7 ms·
NYTimes.com down for some users; paper suspects “external attack”
- j2d3 13y agoHacked by the SEA
- j2d3 13y agoI alternately get the message "Hacked by the SEA" (to my dismay I've been informed this is the Syrian Electronic Army, not the Symbionese Electronic Army...), or a redirect to http://www.boxsecured.com/high_cpu.html http://www.boxsecured.com/high_cpu.html - a 404 error saying hi_cpu.html is not found.
- semenko 13y agoPerhaps more critically, twimg.com (and now Twitter, it seems) has also been compromised. Both share the MelbourneIT registrar. $ whois -h whois.melbourneit.com twitter.com -> now owned by sea@sea.sy (Syrian Electronic Army) The name servers for the Times have been switching back-and-forth for a while. I've chronicled most of it at https://twitter.com/semenko https://twitter.com/semenko
- grey-area 13y agoOuch. If twitter is compromised, sites serving twitter js (which is a lot of sites) are potentially compromised too. I've just checked and at least some widgets from twitter are down at present (all?), twimg.com is not responding. DNS and registrars is a bit of a weak point at present in site security, as once they have that, they can serve users whatever they like. It would be even more damaging and hard to detect if they just tweaked content slightly for a few hours by adjusting some words in stories for some countries rather than hijacking sites.
- semenko 13y agoWell, luckily, Twitter's domains & cert are added to the Chrome HSTS pins list, so Chrome should just serve a scary security error. Looks like their WHOIS data has reverted to normal. Not sure the NS records ever changed (though the contact data did).
- jacquesm 13y agoOne HN'er suggested a tweak to HTML where a hash of the js is taken along with the <script> tag to allow the browser to verify if the js has been modified. Of course this assumes that the js is static and that there are no upgrades to the code. Another option would be to do this as a service but then you'd immediately have another attack vector as well.
- donohoe 13y ago"Syrian Electronic Army claims to have taken control of Twitter.com domain registration" http://www.cnbc.com/id/100988772 http://www.cnbc.com/id/100988772 Tweet with some info regarding Twitter & NYT: https://twitter.com/jaesonschultz/status/372456943312330753 https://twitter.com/jaesonschultz/status/372456943312330753
- deleted 13y ago[deleted]
- AndyJPartridge 13y agoPeople viewing your views and cause, I guess. Due to the worlds media being very selective about what appears, and the tone or context in which it is written, sometimes this is the only way to get your word out. "Your word" being highly subjective. Having the www.nytimes.com traffic being sent to your blog is probably one of the best things you can do. Back in the day, leaflets were dropped from planes that contained what you wanted people to read. This is the much easier, and much much cheaper, way of achieving that aim. EDIT: Removed the joke.
- fatjokes 13y agoNow I want to know what the joke was.
- AndyJPartridge 13y agoI said "...and click an advert or two."
- chc 13y agoI'd imagine it's similar to North Korea's growing online presence: "This is the information about Syria that we want you to know."
- mmmooo 13y agonameservers changed at registrar, gltd reports accordingly. nytimes.com. 172800 IN NS ns27.boxsecured.com. nytimes.com. 172800 IN NS ns28.boxsecured.com. ;; Received 114 bytes from 192.41.162.30#53(192.41.162.30) in 17 ms
- paul_f 13y agoOK, then, the key question is: which registrar are they using and how do that registrar's security get compromised?
