Re: It's 7pm. Do you know where *your* domains are? (was Re: Craigslist hacked?)

2014-11-25 Thread Gregg Berkholtz
A half-day with SQLite, memcached and PHP solved this need for us (auto-configures Nagios). Tracking a few hundred domains at this point. Gosh, I really need to cleanup sources, and punt some of these little tools onto GitHub. Gregg Berkholtz > On Nov 24, 2014, at 4:52 PM, Mike Hale wrote: >

Re: Craigslist hacked?

2014-11-24 Thread Mark Andrews
In message <20141125005124.0c4bf243a...@rock.dv.isc.org>, Mark Andrews writes: > > In message , Randy Epstein writes: > > On 11/24/14, 7:16 PM, "George Herbert" wrote: > > > > > > > >He didn't hack the registry, he hijacked its records. And this is far > > >from the first time a registry accoun

Re: Craigslist hacked?

2014-11-24 Thread Mark Andrews
In message , George Herbert writes: > > On Nov 24, 2014, at 4:18 PM, Randy Epstein > wrote: > > > > Actually, he didn’t hack its records either. He exploited a bug in > BIND. > > > ...returned a legit response plus a tacked-on glue record for > www.internic.net anytime you queried his nameser

Re: Craigslist hacked?

2014-11-24 Thread Randy Epstein
On 11/24/14, 7:51 PM, "Mark Andrews" wrote: > >In message , Randy Epstein writes: >> On 11/24/14, 7:16 PM, "George Herbert" wrote: >> >> > >> >He didn't hack the registry, he hijacked its records. And this is far >> >from the first time a registry account was hacked. But, yeah, *still* >> >n

Re: It's 7pm. Do you know where *your* domains are? (was Re: Craigslist hacked?)

2014-11-24 Thread Mike Hale
It's pretty easy to roll out a Nagios box that checks on your domains, NS results and SSL status. On Mon, Nov 24, 2014 at 4:20 PM, Miles Fidelman wrote: > Jay Ashworth wrote: >> >> In light of the CL domain hijacking, it seems like a good time to ask >> if everyone has an inventory system that ke

Re: Craigslist hacked?

2014-11-24 Thread Mark Andrews
In message , Randy Epstein writes: > On 11/24/14, 7:16 PM, "George Herbert" wrote: > > > > >He didn't hack the registry, he hijacked its records. And this is far > >from the first time a registry account was hacked. But, yeah, *still* > >not secure enough. > > Actually, he didn’t hack its rec

Re: Craigslist hacked?

2014-11-24 Thread George Herbert
> On Nov 24, 2014, at 4:18 PM, Randy Epstein wrote: > > Actually, he didn’t hack its records either. He exploited a bug in BIND. ...returned a legit response plus a tacked-on glue record for www.internic.net anytime you queried his nameserver, which he tricked people into doing with mixt

Re: Craigslist hacked?

2014-11-24 Thread Randy Epstein
On 11/24/14, 7:18 PM, "George Herbert" wrote: >And that was July 1997 not 96, though that does nothing to make me feel >younger ... http://archive.wired.com/politics/law/news/1997/07/5325 Yep. He did it to one of my domains (besides internic.net). >George William Herbert >Sent from my iPhone

Re: It's 7pm. Do you know where *your* domains are? (was Re: Craigslist hacked?)

2014-11-24 Thread Miles Fidelman
Jay Ashworth wrote: In light of the CL domain hijacking, it seems like a good time to ask if everyone has an inventory system that keeps track of all the details (including renewal dates) for their domain registy and SSL certificate accounts. If you use a tool to keep track of this, which one?

Re: Craigslist hacked?

2014-11-24 Thread George Herbert
And that was July 1997 not 96, though that does nothing to make me feel younger ... George William Herbert Sent from my iPhone > On Nov 24, 2014, at 4:16 PM, George Herbert wrote: > > > He didn't hack the registry, he hijacked its records. And this is far from > the first time a registry ac

Re: Craigslist hacked?

