Why are top university websites serving porn? It comes down to shoddy housekeeping.


Websites for some of the world’s most prestigious universities are serving explicit porn and malicious content after scammers exploited the shoddy record-keeping of the site administrators, a researcher found recently.

The sites included berkeley.edu, columbia.edu, and washu.edu, the official domains for the University of California, Berkeley, Columbia University, and Washington University in St. Louis. Subdomains such as hXXps://causal.stat.berkeley.edu/ymy/video/xxx-porn-girl-and-boy-ej5210.html, hXXps://conversion-dev.svc.cul.columbia[.]edu/brazzers-gym-porn, and hXXps://provost.washu.edu/app/uploads/formidable/6/dmkcsex-10.pdf. All deliver explicit pornography and, in at least one case, a scam site falsely claiming a visitor’s computer is infected and advising the visitor to pay a fee for the non-existent malware to be removed. In all, researcher Alex Shakhov said, hundreds of subdomains for at least 34 universities are being abused. Search results returned by Google list thousands of hijacked pages.

A handful of hijacked columbia.edu subdomains listed by Google

A handful of hijacked columbia.edu subdomains listed by Google

One of the sites redirected by a UC Berkeley subdomain.

One of the sites redirected by a UC Berkeley subdomain.

Hijacking a university’s good name

Shakhov, founder of SH Consulting, said that the scammers—which a separate researcher has linked to a known group tracked as Hazy Hawk—are seizing on what amounts to a clerical error by site administrators of the affected universities. When they commission a subdomain such as provost.washu.edu, they create a CNAME record, which assignes a subdomain to a “cononical” domain. When the subdomain is eventually decommissioned—something that happens frequently for various reasons—the record is never removed. Scammers like Hazy Hawk then swoop in by hijacking the old record.

With that, they have now hijacked that university’s subdomain. Given the reputations universities have, search queries then flow to the top of Google’s results.



Source link

  • Related Posts

    Altra Promo Codes: Get 20% Off Plus Free Shipping

    Altra Running’s distinctive wide toe box and zero drop heel-toe design don’t facilitate marathon PRs or punchy 5Ks. But there’s a reason why Leonardo DiCaprio chose to wear all-weather Lone…

    Lachy Groom to back India startup Pronto at a $200M valuation, sources say

    Pronto, an Indian instant house-help startup, is finalizing a funding round led by tech investor Lachy Groom that would value the fast-growing company at about $200 million after investment, TechCrunch…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    The World’s Largest Air Forces By Number Of Bombers

    The World’s Largest Air Forces By Number Of Bombers

    Doug Ford’s stupid fucking FOI change passed…

    Doug Ford’s stupid fucking FOI change passed…

    CGTN: The Art of Governance: How China is shaping a new path for sustainable development

    Trump sends envoys to Islamabad as Iran rules out direct talks

    Trump sends envoys to Islamabad as Iran rules out direct talks

    Altra Promo Codes: Get 20% Off Plus Free Shipping

    Altra Promo Codes: Get 20% Off Plus Free Shipping

    Tie yourself up in wriggling loveknots in this graceful and silly merpeople sex game

    Tie yourself up in wriggling loveknots in this graceful and silly merpeople sex game