- AsymetricCom 13y agoNYTimes DNS has been hyjacked to redirect to SEA Blog (Syrian Electronic Army). Here I mirror the front page and some of the linked content from the English version of the page. You can see the page yourself by using FireFox or another browser besides Chrome that allows you to accept non-standard and mismatched certs. The JavaScript doesn't appear to be malicious, but I'm not an expert. _ * Latest News * Syrian Electronic Army Facebook Page | Number : 220 After the Facebook management shut down the page number 219 The new page link : https://www.facebook.com/SEA.Official.220 https://www.facebook.com/SEA.Official.220 .. Read More... Syria Tube is a page on the social network Facebook it was created in 4/4/2011 in order to publish all the videos of what happening in Syria and the right news about Syria The new page link after the Facebook management closed the main page: https://www.facebook.com/Syria.Tube.Official https://www.facebook.com/Syria.Tube.Official https://www.facebook.com/SEA.Official.220 https://www.facebook.com/SEA.Official.220 _ * Latest Hacks * Time, CNN and WashingtonPost Websites Hacked The Syrian Electronic Army hacked today into Outbrain service and take control of admin panel. The security breach affects CNN, Washington Post, Time and more high profile websites. Outbrain is a content recommendation service whose widget offers to help internet publishers incre.. Read More... Time, CNN and WashingtonPost Websites Hacked Publish date: 2013-08-15 17:10:34 | Views number: 1559 The Syrian Electronic Army hacked today into Outbrain service and take control of admin panel. The security breach affects CNN, Washington Post, Time and more high profile websites. Outbrain is a content recommendation service whose widget offers to help internet publishers increase web traffic at their websites. It does so by presenting them with links to articles and other content. The admin panel of Outbrain is hosted in the local server. However, the SEA hackers managed to login into the panel with the help of VPN and access panel. Zone-H Mirrors : http://www.zone-h.org/mirror/id/20533795 http://www.zone-h.org/mirror/id/20533795 http://www.zone-h.org/mirror/id/20533808 http://www.zone-h.org/mirror/id/20533808 ScreenShots of the Outbrain Administration Pa _ * Media * Syrian state television claims that a pro-government group has hacked into two social messaging networks and seized records of local users. Such a hack could expose Syrian rebels and other activists who depend on the networks to publicize army crackdowns on their hometowns and communicate with each other. Landlines and cell phones are believed to be tapped in Syria. State TV says the social networking site Tango was hacked on Sunday by the Syrian Electronic Army. The Syrian Electronic Army is a shadowy group that supports President Bashar Assad's regime. There was no immediate comment from Tango. Syrian media says another network -- Truecaller -- also was hacked last week. Truecaller said in a statement posted on their website that it had been the target of a cyber-attack. Source: Fox News Some website's talked too about the attack: http://www.foxnews.com/world/2013/07/21/pro-assad-group-hacks-messaging-networks-syrian-state-television-says/?test=latestnews http://www.foxnews.com/world/2013/07/21/pro-assad-group-hack... http://news.softpedia.com/news/Syrian-Electronic-Army-Hacks-Mobile-Messaging-Service-Tango-369644.shtml http://news.softpedia.com/news/Syrian-Electronic-Army-Hacks-... http://www.idigitaltimes.co.uk/articles/492642/20130720/syrian-electronic-army-hacks-tango-messaging-application.htm http://www.idigitaltimes.co.uk/articles/492642/20130720/syri... http://hackread.com/mobile-messaging-service-tango-hacked-by-syrian-electronic-army/ http://hackread.com/mobile-messaging-service-tango-hacked-by... http://thehackernews.com/2013/07/Tango-messenger-hacked-Syrian-Electronic-Army.html http://thehackernews.com/2013/07/Tango-messenger-hacked-Syri... http://threatpost.com/sea-hacks-messaging-app-tango-steals-user-information http://threatpost.com/sea-hacks-messaging-app-tango-steals-u... _ * Leaks * Office of Qatar Emir's mother forces ISP to block SEALeaks website from Google searches/Qatari DNS Office of Emir's mother forces ISP to block SEA | Leakks website from Google searches/Qatari DNS And here is the reply of the ISP: The Syrian Electronic Army obtained the emails after it hacked into Moza mail system .. Read More... SEA Publishes Turkish Ministry of Interior Emails and Passwords Latest Hacks | Media | Leaks | Mobile Version From The Pictures Library :: From The Videos Library :: SEA gave a visit to Social Flow Website/Accounts Office of Qatar Emir's mother forces ISP to block SEALeaks website from Google searches/Qatari DNS [image of email] http://i.imgur.com/gFJQX4W.png http://i.imgur.com/gFJQX4W.png Publish date: 2013-06-29 16:00:20 | Views number: 4862 Office of Emir's mother forces ISP to block SEA | Leakks website from Google searches/Qatari DNS And here is the reply of the ISP: [image content broken] _ * Battalions * Vict0r Battalion | The Shadow Battalion | Th3Pr0 Battalion http://blog.thepro.sy/ http://blog.thepro.sy/ | https://www.facebook.com/SEA.Vict0r.2?_fb_noscript=1 https://www.facebook.com/SEA.Vict0r.2?_fb_noscript=1 _ * Martyrs * Martyr Mohammed Qabbani Martyr Mohammed Qabbani Martyr Lorans Barakat _ * About SEA * The Spark of the Launch The SEA created in 2011 when the Arab media and Western started bias in favor of terrorist groups that have killed civilians, the Syrian Arab Army and the destruction of private and public property, was the Arab media and western form a cover for the continuation of these groups, their actions through the blackout on terrorism in Syria and paste all charges Army Syrian and charged with murder and sabotage... Read More The Mechanism | The Funding | The Vision
- deleted 13y ago[deleted]
- jacquesm 13y agoIn everything associated with the situation in Syria beware of the possibility of false-flag operations.
