Ir para o conteúdo
Advertisement

Por que os principais sites universitários veiculam pornografia? Tudo se resume a uma limpeza de má qualidade.

Centenas de subdomínios de dezenas de universidades foram sequestrados por golpistas.

schedule 19:00 visibility 70 visualizações
Por que os principais sites universitários veiculam pornografia? Tudo se resume a uma limpeza de má qualidade.
Fonte: Ars Technica

Websites for some of the world’s most prestigious universities are serving explicit porn and malicious content after scammers exploited the shoddy record-keeping of the site administrators, a researcher found recently.

The sites included berkeley.edu, columbia.edu, and washu.edu, the official domains for the University of California, Berkeley, Columbia University, and Washington University in St. Louis. Subdomains such as hXXps://causal.stat.berkeley.edu/ymy/video/xxx-porn-girl-and-boy-ej5210.html, hXXps://conversion-dev.svc.cul.columbia[.]edu/brazzers-gym-porn, and hXXps://provost.washu.edu/app/uploads/formidable/6/dmkcsex-10.pdf. All deliver explicit pornography and, in at least one case, a scam site falsely claiming a visitor’s computer is infected and advising the visitor to pay a fee for the non-existent malware to be removed. In all, researcher Alex Shakhov said, hundreds of subdomains for at least 34 universities are being abused. Search results returned by Google list thousands of hijacked pages.

A handful of hijacked columbia.edu subdomains listed by Google One of the sites redirected by a UC Berkeley subdomain.

Hijacking a university's good name

Shakhov, a researcher at SH Consulting, said that the scammers—which a separate researcher has linked to a known group tracked as Hazy Hawk—are seizing on what amounts to a clerical error by site administrators of the affected universities. When they commission a subdomain such as provost.washu.edu, they create a CNAME record, which assigns a URL to the IP address hosting the subdomain. When the subdomain is eventually decommissioned—something that happens frequently for various reasons—the record is never removed. Scammers like Hazy Hawk then swoop in by registering the expired domain name at the base of the old URL.

Read full article

Comments

newspaper

Publicado em

Ars Technica

open_in_new Ler artigo completo

Artigos relacionados

Artemis II: O que acontece com os astronautas agora?
Educação

Artemis II: O que acontece com os astronautas agora?

Crédito, REUTERS/Lexi Parra Os tripulantes da missão Artemis II retornaram com segurança à Terra na sexta-feira (10/4) após reentrarem na atmosfera a 40.000 km/h, pousando ao largo da costa da Califórnia. Eles viajaram mais fundo no espaço do que quaisquer humanos antes deles —…

BBC Portuguese