10 ms·
Details Behind Today's Internet Hacks
- martin_ 13y agoThe details actually look pretty sparse. I'm looking forward to MelbourneIT letting us know the specifics (if they do!).
- pfraze 13y agoParticularly the malware. Is this related to the Google Palestine hacking yesterday? Somebody linked the hacked site and it hit top of HN, so a number of us had to have clicked through to it.
- dibbsonline 13y agoGood to see the MelbsIT product using two factor auth.
- signed0 13y agoAre there any registrars that allow one to set serverDeleteProhibited, serverTransferProhibited, and serverUpdateProhibited?
- D4M14N 13y agoI believe MelbourneIT do (twitter.com has it set and they are registered there)
- dknecht 13y agoYes. CloudFlare has it set that way with Network Solutions.
- ballard 13y agoProbably $$$$, but .... http://reports.internic.net/cgi/whois?whois_nic=microsoft.com&type=domain http://reports.internic.net/cgi/whois?whois_nic=microsoft.co... Domain Name: MICROSOFT.COM Registrar: MARKMONITOR INC. Whois Server: whois.markmonitor.com Referral URL: http://www.markmonitor.com Name Server: NS1.MSFT.NET Name Server: NS2.MSFT.NET Name Server: NS3.MSFT.NET Name Server: NS4.MSFT.NET Name Server: NS5.MSFT.NET Status: clientDeleteProhibited Status: clientTransferProhibited Status: clientUpdateProhibited Status: serverDeleteProhibited Status: serverTransferProhibited Status: serverUpdateProhibited Updated Date: 09-aug-2011 Creation Date: 02-may-1991 Expiration Date: 03-may-2021
- dimitar 13y agoI think most of them do, contrary to the article. I have to deal with this all the time. DomainPeople does have the feature. It is also the registrar for Gate.com and Hostway.
- signed0 13y agoHmm, I was unable to do so on Namecheap or Gandi.
- otterley 13y agoI'm not sure it would have helped in this instance. If the attacker got access to the administrative interface for the registrar, all he'd have to do is unset the relevant flag first, using the same interface, before changing the name server records. These flags are the functional equivalent of forcing you to break a piece of glass before pushing the fire alarm button.
- WestCoastJustin 13y ago> Technical teams from CloudFlare, OpenDNS and Google jumped on a conference call and discovered what appeared to be malware on the site to which the NYTimes.com site was redirected. On the HN post "Google.ps domain was hacked (google.ps)" [1], HN user biot predicted this exact scenario, although not a zero day most likely. He talked about submitting hacked sites to HN "... and thousands of HN readers get infected by a zero-day exploit. Maybe. If you're thinking of submitting a known compromised site to HN, consider instead submitting a third-party site which explains/documents the compromise. Ideally from a respected security research company". [2] [1] https://news.ycombinator.com/item?id=6278737 https://news.ycombinator.com/item?id=6278737 [2] https://news.ycombinator.com/item?id=6279253 https://news.ycombinator.com/item?id=6279253
- Cyranix 13y agoI'd suggest extending the idea to non-responsive sites as well. Instead of submitting a link to a company's homepage when they're being DDOSed or are otherwise unavailable, submit a link to their status page if they have one or, failing that, use a third-party indicator. Off the top of my head I can't think of a third-party indicator that would capture point-in-time availability, but a manually crafted URL like http://isup.me/example.com?1970-01-01T00:00:00Z http://isup.me/example.com?1970-01-01T00:00:00Z would get the point across just fine.
- joshschreuder 13y agoMaybe something like Zapier's API Status Board, though I'm not sure how realtime and whether it only applies to site's APIs rather than their general websites. https://zapier.com/status/ https://zapier.com/status/
- bryanh 13y agoIt applies to their APIs specifically. It is realtime within ~5 minutes.
- holdenc 13y agoSo, if my DNS is hacked, I can call Google and OpenDNS and have them correct my records upstream? And then contact Verisign for a registry lock? And expect a personal response from MelbourneIT (even though it's likely their reseller's fault)? This is great news!
- eastdakota 13y agoIf you're the paper of record, yes.
- ars 13y agoIf your personal DNS is hacked? Probably not. But if your entire registry is hacked? Probably yes, assuming you have sufficient credibility for them to notice you.
- alien_acorn 13y ago> The correct name servers should have been DNS.EWR1.NYTIMES.COM and DNS.SEA1.NYTIMES.COM. How does this work? How would you get to DNS.EWR1.NYTIMES.COM without first knowing where nytimes.com is?
- zhoutong 13y agoNameservers have their IPs registered with the registry, and they are returned in the additional answers section. These are called "glue records".