- deleted 13y ago[deleted]
- jacquesm 13y agoEven more unlikely: the SEA itself could be a false flag operation... At a risk of putting on a tinfoil hat some of the Syrian activity as of late seems mighty convenient, practically an invitation to a couple of cruise missiles or something with similar effects. For all I know this is genuine but it is very hard to be 100% sure of anything like this as an outside observer. It wouldn't be the first time false flag operations were used to create sympathy in the populace for some war or to demonize a party. http://en.wikipedia.org/wiki/Gleiwitz_incident http://en.wikipedia.org/wiki/Gleiwitz_incident http://en.wikipedia.org/wiki/Gulf_of_Tonkin_incident http://en.wikipedia.org/wiki/Gulf_of_Tonkin_incident (disputed) http://en.wikipedia.org/wiki/Operation_Ajax http://en.wikipedia.org/wiki/Operation_Ajax
- jordanb 13y agoKinda crazy that the Europeans have decided that Obama is war mongering considering there is no possible American interest in getting into this mess, and just a few weeks ago the administration was arguing about the finer points of the meaning of the word 'chemical.' EDIT: Ok so with respect to your insinuation about "American interests," honestly, I'd like to hear what you think they are. Obama called the situation in Libya a "shit sandwich," and as far as I can tell Syria is a shit hoagie. So I'd really like to know what can be gained in Syria other than brownie points from knowing we upheld the R2P. With respect to Powell and Iraq, I'd observe that Kerry is not Powell, Obama is not Bush, Syria is not Iraq, and the evidence at hand isn't curveball and yellowcake. Bringing up Powell and Iraq while ignoring the particulars of that event and this event is sloppy reasoning. I haven't personally seen any evidence that Obama "rushing to bomb" anyone. I've seen months and months of the Obama administration trying to figure out how they are going to wipe their hands of this mess, and a week of them deciding that they can't. But on the whole I agree that you can't "un-bomb" someone, but you also can't spool back a massacre, and you can't uphold the R2P after-the-fact. We learned that in Rwanda.
- tysone 13y agoWe are now publishing at a backup site: http://news.nytco.com http://news.nytco.com
- deleted 13y ago[deleted]
- hughesey 13y agoNS records pointing to Syrian Electronic Army - http://viewdns.info/dnsrecord/?domain=nytimes.com http://viewdns.info/dnsrecord/?domain=nytimes.com
- kalleboo 13y agoWhy the heck are both Twitter and the New York Times using a in the context small Australian registrar? (MelbourneIT) edit: looks like MelbourneIT do DNS for a ton of big names. really really weird.
- ejdyksen 13y agoI'm wondering this, too. Does MelbourneIT have some sort of service or reputation that makes it attractive to large companies like Twitter or NYTimes?
- philip1209 13y agoOpenDNS blocked the Syrian domains and updated its DNS resolvers to omit them: https://twitter.com/davidu/status/372482424313110529 https://twitter.com/davidu/status/372482424313110529 Verify at: http://www.opendns.com/support/cache/ http://www.opendns.com/support/cache/
- nrmilstein 13y agoYou can still get to the New York Times by going to their IP address: http://170.149.168.130/ http://170.149.168.130/