<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Aten Labs &#187; captured</title>
	<atom:link href="http://atenlabs.com/blog/tag/captured/feed/" rel="self" type="application/rss+xml" />
	<link>http://atenlabs.com/blog</link>
	<description>San Diego&#039;s Premier IT Security Consultancy</description>
	<lastBuildDate>Wed, 29 Feb 2012 19:14:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Twitter, DNS, the &#8220;Iranian cyber army&#8221; and panic &#8211; an analysis</title>
		<link>http://atenlabs.com/blog/twitter-dns-the-iranian-cyber-army-and-panic-an-analysis/</link>
		<comments>http://atenlabs.com/blog/twitter-dns-the-iranian-cyber-army-and-panic-an-analysis/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 08:44:45 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[capture]]></category>
		<category><![CDATA[captured]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[ettiquite]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[poison]]></category>
		<category><![CDATA[poisoned]]></category>
		<category><![CDATA[sensationalism]]></category>
		<category><![CDATA[sensationalist]]></category>
		<category><![CDATA[theft]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=85</guid>
		<description><![CDATA[Status.twitter.com tells us that DNS records were overwritten temporarily tonight by attackers to redirect HTTP traffic to another host that was originally destined for twitter.com. With the information that I know now (12:40am, 12/18): The host which contained the landing page was hosted with bluehost. This tells us a few things They didn&#8217;t have the [...]]]></description>
			<content:encoded><![CDATA[<p>Status.twitter.com tells us that DNS records were overwritten temporarily tonight by attackers to redirect HTTP traffic to another host that was originally destined for twitter.com.</p>
<p>With the information that I know now (12:40am, 12/18):</p>
<p>The host which contained the landing page was hosted with bluehost. This tells us a few things</p>
<ul>
<li>They didn&#8217;t have the infrastructure to do packet captures, or credential theft. Bluehost does shared hosting.</li>
<li>Any attempt to do so would have thrown TONS of SSL errors, and very likely DDoS&#8217;ed the server hosting the landing page. (Twitter had HUNDREDS of servers, these guys had 1.). All of your twitter apps would have thrown errors, or flat out stopped working.</li>
<li>Twitters security infrastructure was left untouched, and was not a target of the attack.</li>
</ul>
<p>I&#8217;ve been watching twitter scroll with sensationalism and panic, people yelling &#8220;OH GOD TWITTER GOT HACKED EVERYONE CHANGE YOUR PASSWORDS NOW&#8221;.</p>
<p>Please &#8211; don&#8217;t do that.</p>
<p>Its going to make everyones job harder who have to work on this situation, it incites panic and causes people to prematurely flip out and do things they probably shouldn&#8217;t do.</p>
<p>I&#8217;ve had to deal with this in the past &#8211; people throwing their arms in the air and screaming about passwords being compromised when they in fact weren&#8217;t. It did not end well.</p>
<p>Please &#8211; think before you hit send.</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/twitter-dns-the-iranian-cyber-army-and-panic-an-analysis/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

