The Mac Observer

Anonymous Sri Lanka Attacks Apple & Others, Reveals Name Server Records

TMO Talk (83)

[WARNING: This article includes quoted profanity. - Editor]

 

The Bad Guys

A hacker group calling itself Anonymous Sri Lanka announced this week that it had successfully launched a DNS Cache Snoop Poisoning attack against Apple, Facebook, and other high-profile tech companies. In a post to hacker hangout and repository Pastebin, the group released the primary DNS name server records associated with those companies, listing hundreds of entries, some of which these companies may not have intended to make public.

Anonymous Sri Lanka (ignoring the irony of the lack of anonymity such specifics impart) posted lists of all of the name server records with names like, “APPLE.COM - World’s Largest Consumer Electronics Leader DNSi,” and “FACEBOOK.COM - The World’s Social Media Giant - DNS R00T3D, Fuck3D and Leaked.”

To that effect, the group offered a (vaguely literate) mini-manifesto to explain its attack against Facebook, writing:

Yo Facebook Assholes - If you want to run a Social Network - do it as it is as a real guys. Don’t try be smart asses. You are the most stupid and notorious fuckheads ever. The way you control and treat to your members are not acceptable under any circumstances.

But we don’t care who you are and what you do. Do not BLOCK the people and do not CONTROL them. Where is your fucking FREEDOM or the SOCIALISM. Censorship = Freedom (Don’t try to change the meaning of the wordings). Let the people have their own freedom on the social networks. This is hack against your fuckhead censorship.

The group offered no such commentary on Apple.

In the headers of their post, they claimed that, “Primary DNS Server Hacked with DNS Cache Snoop Poisoning.” They offered no proof of the cache poisoning, but did provide proof of the snooping in the form of listing Apple’s DNS name servers.

For most of us mortals, there’s not a whole lot in the information in that list. The group found the company’s DNS name servers, showed that it tried to perform a zone transfer on those servers (it failed), and then listed hundreds of individual servers such as:

  • 17.254.3.16 gidget16.apple.com
  • 17.254.3.65 customer.apple.com
  • 17.254.2.108 testswupdate.apple.com

As we said, that doesn’t seem all that interesting. What it does, however, is provide a starting point for others to probe these individual servers for vulnerabilities. Even that may not seem like a big deal, especially for a domain like customer.apple.com, which was already known to exist.

For the rest, servers like jobsws2.apple.com, the starting point could be seen as valuable to the bad guys and a nuisance to Apple and its cyber security team. Plus, it’s fun to conclude that that stands for “Jobs Work Station #2.”

Then there are listings such as icloudstatus.apple.com, which could suggest that Apple is working on a monitoring tool for iCloud status. The company provided such tools for .Mac and MobileMe, and doing so for the much larger iCloud is logical.

Similarly, webcast.apple.com does resolve to a page with the image below. ZOMG! Is that an unannounced product? Our guess is that it’s an internal tool for meetings, but it’s another example of the bad guys having a new starting point.

Webcast Studio Off Air

Webcast Studio Off Air

Dave Hamilton contributed (greatly) to this article.

Post A Comment or Log-in. Need an account? Register here.

9 Observer Comments

I just want to point out that the title of this article is a little misleading.

The “anonymous” group that did these attacks is not the same “anonymous” group that most people think of (the ones that did the BART hackings, etc.). It is an unrelated group trying to tag along on the bigger group’s media attention.

Please correct me if I’m completely wrong, but that’s what my research seems to indicate.

The affiliations and specifics of these “organizations” are rather loose, to my understanding. Their PR folks can let me know if they have a problem. smile

I agree with Computerbandgeek this is not the same group that has been in the news lately

As I noted, affiliations in such groups are always loose, and we are frankly not responsible for their public relations.

However, specificity never hurt, so I edited the piece to make it clear that it was “Anonymous Sri Lanka” that performed these actions.

   Actions Bosco (Brad Hutchings) said on August 31st, 2011 at 10:04 PM (Edited: 05/26/2012 12:39 AM):

They’re probably like AQI (Al Queda in Iraq). They pay their affiliate fees, deploy the branding kit, and get worldwide attention even if they’re not quite so bad-ass as the franchisers.

That’s funny, Brad. big grin

Thanks for clarifying the article. I know what you mean about it being hard to tell all the groups apart, considering the fact that some of the members of the groups can’t even tell each other apart. wink

But in this particular case equating these guys to the big boys is somewhat analogous to equating Al Gore to someone sitting in a tree scheduled for removal while smoking pot and shouting slogans into a bullhorn.

I just started a sentence with “but”. I guess it’s time for bed :O

But in this particular case equating these guys to the big boys is somewhat analogous to equating…

That all depends on one’s personal opinions of the groups—and people—mentioned. wink

Post A Comment or Log-in. Need an account? Register here.
 

Recent Headlines - Updated May 26th

Sat, 10:00 AM
MacOS KenDensed - MacOS KenDensed: Apple’s Patent Lawsuit & Antitrust Shuffle
Fri, 5:58 PM
News - Sotheby’s to Auction Steve Jobs Atari Memo (Photo Gallery)
5:42 PM
Free on iTunes - 3 Free iOS Apps for News Hounds
3:00 PM
Rumor - Nest Thermostat Reportedly Coming to Apple Retail Stores
2:40 PM
Particle Debris - The TV Industry’s Dreadful Little Secret
2:33 PM
News - Mobile Devices Account for 20% of Web Traffic in US, Canada
12:49 PM
News - Apple Now Offering “Free App of the Week” for iOS
12:21 PM
News - Tim Cook Declines $75 Million Dividend Payout
11:25 AM
News - Absinthe 2.0 Provides Untethered Jailbreak for iOS 5.1.1
11:09 AM
Quick Look Review - F18 Carrier Landing (iOS) is a Boatload of Fun
10:51 AM
TMO Appearances - Jeff Gamet talks Cool Apps & Accessories on Not Another Mac Podcast
10:12 AM
Hot Forum Topic - Forum Poll: Which is Your Favorite Photo Sharing Service?
 

The Mac Observer Reader Specials

  • Macsales Add 2nd Hard Drive or SSD to Mac mini, MacBook or MacBook Pro. 1TB of Hard Drive or SSD Capacity from $64.99! Video Guides Make it easy - OWC DataDoubler - Macsales.com
  • Mac RAM Upgrades: MacBook Pro 16GB kits $475, 8GB Kits for $119.99! iMac 16GB RAM Kits (4x 4GB) for $229.99! Mac Pro Memory 32GB Kit for $399.99, 64GB Kit for $889.99! Mac Hard Drives 2TB Seagate SATA II for $249.99! Click Here!
  • Macpokeronline.com If you're using a Mac, then you've gotta check out PokerOnAMac.com. Online casinos and poker rooms are literally giving away cash and the casino sites at Poker on a Mac do the unthinkable, they actually reward! Join today, the download is free!
  •  Looking to find online casinos for mac? We can help you find the best real money casino sites where you can play your favorite casino games including blackjack and slots.

Apple Stock Quote (AAPL)

Loading...

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features

Support The Mac Observer

We noticed you may be running AdBlock on your computer. It takes real money to run this site and to deliver the news, tips, and opinions you love to read.

If you wish to block the ads that pay for the creation of our content, we ask that you instead support TMO Directly, either with a $5 monthly recurring contribution, or a one-time donation of any amount of your choice. Thanks!

Subscribe with Paypal Donate with Paypal