TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Twitter, NYT Whois and DNS altered, Syrian Electronic Army takes responsibility

163 pointsby jpadilla_over 11 years ago

22 comments

dobbsbobover 11 years ago
US is about to bomb Syrian military assets so this is Iran&#x27;s response. The SEA is clearly Iranian. Email them something in Farsi or PM one of their propaganda accounts on youtube they usually answer.<p>last time I checked ns1.syrianelectronicarmy.com was hosted out of Russia and includes &quot; qatar-leaks.com&quot; which seems to have disappeared
评论 #6287499 未加载
cpursleyover 11 years ago
&quot;We are protecting you from the hacker-terrorists&quot;<p>Is this not obvious to everyone else as it is to me? People, think about what is happening here and the timing of it all.<p>This is a false flag operation to turn the public opinion against &quot;hackers&quot; so these crazy internet regulations bills can start passing and so that they can get away with spying scandal.<p>If these &quot;hackers&quot; taking down social media sites and NYT times were actually the Syrian government, they&#x27;d be going after US government targets in an effort to undermine the bombing that&#x27;s about to begin.<p>Their regime is about to get bombed. Taking down twitter is low on their priority list. But it&#x27;s quite good timing for a propaganda campaign against &quot;hackers&quot; and now allows the US government to label hackers as terrorists. Scary stuff.
评论 #6287239 未加载
评论 #6287167 未加载
评论 #6287205 未加载
评论 #6287069 未加载
评论 #6287131 未加载
评论 #6287231 未加载
评论 #6287286 未加载
bluetideproover 11 years ago
As someone asked in the comments of the article asked (no response yet), I&#x27;m curious myself...<p>&gt; &quot;<i>twimg.com is a domain used by Twitter which is an widget company that is part of a network of sites, cookies, and other technologies used to track you, what you do and what you click on, as you go from site to site, surfing the Web. Does that not mean that SEA will be intercepting this data?</i>&quot;
评论 #6287233 未加载
评论 #6286715 未加载
jvalover 11 years ago
Ok, firstly whois Microsoft.com just returns all URLs with Microsoft.com in them, even as a subdomain, so they haven&#x27;t been hacked and that result has been there for ages. Same goes for Verisign etc.<p>TechCrunch is reporting that registrar MelbourneIT has been hacked.. This wouldn&#x27;t surprise me but I&#x27;m puzzled as to why either site would register with such a bad registrar.
评论 #6287024 未加载
评论 #6286891 未加载
评论 #6289837 未加载
评论 #6286858 未加载
grumpsover 11 years ago
How hard is this to do...<p>I ask because I find it harder to believe that they are responsible for this. Just like I don&#x27;t trust the YouTube videos either. I would find it more likely that three letter agencies are involved as PR.
评论 #6286628 未加载
nfozover 11 years ago
Don&#x27;t trust anything you read here, folks...... too many that don&#x27;t know anything about WHOIS or DNS.....
评论 #6287905 未加载
评论 #6287282 未加载
Shankover 11 years ago
While they may have fixed twimg.com on the DNS level, changes are still taking forver to propogate back out. Right now I&#x27;m still getting no data from it.<p>To add to the matter, SEA is certainly aware of this:<p>&quot;So, do we host <a href="http://twimg.com" rel="nofollow">http:&#x2F;&#x2F;twimg.com</a> with Javascript code so all Twitter users will be redirect to our website? #SEA&quot;<p><a href="https://twitter.com/Official_SEA16/status/372496956020379648" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;Official_SEA16&#x2F;status&#x2F;372496956020379648</a>
fotcornover 11 years ago
The twitter frontpage is completly broken for me. Static assets like css and javascript are served by twimg.com, which are now missing. If SEA has access to a server which can take the load of twimg.com, they can inject their Javascript and possible exploits to ALL twitter users...
评论 #6287112 未加载
signed0over 11 years ago
Woah! Has Verisign been hacked?<p>$ whois twitter.com<p>Whois Server Version 2.0<p>Domain names in the .com and .net domains can now be registered with many different competing registrars. Go to <a href="http://www.internic.net" rel="nofollow">http:&#x2F;&#x2F;www.internic.net</a> for detailed information.<p>TWITTER.COM.GET.ONE.MILLION.DOLLARS.AT.WWW.UNIMUNDI.COM<p>TWITTER.COM<p>And then:<p>$ whois verisign.com<p>Whois Server Version 2.0<p>Domain names in the .com and .net domains can now be registered with many different competing registrars. Go to <a href="http://www.internic.net" rel="nofollow">http:&#x2F;&#x2F;www.internic.net</a> for detailed information.<p>VERISIGN.COM.MIGHT.SUCK.FYRAE.COM<p>VERISIGN.COM<p>I get really crazy responses like this for almost every major site I try (cnn.com, yahoo.com, google.com).
评论 #6286716 未加载
评论 #6286699 未加载
评论 #6287094 未加载
评论 #6287420 未加载
pain_perduover 11 years ago
DNS Records have been hijacked and point to Syrian Electronic Army<p><a href="http://i.imgur.com/RwH0mpI.png" rel="nofollow">http:&#x2F;&#x2F;i.imgur.com&#x2F;RwH0mpI.png</a>
