{"id":9299,"date":"2008-12-09T12:55:00","date_gmt":"1999-11-29T20:00:00","guid":{"rendered":"https:\/\/aidanfinn.com\/?p=9299"},"modified":"2008-12-09T12:55:00","modified_gmt":"1999-11-29T20:00:00","slug":"digiweb-hacked-microsoft-ireland-appears-like-it-was-hacked","status":"publish","type":"post","link":"https:\/\/aidanfinn.com\/?p=9299","title":{"rendered":"Digiweb Hacked?  Microsoft Ireland &#8220;Appears&#8221; Like It Was Hacked"},"content":{"rendered":"<p>One of my colleagues told me to look at <a href=\"http:\/\/www.microsoft.ie\/\">www.microsoft.ie<\/a>.\u00a0 I did and I took a screen shot:\n<\/p>\n<p><a href=\"http:\/\/0m8fsg.bay.livefilestore.com\/y1pw078s0L7mb-al72T5qbpYNnBb3EZzRSg9U_UCBDWMlY_a5__3Gm9cAlqERqcl4IAif2cLo1PsNNw-d5Q7cA1tQ?PARTNER=WRITER\"><img loading=\"lazy\" decoding=\"async\" style=\"border-right:0px;border-top:0px;border-left:0px;border-bottom:0px\" height=\"319\" alt=\"MsIEhacked\" src=\"http:\/\/byfiles.storage.msn.com\/y1pnqLwkckhE2IWoI3uqTOOYBuzcETu4I8blCxnm0a2TtuHmple49eFZT-v3rE7pc7IXTIDz1wuOreigvSKWnEOFw?PARTNER=WRITER\" width=\"404\" border=\"0\" \/><\/a>\n<\/p>\n<p>That, on the face of it, would look like Microsoft were hacked and someone had defaced the Irish site.\u00a0 I checked the <a href=\"http:\/\/www.microsoft.com\/ireland\/\" target=\"_blank\">genuine MS Ireland URL<\/a> and it was OK.\u00a0 A quick lookup on DNSTools and I found this:\n<\/p>\n<p><em>% Information related to &#8216;80.93.17.0 &#8211; 80.93.17.255&#8217;<br \/>inetnum:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 80.93.17.0 &#8211; 80.93.17.255<br \/>netname:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 nov-sh<br \/>descr:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Novara Shared Hosting<br \/>country:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 IE<br \/>admin-c:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 nov23-ripe<br \/>tech-c:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 nov23-ripe<br \/>status:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 ASSIGNED PA<br \/>mnt-by:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 mnt-novara32<br \/>mnt-lower:\u00a0\u00a0\u00a0\u00a0\u00a0 mnt-novara32<br \/>mnt-routes:\u00a0\u00a0\u00a0\u00a0 mnt-novara32<br \/>source:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RIPE # Filtered<br \/>person:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Eoin Costello<br \/>address:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 3, North Earl Street Dublin 1, Ireland<br \/>phone:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 +35318583091<br \/>nic-hdl:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 nov23-ripe<br \/>source:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RIPE # Filtered<br \/>% Information related to &#8216;80.93.16.0\/20AS31122&#8217;<br \/>route:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 80.93.16.0\/20<br \/>descr:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Novara Route Object<br \/>origin:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 AS31122<br \/>mnt-by:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 DIGIWEB-MNT<br \/>source:\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RIPE # Filtered<\/em>\n<\/p>\n<p>Novara was acquired by Digiweb a while ago.\u00a0 It looks like someone set up a DNS record to point to a site hosted on their shared service web servers.\u00a0 Ouch!\n<\/p>\n<p>EDIT:\n<\/p>\n<p>This <em>looks<\/em> like a DNS hack was perpetrated on Digiweb.\u00a0 I cannot say for definite but that&#8217;s what it smells like to me.\u00a0 It looks like stuff that was 100% outside of MS&#8217;s control.\n<\/p>\n<p>EDIT #2:\n<\/p>\n<p>And for the twits wearing tinfoil hats: No, the Microsoft Ireland site was <strong>not<\/strong> actually defaced.\u00a0 The\u00a0.ie DNS record just redirects to the Ireland subpages of corporate.\u00a0 That record (it looks as if it was Novara hosted but I could be wrong) was altered and a <strong>fake<\/strong> page on a Novara\/Digiweb server was set up.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of my colleagues told me to look at <a href=\"http:\/\/www.microsoft.ie.\u00a0\" rel=\"nofollow\">http:\/\/www.microsoft.ie.\u00a0<\/a> I did and I took a screen shot: That, on the face of it, would look like Microsoft were hacked and someone had defaced the Irish site.\u00a0 I checked the genuine MS Ireland URL and it was OK.\u00a0 A quick lookup on DNSTools and I &hellip; <a href=\"https:\/\/aidanfinn.com\/?p=9299\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Digiweb Hacked?  Microsoft Ireland &#8220;Appears&#8221; Like It Was Hacked&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-9299","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"jetpack_featured_media_url":"","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/9299","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9299"}],"version-history":[{"count":0,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/9299\/revisions"}],"wp:attachment":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9299"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9299"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9299"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}