2014-11-24 Thread Randy Epstein
On 11/24/14, 7:16 PM, "George Herbert" wrote: > >He didn't hack the registry, he hijacked its records. And this is far >from the first time a registry account was hacked. But, yeah, *still* >not secure enough. Actually, he didn’t hack its records either. He exploited a bug in BIND. >George W

Re: It's 7pm. Do you know where *your* domains are? (was Re: Craigslist hacked?)

2014-11-24 Thread Josh Luthman
Xymon has a built in test to check SSL cert expiration. Josh Luthman Office: 937-552-2340 Direct: 937-552-2343 1100 Wayne St Suite 1337 Troy, OH 45373 On Nov 24, 2014 7:14 PM, "Jay Ashworth" wrote: > In light of the CL domain hijacking, it seems like a good time to ask > if everyone has an inven

Re: Craigslist hacked?

2014-11-24 Thread George Herbert
He didn't hack the registry, he hijacked its records. And this is far from the first time a registry account was hacked. But, yeah, *still* not secure enough. George William Herbert Sent from my iPhone > On Nov 24, 2014, at 2:17 PM, Randy Epstein wrote: > >> On 11/24/14, 5:08 PM, "Michael

It's 7pm. Do you know where *your* domains are? (was Re: Craigslist hacked?)

2014-11-24 Thread Jay Ashworth
In light of the CL domain hijacking, it seems like a good time to ask if everyone has an inventory system that keeps track of all the details (including renewal dates) for their domain registy and SSL certificate accounts. If you use a tool to keep track of this, which one? Do you have things set

Re: Craigslist hacked?

2014-11-24 Thread Randy Epstein
On 11/24/14, 5:08 PM, "Michael T. Voity" wrote: >I hate to say this, But I think that Network Operators have not see the >last of of this DNS Hijacking. Craigslist might have been a test to see >how far they could get and how long it would take for it to be >discovered. I hope the FBI and the o

Re: Craigslist hacked?

2014-11-24 Thread Brian Henson
It still seems broken in some areas. Mail is bouncing from Hotmail to craigslist. On Mon, Nov 24, 2014 at 5:08 PM, Michael T. Voity wrote: > I hate to say this, But I think that Network Operators have not see the > last of of this DNS Hijacking. Craigslist might have been a test to see how > far

Re: Craigslist hacked?

2014-11-24 Thread Michael T. Voity
I hate to say this, But I think that Network Operators have not see the last of of this DNS Hijacking. Craigslist might have been a test to see how far they could get and how long it would take for it to be discovered. I hope the FBI and the other Federal agencies out there are involved with

Re: Craigslist hacked?

2014-11-24 Thread Stephen Satchell
On 11/24/2014 08:41 AM, Alain Hebert wrote: > Well, > > NetSol? > > Is it just me or they came up a few times lately (past year) in high > profil case of DNS Hijacking? > Someone was kind enough to break into one of my domains at Register.com -- and to their credit Register.com dete

Re: Craigslist hacked?

2014-11-24 Thread Alain Hebert
Well, NetSol? Is it just me or they came up a few times lately (past year) in high profil case of DNS Hijacking? On 11/23/14 23:06, Mehmet Akcin wrote: > yes it's been hijacked thru registrar level and someone was able to change > name servers, now it's back to normal but you will ne

Re: Craigslist hacked?

2014-11-24 Thread Randy Bush
> Probably a good time to remind folks of HTTPS everywhere plugin for > Chrome and Firefox :-) what? and deter natural selection? i have hope for this really being improved next year https://www.eff.org/deeplinks/2014/11/certificate-authority-encrypt-entire-web randy

Re: Craigslist hacked?