- teddyh 13y agoThe top level servers (for .com in this case) has A (and/or AAAA) records for the name servers to prevent this kind of catch-22. These out-of zone records are called glue records.
- pavs 13y agoBasically zero information. They keep telling us how MelbourneIT is usually more secure but doesn't do on to tell us how it is any more secure than other registrars. More importantly, even with admin access to to their control panel how can it be so easy to change registry information of such high profile sites with a click of a button?
- throwaway86 13y agoDevilishly clever marketing for Cloudflare, though. Clearly I need to spend my days on more bridge calls for situations affecting other ops teams that have nothing to do with me, so my company can put out a PR piece from a position of authority about how awesome we are. What exactly did a team of people at Cloudflare do today? Consult? Do you bill hourly or is it a friendly NYT discount? What was your plan connecting end users with recursive operators? Want them to manually flush their resolvers out of the normal DNS TTL protocol? Is that a service that comes with my Cloudflare subscription? Next time a startup goes down, ask yourself: if I were on a bridge call with their ops team, could I use this to sell my company's reliability product? Clearly, the answer is yes. Classy, too, jumping out in front of MelbourneIT's response then speculating on it. I would be furious about Cloudflare writing a details-thin "postmortem," headlining it as a postmortem, analyzing my initial statement to customers in it, then getting it on HN before DNS caches are even cold from the incident itself. It's not even subtle. This is the sort of thing I remember in discussions about using Cloudflare. There's lots of choices for CDNs, a market growing surprisingly full of ambulance chasers: one CDN startup had the fucking courage to email me directly after a hellish multi-hour outage and say "want to set up a call to discuss how our product could have prevented this outage?" I was still awake from fixing the problem overnight and no, your CDN is not going to fix my catastrophic DB failure. Get bent. This is a disgusting move by Cloudflare. The little human network signoff made me gag; don't forget, small ops teams, you will only get things done if you know people. Notice HuffPo wasn't on the call? Exactly.
- solistice 13y agoDidn't they pull a similar story telling people an attack on them by Cyberbunker impacted the London Internet Exchange, prompting quite some pandemonium? I remember there being a more somber post after the whole incident by another blog detailing just how little fluctations there were on the alleged day of the incident, and how the numbers didn't stack up. Cloudflare is tricky, isn't it?
- willvarfar 13y ago> At 1:19pm (PDT) today, a researcher noticed that the New York Times' website wasn't loading. So if the content on the redirected page had been more subtle - for example, mirroring NYTimes but editing stories etc - then things would have taken a lot longer to have been noticed?
- nly 13y agoHow would setting the registrar lock have helped in this case? The registrar lock can be unlocked by the current registrar... which was the target in this case. It's good advice, but seems kind of irrelevant. > It's worth noting that while some of Twitter's utility domains were redirected, Twitter.com was not -- and Twitter.com has a registry lock in place.
- eastdakota 13y agoregistry lock != registrar lock The former is with Verisign and cannot easily be removed by the registrar. The latter is with the registrar and can be removed by the registrar. In whois status codes "clientXXX" = registrar lock (weak). "serverXXX" = registry lock (stronger).
- damian2000 13y agoI'm amazed that Melbourne IT seem to be held in high regard these days. Going back to the 1990s, they had a monopoly on Australian domain registration, they charged the earth, and had really crap customer service.
- WatchDog 13y agoI've only heard bad things about them.
- peterwwillis 13y agoI'll bet five dollars the credentials were stolen by a botnet the SEA runs or has access to. You wouldn't believe the shit that pops up sometimes. (It's also incredibly trivial to take over botnets run by jackasses who took a tutorial in setting up Zeus) Less likely but still highly possible would be spear phishing of registrar resellers. Edit: I don't know why, but the nameservers I use don't resolve any address for nytimes.com now. If I query 8.8.8.8 directly I get a response. So, could be they're still suffering from this attack, which sucks.
- agwa 13y ago> MelbourneIT has traditionally been known as one of the more secure registrars They were one of the registrars compromised back in May as part of Hack the Planet[1]. If I recall correctly, they were the only registrar where the attackers actually got shell access on a server. That's when they lost any reputation for security in my eyes. [1] http://www.theregister.co.uk/2013/05/09/melbourne_it_hacking/ http://www.theregister.co.uk/2013/05/09/melbourne_it_hacking...
- dotBen 13y agoI don't think I understand why CloudFlare was involved - do they provide services to NYT, it isn't clear from the post that they do.
- throwaway86 13y agoNo, they're the concerned citizen that performed first aid on the motorist, then hung around to take questions from the media.