Outline ·
[ Standard ] ·
Linear+
/k/, open google.com.my now
|
TSLord Tiki Mick
|
Oct 11 2013, 12:35 AM, updated 13y ago
|
|
You see this ka CODE Index of /
cgi-bin/
Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Server at www.google.com.my Port 80
*EDIT*Let clear things up. google.com.my was not hacked, according to buysellaccount, it was DNS poisoning. The thing you see was not hosted on google's server but attacker's server. The attacker poisoned a DNS so that www.google.com.my would be redirected to his/her own IP instead of google's IP. This post has been edited by Lord Tiki Mick: Oct 11 2013, 02:08 AM
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 12:42 AM
|
|
QUOTE(roimekoi @ Oct 11 2013, 12:36 AM) Not sure. 8.8.8.8 ka? QUOTE(win7 @ Oct 11 2013, 12:36 AM) Google Malaysia is roask now... sofmoded by johnkorIni semua salah... QUOTE(fazil0610 @ Oct 11 2013, 12:38 AM) no, kenot open only google.com can what happen ah. Nothing in / except for cgi-bin. Sudah kena hack.
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 12:45 AM
|
|
QUOTE(,Oct 11 2013, 12:42 AM) Index of / cgi-bin/ Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Server at www.google.com.my Port 80 Means you can see la? IP is 142.4.211.288. That in Malaysia ka?
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 12:49 AM
|
|
Btw, my DNS is my router. Dunno router use what DNS.
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 01:07 AM
|
|
QUOTE(,Oct 11 2013, 12:51 AM) how u got my ip   QUOTE(Atomars @ Oct 11 2013, 12:51 AM) When I opened google.com.my, it shows "Hacked by 1337" "Google Malaysia STAMPED by PAKISTANI LEETS". QUOTE(fazil0610 @ Oct 11 2013, 12:54 AM) Pakis balas dendam QUOTE(Boy96 @ Oct 11 2013, 12:57 AM) Google Malaysia mah. Most of their workers are for marketing only.
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 01:08 AM
|
|
Tomorrow masuk berita one!
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 01:10 AM
|
|
QUOTE(poad @ Oct 11 2013, 01:09 AM) sure ke?tv3 only siar politik je..haha No. Masuk bbc, google news, wikinews liddat...
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 01:19 AM
|
|
QUOTE(alien3d @ Oct 11 2013, 01:17 AM) Not working la. The turn off apache d
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 01:24 AM
|
|
QUOTE(Xploit Machine @ Oct 11 2013, 01:21 AM)  kebodohan terlampau  You think Malaysian punya kerja ka?
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 01:37 AM
|
|
QUOTE(alien3d @ Oct 11 2013, 01:24 AM) apache ? dono when google use apache For www.google.com.my. See my first post. Not apache ka?
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 01:37 AM
|
|
QUOTE(Xploit Machine @ Oct 11 2013, 01:35 AM)
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 01:52 AM
|
|
QUOTE(buysellaccount @ Oct 11 2013, 01:36 AM) malunya. dns poisoning. semalam oso dah slowdown. not sure if kena dos. So it's not actually google, but hacker's IP?
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 01:59 AM
|
|
QUOTE(buysellaccount @ Oct 11 2013, 01:55 AM) yea, mostly the page also is hosted on another hacked server. that apache line when you view the root directory most probably the hacked server, not google's. Not google's DNS yang kena poisoned right?
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 02:10 AM
|
|
QUOTE(buysellaccount @ Oct 11 2013, 02:06 AM) our country handle .my, poison our dns, the new ip will be updated to all other dns. i'm using 8.8.8.8 also. so it is Malaysian fault right? Vulnerable DNS!
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 02:14 AM
|
|
QUOTE(ketnave @ Oct 11 2013, 02:12 AM)  selamat pagi ... (petang)  really ar ?! I don't see it from the US side ... Different DNS. They poisoned local DNS, say TM's, so all use TM's DNS will be affected. Right?
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 02:21 AM
|
|
QUOTE(xDragonZ @ Oct 11 2013, 02:15 AM) They actually modified the mynic records How? QUOTE(ketnave @ Oct 11 2013, 02:17 AM) eh, no idea on how it will propagate or it's effect ... I only know that this seems to be the hacking trend now ...  it's like messing up windows hosts file to redirect the request to another IP instead of the legit one, the actual site isn't actually hacked or anything, but the user will not see the actual site, but instead, a defaced one. Actually I also don't know.
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 02:26 AM
|
|
QUOTE(ketnave @ Oct 11 2013, 02:24 AM) Maybe http://mynic.my/en/index.php got compromised ... if that's the case ... then ... potential for all .my DNS records to be updated would be DAMN HIGH ...  Habislah!
|
|
|
|
|
|
TSLord Tiki Mick
|
Oct 11 2013, 02:30 AM
|
|
QUOTE(ketnave @ Oct 11 2013, 02:29 AM) why habis pulak ?! If all they did was just defacing the website, then not much harm lar ... other than bruised ego  If they are setting up to phish ... diff story all together ...  habislah mynic.  cimbclicks got .my This post has been edited by Lord Tiki Mick: Oct 11 2013, 02:31 AM
|
|
|
|
|