2014-11-24 Thread Harry Hoffman
Probably a good time to remind folks of HTTPS everywhere plugin for Chrome and Firefox :-) Cheers, Harry On Nov 24, 2014 1:04 AM, Christopher Morrow wrote: > > On Sun, Nov 23, 2014 at 11:51 PM, Randy Bush wrote: > > and what tasty things did the hijacker's web site serve? > > probably not mu

Re: Craigslist hacked?

2014-11-23 Thread Christopher Morrow
On Sun, Nov 23, 2014 at 11:51 PM, Randy Bush wrote: > and what tasty things did the hijacker's web site serve? probably not much for very long... :( CL traffic is a bit crushy.

Re: Craigslist hacked?

2014-11-23 Thread Lyndon Nerenberg
On Nov 23, 2014, at 8:51 PM, Randy Bush wrote: > and what tasty things did the hijacker's web site serve? Firefox on my Mac started acting very strangely after encountering one of the 'unresponsive' versions of craigslist.ca. Apparent browser hangs, javascript script timeouts, and odd things

Re: Craigslist hacked?

2014-11-23 Thread Josh Luthman
I get the favicon.ico but Chrome says Error code: ERR_CONNECTION_TIMED_OUT Josh Luthman Office: 937-552-2340 Direct: 937-552-2343 1100 Wayne St Suite 1337 Troy, OH 45373 On Sun, Nov 23, 2014 at 11:15 PM, Brian Henson wrote: > I did a cache flush at googledns and it started resolving to a diffe

Re: Craigslist hacked?

2014-11-23 Thread Randy Bush
and what tasty things did the hijacker's web site serve? randy

Re: Craigslist hacked?

2014-11-23 Thread Nate Itkin
Looking at San Diego. Suspecting an issue with Google DNS. Google--> dig @8.8.8.8 cities.l.craigslist.org. +short 74.63.219.135 My resolver--> dig cities.l.craigslist.org. +short 208.82.238.226 Authoritative--> dig @208.82.236.210 cities.l.craigslist.org. +short +norec 208.82.236.242 On Sun, N

Re: Craigslist hacked?

2014-11-23 Thread Brian Henson
I did a cache flush at googledns and it started resolving to a different IP than the one earlier. Thinking the DNS may have been compromised somewhere. New IP is 208.91.197.27 old one was 74.63.219.135 On Sun, Nov 23, 2014 at 10:53 PM, Ken Chase wrote: > down for me and http://www.downforeveryon

Re: Craigslist hacked?

2014-11-23 Thread Mehmet Akcin
yes it's been hijacked thru registrar level and someone was able to change name servers, now it's back to normal but you will need to clear your caches and perhaps your ISP too. (if you are using 8.8.8.8 , they have already cleared the caches) Sponsoring Registrar:Network Solutions, LLC (R63-LROR)

Re: Craigslist hacked?

2014-11-23 Thread Brian Henson
Im seeing it resolve to 74.63.219.135 on my network and on http://whois.domaintools.com/craigslist.org On Sun, Nov 23, 2014 at 10:57 PM, Quinn Kuzmich wrote: > CoSprings list is coming up fine. > > On Sun, Nov 23, 2014 at 8:41 PM, Brian Henson wrote: > >> Is anyone else seeing their local craig

Re: Craigslist hacked?

2014-11-23 Thread Quinn Kuzmich
CoSprings list is coming up fine. On Sun, Nov 23, 2014 at 8:41 PM, Brian Henson wrote: > Is anyone else seeing their local craigslist redirected to another site > other than craigslist? I see it loading http://digitalgangster.com/5um. >

Re: Craigslist hacked?

2014-11-23 Thread Miles Fidelman
Boston is just fine, and all the links from there, to other craigslist sites seem to be working as well. Chaim Rieger wrote: Comes up normal for me in LA, on twc. On Nov 23, 2014 7:43 PM, "Brian Henson" wrote: Is anyone else seeing their local craigslist redirected to another site other than

Re: Craigslist hacked?

