in latency. Congrats on the achievement.
- edgineer 3y agoWhat could a TLA do with this if it had time to plan ahead?
- timschmidt 3y agoServe malicious updates from a locally controlled machine, for one. Lord knows about auth.
- wrboyce 3y agoDo most DNS forwarders not block addresses that resolve to a local IP these days? I know dnsmasq does, and NextDNS too I think.
- donmcronald 3y agoI think most will see it as a DNS rebinding attack [1]. 1. https://en.wikipedia.org/wiki/DNS_rebinding https://en.wikipedia.org/wiki/DNS_rebinding
- wrboyce 3y agoThat’s the phrase I was looking for!
- drexlspivey 3y agoWhy? Having local IPs on a public DNS is a legitimate use case.
- wolverine876 3y agoIn fact, some people block domains by routing them to 127.0.0.1 in their host files. I've used private ranges too, in places where loopback might possibly do something funky.
- wrboyce 3y agoAs another reply mentioned, to prevent DNS rebinding attacks. The general expectation is you will whitelist domains from which you expect RFC1918 responses.
- keyle 3y agoDamn you Murphy's law.
- _nickwhite 3y agoAn entry-level admin is now unemployed, just before the holidays.
- 98codes 3y agoNah, if it's already reverted, they're good to go. A post-mortem with how something like that got through will definitely be on the table though.
- taspeotis 3y agoThe seniors all go on leave and the interns are left to run the place. If they fired the juniors the seniors would have to come back from holiday!
- johnnyanmac 3y agoI'm wondering how such a change would get "merged" in to begin with. I imagine even non-network engineers would get this huge itch having a large corporate contain a private IP in the changelist (I'm the non network engineer and can't really explain why it's bad. But it FEELS wrong and sometimes you at least need to use instinct to get another pair of eyes on something).
- blorenz 3y agoI hope not. Failures are on a spectrum and this was unfortunate but probably not malicious. All things considered this should be a lesson learned. There should be more failsafe mechanisms in place so juniors can fail safely and learn from them. The absolute worst thing we can do is shame an individual so they don’t attempt to try new things in fear of ridicule.
- wolverine876 3y ago> There should be more failsafe mechanisms in place so juniors can fail safely and learn from them. And if not, whoever put the junior in that role is the person responsible for the problem.
- 3y ago
- dvaun 3y agoMaybe Sydney tried to breakout…
- fouc 3y agoGood point. Let's watch Microsoft executives & employees closely for signs of panicking over an escaped AGI.
- quickthrower2 3y agoFor the uninitiated, can some traffic get sent to 192.168.1.1. Is it round robin?
- stop50 3y agoYes it is.
- YetAnotherNick 3y agoI could be wrong but in my experience OS just selects one random and uses that for some time not round robins it.
- quickthrower2 3y agoEven if that is the case, if it is random, some section of DNS would send traffic to it. Maybe it was OK because most resolvers would ignore the local address on the list??
- iameli 3y agoWait wait wait wait. Bunny.net accidentally changed their DNS to 127.0.0.1 and took a bunch of their CDN users down today too. Coincidence? Weird day.
- coolspot 3y agoEmployees mixing up SSH consoles while setting up their smart home Christmas lights over weekend.
- deleted 3y ago[deleted]
- ragebol 3y ago<singing voice="Chris Rea">Becoming 'home' for Christmas </singing>
- account42 3y agoProbably just developers trying to meet deliveries/targets before the holidays.
- Waterluvian 3y agoSo let me see if I understand. With this DNS record, if me or Windows tries to hit “microsoft.com” there’s a 1/7 chance it hit my router instead?
- aaomidi 3y agoYes
- bastard_op 3y agoHow the hell did that pass any sort of responsible review process at Microsoft? Now Microsoft owns all your home networks, only like the default address on every home router out there...
- nightfly 3y agoAny risk here is nearly the opposite of what you seem to think it is
- YetAnotherNick 3y agoNo, it's that when you open microsoft.com it could open your router page.
