TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Details Behind Today's Internet Hacks

140 pointsby dknechtover 11 years ago

13 comments

WestCoastJustinover 11 years ago
&gt; <i>Technical teams from CloudFlare, OpenDNS and Google jumped on a conference call and discovered what appeared to be malware on the site to which the NYTimes.com site was redirected.</i><p>On the HN post <i>&quot;Google.ps domain was hacked (google.ps)&quot;</i> [1], HN user <i>biot</i> predicted this exact scenario, although not a zero day most likely. He talked about submitting hacked sites to HN <i>&quot;... and thousands of HN readers get infected by a zero-day exploit. Maybe. If you&#x27;re thinking of submitting a known compromised site to HN, consider instead submitting a third-party site which explains&#x2F;documents the compromise. Ideally from a respected security research company&quot;.</i> [2]<p>[1] <a href="https://news.ycombinator.com/item?id=6278737" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=6278737</a><p>[2] <a href="https://news.ycombinator.com/item?id=6279253" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=6279253</a>
评论 #6290926 未加载
pavsover 11 years ago
Basically zero information. They keep telling us how MelbourneIT is usually more secure but doesn&#x27;t do on to tell us how it is any more secure than other registrars. More importantly, even with admin access to to their control panel how can it be so easy to change registry information of such high profile sites with a click of a button?
评论 #6288686 未加载
willvarfarover 11 years ago
&gt; At 1:19pm (PDT) today, a researcher noticed that the New York Times&#x27; website wasn&#x27;t loading.<p>So if the content on the redirected page had been more subtle - for example, mirroring NYTimes but editing stories etc - then things would have taken a lot longer to have been noticed?
signed0over 11 years ago
Are there any registrars that allow one to set serverDeleteProhibited, serverTransferProhibited, and serverUpdateProhibited?
评论 #6288265 未加载
评论 #6288335 未加载
评论 #6288291 未加载
评论 #6288260 未加载
评论 #6288248 未加载
holdencover 11 years ago
So, if my DNS is hacked, I can call Google and OpenDNS and have them correct my records upstream? And then contact Verisign for a registry lock? And expect a personal response from MelbourneIT (even though it&#x27;s likely their reseller&#x27;s fault)? This is great news!
评论 #6288452 未加载
评论 #6288461 未加载
martin_over 11 years ago
The details actually look pretty sparse. I&#x27;m looking forward to MelbourneIT letting us know the specifics (if they do!).
评论 #6288167 未加载
damian2000over 11 years ago
I&#x27;m amazed that Melbourne IT seem to be held in high regard these days. Going back to the 1990s, they had a monopoly on Australian domain registration, they charged the earth, and had really crap customer service.
评论 #6289699 未加载
alien_acornover 11 years ago
&gt; The correct name servers should have been DNS.EWR1.NYTIMES.COM and DNS.SEA1.NYTIMES.COM.<p>How does this work? How would you get to DNS.EWR1.NYTIMES.COM without first knowing where nytimes.com is?
评论 #6288400 未加载
评论 #6288405 未加载
nlyover 11 years ago
How would setting the registrar lock have helped in this case? The registrar lock can be unlocked by the current registrar... which was the target in this case.<p>It&#x27;s good advice, but seems kind of irrelevant.<p>&gt; It&#x27;s worth noting that while some of Twitter&#x27;s utility domains were redirected, Twitter.com was not -- and Twitter.com has a registry lock in place.
评论 #6290064 未加载
peterwwillisover 11 years ago
I&#x27;ll bet five dollars the credentials were stolen by a botnet the SEA runs or has access to. You wouldn&#x27;t believe the shit that pops up sometimes. (It&#x27;s also incredibly trivial to take over botnets run by jackasses who took a tutorial in setting up Zeus) Less likely but still highly possible would be spear phishing of registrar resellers.<p>Edit: I don&#x27;t know why, but the nameservers I use don&#x27;t resolve any address for nytimes.com now. If I query 8.8.8.8 directly I get a response. So, could be they&#x27;re still suffering from this attack, which sucks.
agwaover 11 years ago
&gt; MelbourneIT has traditionally been known as one of the more secure registrars<p>They were one of the registrars compromised back in May as part of Hack the Planet[1]. If I recall correctly, they were the only registrar where the attackers actually got shell access on a server. That&#x27;s when they lost any reputation for security in my eyes.<p>[1] <a href="http://www.theregister.co.uk/2013/05/09/melbourne_it_hacking/" rel="nofollow">http:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2013&#x2F;05&#x2F;09&#x2F;melbourne_it_hacking...</a>
dotBenover 11 years ago
I don&#x27;t think I understand why CloudFlare was involved - do they provide services to NYT, it isn&#x27;t clear from the post that they do.
评论 #6290826 未加载
dibbsonlineover 11 years ago
Good to see the MelbsIT product using two factor auth.