mpchletsover 11 years ago
So not sure what to say, but this is the email I received from DynEct the other day: subject: Webinar Wednesday: Are You Prepared For DNS Disaster? sender: Dyn hello@dyn.com via dynect-mailer.net<p>and some info from my old whois: $ whois twitter.com<p>Whois Server Version 2.0<p>Domain names in the .com and .net domains can now be registered with many different competing registrars. Go to <a href="http://www.internic.net" rel="nofollow">http:&#x2F;&#x2F;www.internic.net</a> for detailed information.<p><pre><code> Server Name: TWITTER.COM.GET.ONE.MILLION.DOLLARS.AT.WWW.UNIMUNDI.COM IP Address: 209.126.190.71 Registrar: PDR LTD. D&#x2F;B&#x2F;A PUBLICDOMAINREGISTRY.COM Whois Server: whois.PublicDomainRegistry.com Referral URL: http:&#x2F;&#x2F;www.PublicDomainRegistry.com Domain Name: TWITTER.COM Registrar: MELBOURNE IT, LTD. D&#x2F;B&#x2F;A INTERNET NAMES WORLDWIDE Whois Server: whois.melbourneit.com Referral URL: http:&#x2F;&#x2F;www.melbourneit.com Name Server: NS1.P34.DYNECT.NET Name Server: NS2.P34.DYNECT.NET Name Server: NS3.P34.DYNECT.NET Name Server: NS4.P34.DYNECT.NET</code></pre>
InclinedPlaneover 11 years ago
Last update on status.twitter.com was August 6th.<p>Get your shit together guys, this is serious business.<p>Edit: looks like there&#x27;s an update now: <a href="http://status.twitter.com/post/59528478030/twitter-service-issue" rel="nofollow">http:&#x2F;&#x2F;status.twitter.com&#x2F;post&#x2F;59528478030&#x2F;twitter-service-i...</a>
dimitarover 11 years ago
Why hasn&#x27;t the SEA changed the nameservers?
评论 #6286686 未加载
评论 #6286634 未加载
unreal37over 11 years ago
Whoa. Twitter, NYTimes, HuffPo... all had their DNS records hacked? This seems huge.
评论 #6289854 未加载
评论 #6286851 未加载
mpchletsover 11 years ago
Seems to me that melbourneit.com was the cause of these problems - that is the related link between all these different problems - basically poisoning the DNS of any popular company that uses them.
ninjazee124over 11 years ago
NYTimes seems to be down and Twitter is be loading all wrong because twimg.com is down. Whoa! This is some serious stuff.
评论 #6287243 未加载
unhammerover 11 years ago
Is this what DNSSEC is supposed to protect you from? (Or could they just change your dnssec records as well?)
jeremycoleover 11 years ago
twimg.com seems to be hijacked
评论 #6286850 未加载
flaktrakover 11 years ago
this is about all the Syrian govt can retaliate with. it&#x27;s not like they can physically reach and stop the USA from attacking them.
N0RMANover 11 years ago
the traceroute for twimg.com end&#x27;s in russia, I&#x27;m right? (141.105.64.37)
评论 #6287713 未加载
Questionoorover 11 years ago
SEA has a history of doing much more than attempting to offset perceived propaganda[1]. With in that site is dozens of gigabytes of logs from Bluecoat[2] proxy hardware that sat in datacenters for Syrian ISPs.<p>A good amount of what is contained in the logs is things like porn searches, more porn, porn. But amongst the typical naughty bits things like religious queries for Christians, Catholics, Jews, Muslims were being recorded.<p>Telecomix[3] helped to leak the log-set, and as it stands it is _the_ example of how state entities monitor peoples of &#x27;interest.&#x27; Much of these people are long since dead, killed early on as they were the most public[4].<p>So while the SEA&#x27;s most public facing events are hijacks, phising, and massive redirects. Please do focus on the end result of pervasive surveillance[5].<p>[1] <a href="http://bluesmote.com/" rel="nofollow">http:&#x2F;&#x2F;bluesmote.com&#x2F;</a><p>[2] <a href="http://www.bluecoat.com/" rel="nofollow">http:&#x2F;&#x2F;www.bluecoat.com&#x2F;</a><p>[3] <a href="http://en.wikipedia.org/wiki/Telecomix" rel="nofollow">http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Telecomix</a><p>[4] <a href="http://en.wikipedia.org/wiki/Ibrahim_Qashoush" rel="nofollow">http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Ibrahim_Qashoush</a><p>[5] <a href="http://imgur.com/gallery/qz7wm" rel="nofollow">http:&#x2F;&#x2F;imgur.com&#x2F;gallery&#x2F;qz7wm</a>
评论 #6287040 未加载
fudyyover 11 years ago
Sorry to be cynical and bring politics into this, but I hope that U.S. liberals respond the way they did to Bush to Obama with this strike.<p>Comedians, the media, etc. accused Bush of an adjust war for someone that used a chemical attack on his own people because there were no found WMD&#x27;s even though there was evidence of a chemical attack.<p>Now we are going in again to try to save things. Will Obama come out as a hero? Probably. Should he? Well if he should, Bush needs to get some slack finally.<p>Don&#x27;t get me wrong- I think we should do something. But when I hear we are going to do another 3 day bombing run, it&#x27;s just like Iraq all over again, except this time it&#x27;s who the Democrats want to bomb. Isn&#x27;t there an answer that doesn&#x27;t involve bombing? What are we, Germany in WWII?
评论 #6288132 未加载
评论 #6288152 未加载