- CodeWriter23 3y ago> Now Microsoft owns all your home networks Only if you’re slumming around 192.168.x.x
- adolph 3y agoI for one only use Class A CIDR, 10.0.0.0/8
- CodeWriter23 3y agoSame
- horusthegame 3y ago[flagged]
- plorkyeran 3y agoYou have the danger of this backwards: this is a very bad security problem for Microsoft, and not a problem for people outside of MS (except to the extent that we're all indirectly reliant on MS being secure). Pointing a domain at an IP address does not give you any power over than IP address, and you can point a domain at anything you want.
- aaomidi 3y agoY'all, instead of the constant confirmed here. Just do an authoritative lookup. dig +trace +short microsoft.com NS a.root-servers.net. from server 100.100.100.100 in 10 ms. NS b.root-servers.net. from server 100.100.100.100 in 10 ms. NS c.root-servers.net. from server 100.100.100.100 in 10 ms. NS d.root-servers.net. from server 100.100.100.100 in 10 ms. NS e.root-servers.net. from server 100.100.100.100 in 10 ms. NS f.root-servers.net. from server 100.100.100.100 in 10 ms. NS g.root-servers.net. from server 100.100.100.100 in 10 ms. NS h.root-servers.net. from server 100.100.100.100 in 10 ms. NS i.root-servers.net. from server 100.100.100.100 in 10 ms. NS j.root-servers.net. from server 100.100.100.100 in 10 ms. NS k.root-servers.net. from server 100.100.100.100 in 10 ms. NS l.root-servers.net. from server 100.100.100.100 in 10 ms. NS m.root-servers.net. from server 100.100.100.100 in 10 ms. RRSIG NS 8 0 518400 20240101050000 20231219040000 46780 . fG/YHtUJu3YMAm9Mlzzvp3xG4UCPG01aYNnlyF1HfAHdZpR+L88CVUcz NFHq9M45KjB7ZTlSFt2JvEyK/8FcavZLOthkXRREbJQswjLCbhiPQCbq tQLF+tKaNYUihqawCfjgZy1i5YwYjmphbjfzwoKo1POtepf0YCIcuLBi nQFw4Lr79O6cjyg6qlYnqaK6z4Xi5qt6ocohJafjs86LuuRo2WvmJ1IK k0ZUoAC6Qyjz4MVhqHMvQGdp7EnzjoL8Y9PTXeUuD6Ixp/Aklj2psLjD TZDPYN1q+zDd1giFyuwNRX9DG1zrxzN2lzQiLWmGKrzP3DvFWL1L2Ts1 FWjy/Q== from server 100.100.100.100 in 10 ms. ;; UDP setup with 2001:502:7094::30#53(2001:502:7094::30) for microsoft.com failed: network unreachable. ;; UDP setup with 2001:502:7094::30#53(2001:502:7094::30) for microsoft.com failed: network unreachable. ;; UDP setup with 2001:502:7094::30#53(2001:502:7094::30) for microsoft.com failed: network unreachable. A 20.112.250.133 from server 150.171.10.39 in 20 ms. A 20.231.239.246 from server 150.171.10.39 in 20 ms. A 20.76.201.171 from server 150.171.10.39 in 20 ms. A 20.70.246.20 from server 150.171.10.39 in 20 ms. A 20.236.44.162 from server 150.171.10.39 in 20 ms. A 192.168.1.0 from server 150.171.10.39 in 20 ms.
