3 ms·
Perhaps more critically, twimg.com (and now Twitter, it seems) has also been compromised. Both share the MelbourneIT registrar. $ whois -h whois.melbourneit.co
by semenko 13y ago
Perhaps more critically, twimg.com (and now Twitter, it seems) has also been compromised. Both share the MelbourneIT registrar.
$ whois -h whois.melbourneit.com twitter.com -> now owned by sea@sea.sy (Syrian Electronic Army)
The name servers for the Times have been switching back-and-forth for a while. I've chronicled most of it at https://twitter.com/semenko https://twitter.com/semenko
- grey-area 13y agoOuch. If twitter is compromised, sites serving twitter js (which is a lot of sites) are potentially compromised too. I've just checked and at least some widgets from twitter are down at present (all?), twimg.com is not responding. DNS and registrars is a bit of a weak point at present in site security, as once they have that, they can serve users whatever they like. It would be even more damaging and hard to detect if they just tweaked content slightly for a few hours by adjusting some words in stories for some countries rather than hijacking sites.
- semenko 13y agoWell, luckily, Twitter's domains & cert are added to the Chrome HSTS pins list, so Chrome should just serve a scary security error. Looks like their WHOIS data has reverted to normal. Not sure the NS records ever changed (though the contact data did).
- jacquesm 13y agoOne HN'er suggested a tweak to HTML where a hash of the js is taken along with the <script> tag to allow the browser to verify if the js has been modified. Of course this assumes that the js is static and that there are no upgrades to the code. Another option would be to do this as a service but then you'd immediately have another attack vector as well.