2014-11-23 Thread Lyndon Nerenberg
On Nov 23, 2014, at 7:41 PM, Brian Henson wrote: > Is anyone else seeing their local craigslist redirected to another site > other than craigslist? I see it loading http://digitalgangster.com/5um. *.craigslist.ca and *.craigslist.org have been offline since about 16:40 Pacific Standard Time fr

Re: Craigslist hacked?

2014-11-23 Thread Ted Cooper
On 24/11/14 13:41, Brian Henson wrote: > Is anyone else seeing their local craigslist redirected to another site > other than craigslist? I see it loading http://digitalgangster.com/5um. > Over on [dns-operations]: > On 24/11/14 13:38, Brad Volz wrote:> >> The craigslist account at one of our r

Re: Craigslist hacked?

2014-11-23 Thread Ken Chase
down for me and http://www.downforeveryoneorjustme.com/craigslist.org /kc On Sun, Nov 23, 2014 at 07:45:35PM -0800, Chaim Rieger said: >Comes up normal for me in LA, on twc. >On Nov 23, 2014 7:43 PM, "Brian Henson" wrote: > >> Is anyone else seeing their local craigslist redirected to a

Re: Craigslist hacked?

2014-11-23 Thread Brian Henson
Maybe an area based issue. tons of reports here http://www.isitdownrightnow.com/craigslist.org.html On Sun, Nov 23, 2014 at 10:48 PM, Brian Artschwager wrote: > Same here, New Jersey. > > On Sun, Nov 23, 2014 at 10:43 PM, aUser wrote: > >> I can't reach my local one or the Fresno one. Server u

Re: Craigslist hacked?

2014-11-23 Thread Brian Artschwager
Same here, New Jersey. On Sun, Nov 23, 2014 at 10:43 PM, aUser wrote: > I can't reach my local one or the Fresno one. Server unreachable. > > Sent from my iPhone 5S. > > > On Nov 23, 2014, at 7:41 PM, Brian Henson wrote: > > > > Is anyone else seeing their local craigslist redirected to anothe

Re: Craigslist hacked?

2014-11-23 Thread Brian Henson
strange when I go to Boise.craigslist or dayton.craigslist.org I get a site that shows digital Gangster for life as the title. so do some of the other tools outside my network. On Sun, Nov 23, 2014 at 10:45 PM, Charles Mills wrote: > Not seeing that here The local site and the general http;// >

Re: Craigslist hacked?

2014-11-23 Thread Charles Mills
Not seeing that here The local site and the general http;// www.craigslist.org both look to be going to the correct site. On Sun, Nov 23, 2014 at 10:41 PM, Brian Henson wrote: > Is anyone else seeing their local craigslist redirected to another site > other than craigslist? I see it loading htt

Re: Craigslist hacked?

2014-11-23 Thread Chaim Rieger
Comes up normal for me in LA, on twc. On Nov 23, 2014 7:43 PM, "Brian Henson" wrote: > Is anyone else seeing their local craigslist redirected to another site > other than craigslist? I see it loading http://digitalgangster.com/5um. >

Re: Craigslist hacked?

2014-11-23 Thread Bryan Tong
Not here, spyware maybe? On Sun, Nov 23, 2014 at 8:41 PM, Brian Henson wrote: > Is anyone else seeing their local craigslist redirected to another site > other than craigslist? I see it loading http://digitalgangster.com/5um. > -- eSited LLC (701) 390-9638

Re: Craigslist hacked?

2014-11-23 Thread aUser
I can't reach my local one or the Fresno one. Server unreachable. Sent from my iPhone 5S. > On Nov 23, 2014, at 7:41 PM, Brian Henson wrote: > > Is anyone else seeing their local craigslist redirected to another site > other than craigslist? I see it loading http://digitalgangster.com/5um.

Craigslist hacked?

2014-11-23 Thread Brian Henson
Is anyone else seeing their local craigslist redirected to another site other than craigslist? I see it loading http://digitalgangster.com/5um.