- adolph 3y agoOr from a bunch of dnses: $ export srch="192.168.1.0"; echo "as of $(date '+%s';):"; for dns in 1.1.1.1 8.8.8.8 76.76.2.0 9.9.9.9 208.67.222.222 185.228.168.9 76.76.19.19 94.140.14.14; do dig @${dns} microsoft.com +short | grep "${srch}" > /dev/null; if [ $? == 0 ]; then echo "${dns} still has ${srch} for microsoft.com"; else echo "${dns} no longer has ${srch} for microsoft.com"; fi; done as of 1703033639: 1.1.1.1 still has 192.168.1.0 for microsoft.com 8.8.8.8 still has 192.168.1.0 for microsoft.com 76.76.2.0 still has 192.168.1.0 for microsoft.com 9.9.9.9 still has 192.168.1.0 for microsoft.com 208.67.222.222 still has 192.168.1.0 for microsoft.com 185.228.168.9 still has 192.168.1.0 for microsoft.com 76.76.19.19 still has 192.168.1.0 for microsoft.com 94.140.14.14 still has 192.168.1.0 for microsoft.com $ pbpaste | sed 's;^; ;' | pbcopy
- p1mrx 3y agomicrosoft.com is currently IPv6-only on my network, because OpenWrt's DNS rebinding protection filters out the A records: $ ping -4 microsoft.com ping: microsoft.com: Address family for hostname not supported $ ping -6 microsoft.com PING microsoft.com(2603:1030:c02:8::14 (2603:1030:c02:8::14)) 56 data bytes 64 bytes from 2603:1030:c02:8::14 (2603:1030:c02:8::14): icmp_seq=1 ttl=112 time=68.4 ms
- dan15 3y agoI'm surprised 192.168.1.0 is still there 2.5 hours later https://dnstools.ws/lookup/microsoft.com/A/ https://dnstools.ws/lookup/microsoft.com/A/
- TacticalCoder 3y agoWait... Can DNS resolvers be configured so that RFC1918 is respected? I mean: I don't expect anything less from Microsoft than doing stuff like that and it cannot affect me for I nullroute microsoft.com from my unbound server (unboud takes wildcard when nullrouting or NXDOMAINing crap domains like microsoft.com or meta.com etc., which is sweet). However I'd expect my trusty DNS resolver to also prevent me from anyone not on my private LANs to impersonate addresses reserved for private uses. Does anyone know here if it's easily doable?
- bewaretheirs 3y agoYes, some can. Unbound's "private-address" and "private-domain" directives control this. Similarly, bind9 has "deny-answer-addresses" (with an "except-from" option so you can specify local domains that are allowed to use them): https://bind9.readthedocs.io/en/v9.18.20/reference.html#content-filtering https://bind9.readthedocs.io/en/v9.18.20/reference.html#cont... Not sure about others.
- dgl 3y agoYou're looking for DNS rebinding protection, many DNS servers support it. However there are some cases where things do use private IPs in DNS records outside of the local domain, one example is Plex (e.g. https://support.plex.tv/articles/206225077-how-to-use-secure-server-connections/ https://support.plex.tv/articles/206225077-how-to-use-secure... suggests turning off DNS rebinding protection) -- although in some cases you can allow particular domains which is a much better way than turning it off entirely. (See also the sibling comment about microsoft.com being IPv6 only as a result of a particular implementation of DNS rebinding protection: https://news.ycombinator.com/item?id=38704159 https://news.ycombinator.com/item?id=38704159)
- WarOnPrivacy 3y agoMy Unbound servers strip RFC out. Public resolvers keep DNS answers intact because they can carry alt data like how dodgy a SMTP server is.
- icedchai 3y agoI wouldn't expect it to. I have plenty of RFC-1918 addresses in a subdomain of my public DNS zone for my home network. It's been that way for decades. (Perhaps I should use split DNS, but...)
- lsago 3y agoI was getting an empty answer for microsoft.com. Turns out my dnsmasq is blocking it: $ dig microsoft.com. | grep EDE ; EDE: 15 (Blocked) resolver.log:Dec 20 00:43:57 router dnsmasq[8172]: possible DNS-rebind attack detected: microsoft.com
- whatever1 3y ago[flagged]
- tills13 3y agoYes, even experts make mistakes.
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]
- apapapa 3y agoThey probably asked copilot to manage their DNS servers
- monomyth 3y ago"help us bring Microsoft to every home's network"
- barryrandall 3y agoAI-driven type coercion is a new type of debugging hell.
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]
- sk921 3y agostumbled on this thread, my device just got blocked by my at home router. My dns is 192.168.1.1, any suggestions for how to troubleshoot this?
- deleted 3y ago[deleted]
- Pliskin 3y agoWas someone able to generate a *.microsoft.com SSL certificate when doing domain validation on non-microsoft machine ?
- invig 3y ago"Works on my machine"
- Ameliabrnnr 3y agoEmployees mix up SSH consoles while setting up their smart home Christmas lights over the weekend. https://www.rtasks.online/ https://www.rtasks.online/
- devilsAdv0cate 3y ago[dead]