find you on :butterfedy1: fediverse<p><span class="h-card"><a class="u-url mention" href="https://freesoftwareextremist.com/users/r" rel="nofollow noopener noreferrer" target="_blank">@r</a></span> <span class="h-card"><a class="u-url mention" href="https://mastodon.social/@torproject" rel="nofollow noopener noreferrer" target="_blank">@torproject</a></span> <span class="h-card"><a class="u-url mention" href="https://social.librem.one/@m0xee" rel="nofollow noopener noreferrer" target="_blank">@m0xee</a></span> <span class="h-card"><a class="u-url mention" href="https://shitposter.world/users/jeffcliff" rel="nofollow noopener noreferrer" target="_blank">@jeffcliff</a></span> <span class="h-card"><a class="u-url mention" href="https://social.hendrixgames.com/users/thendrix" rel="nofollow noopener noreferrer" target="_blank">@thendrix</a></span> <span class="h-card"><a class="u-url mention" href="https://mk.gabe.rocks/@gabriel" rel="nofollow noopener noreferrer" target="_blank">@gabriel</a></span> <span class="h-card"><a class="u-url mention" href="https://social.fbxl.net/users/sj_zero" rel="nofollow noopener noreferrer" target="_blank">@sj_zero</a></span> <span class="h-card"><a class="u-url mention" href="https://freesoftwareextremist.com/users/Suiseiseki" rel="nofollow noopener noreferrer" target="_blank">@Suiseiseki</a></span> The last time Tor browser crapped itself INSTANTLY was shortly after i loaded this ARCHIVED VERSION OF <a href="https://web.archive.org/web/20241010052745/https://thehackernews.com/2024/09/watering-hole-attack-on-kurdish-sites.html" rel="nofollow noopener noreferrer" target="_blank">this page</a> (<span class="h-card"><a class="u-url mention" href="https://mastodon.archive.org/@internetarchive" rel="nofollow noopener noreferrer" target="_blank">@internetarchive</a></span>). Someone on fedi shared the, iirc, non-archived version of this link and i was curious.</p><p><strong>I made a note of the browser crash in october, i must've had JS enabled because my note says "reqJs"</strong></p><p>I have only just in the past few days had a chance to READ the note and revisit the page. As a part-time "coincidence suspector" I find it interesting that loading that page caused my browser to die instantly.... it doesn't now (not that that means much). If i had a chance to read it in october i'd have had a good few things to say about so-called "(<a class="hashtag" href="https://wizard.casa/collections/tags/wateringhole" rel="nofollow noopener noreferrer" target="_blank">#wateringHole</a>) attacks". I feel a *cough* coming on....</p><p>The following are mentioned in the atricle, as attacked sites (my notes in parenthesis):</p><p>- <a class="hashtag" href="https://wizard.casa/collections/tags/rojnews" rel="nofollow noopener noreferrer" target="_blank">#rojnews</a> .news * COUGH* (<a class="hashtag" href="https://wizard.casa/collections/tags/cloudflare" rel="nofollow noopener noreferrer" target="_blank">#cloudflare</a> (cf), not visited)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/hawarnews" rel="nofollow noopener noreferrer" target="_blank">#hawarnews</a> .com (cf, not visited)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/targetplatform" rel="nofollow noopener noreferrer" target="_blank">#targetplatform</a> .net (packed with youtube videos, seems westernized)</p><p>I'd be VERY interested to know whether the sites above were cf during/before this attack but either way this is quite concerning, if the site was cf before the attack that could address HOW those sites were breached in the first place. If cf during the attack, then cf has failed in its mission to protect from the <a class="hashtag" href="https://wizard.casa/collections/tags/cyberattack" rel="nofollow noopener noreferrer" target="_blank">#cyberattack</a>. If the sites became cf after, then we must ask do sites immediately become cf'd when a problem emerges? Would Kurdish outlets knowingly have a policy like that? Do the site owners EVEN KNOW the site is cf? This is not as silly a question as it sounds.</p><p>Next i checked <a class="hashtag" href="https://wizard.casa/collections/tags/kurdish" rel="nofollow noopener noreferrer" target="_blank">#kurdish</a> news sites found in my own searches (with notes):</p><p>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurditv" rel="nofollow noopener noreferrer" target="_blank">#kurditv</a> .com * STILL COUGHING* (requires <a class="hashtag" href="https://wizard.casa/collections/tags/google" rel="nofollow noopener noreferrer" target="_blank">#google</a> js(without integrity checks?!) to view videos!)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdistanobserver" rel="nofollow noopener noreferrer" target="_blank">#kurdistanobserver</a> .com (on googl servers, not visited)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/thekurdishproject" rel="nofollow noopener noreferrer" target="_blank">#thekurdishproject</a> .org (cf, not visited (NV))<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/infopig" rel="nofollow noopener noreferrer" target="_blank">#infopig</a> .com (down at time of test)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/iranpressnews" rel="nofollow noopener noreferrer" target="_blank">#iranpressnews</a> .com (cf, NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/ekurd" rel="nofollow noopener noreferrer" target="_blank">#ekurd</a> .net (cf, NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdpa" rel="nofollow noopener noreferrer" target="_blank">#kurdpa</a> .net (cf, NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/newslive" rel="nofollow noopener noreferrer" target="_blank">#newslive</a> .com (cf NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdistan24" rel="nofollow noopener noreferrer" target="_blank">#kurdistan24</a> .net (cf NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/basnews" rel="nofollow noopener noreferrer" target="_blank">#basnews</a> .com (cf NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdistantv" rel="nofollow noopener noreferrer" target="_blank">#kurdistantv</a> .net (cf NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/zagrosnews" rel="nofollow noopener noreferrer" target="_blank">#zagrosnews</a> .net (cf NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdistanin" rel="nofollow noopener noreferrer" target="_blank">#kurdistanin</a> .net (googl non-integrity checked js.... bunny, cf and amazon cloudfront resources)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdistantribune" rel="nofollow noopener noreferrer" target="_blank">#kurdistantribune</a> .com (fetches non-integrity checked statcounter (cf) js, which is blocked by uBlockOrigin if u use TorBrowser in TailsOS. Uses youtube, feedburner (cf), <a class="hashtag" href="https://wizard.casa/collections/tags/facebook" rel="nofollow noopener noreferrer" target="_blank">#facebook</a> and #twitter/ <a class="hashtag" href="https://wizard.casa/collections/tags/fastly" rel="nofollow noopener noreferrer" target="_blank">#fastly</a> fetches snitch on the EXACT articles u read(!!!), with twitter js not being integrity checked)</p><p><strong>WATERING HOLE ATTACK RATING = EXTREME</strong><br><strong>DIGITAL COLONIALISM INDEX = 99%?</strong></p><p>*END COUGH* <em>(yeah i spent a few good hours coughing this up like a bad furball)</em> :acat_chew:</p><p><strong>The article itself is not even very complete.... how are the supposed <a class="hashtag" href="https://wizard.casa/collections/tags/apk" rel="nofollow noopener noreferrer" target="_blank">#APK</a> files/apps getting manually(?) approved and installed on peoples' devices?</strong> .... <span class="h-card"><a class="u-url mention" href="https://floss.social/@fdroidorg" rel="nofollow noopener noreferrer" target="_blank">@fdroidorg</a></span> should be so lucky. Maybe the fdroid team need to take a feather from this hackers black hat? <strong>am i missing something here or does this story</strong> <em>SMELL</em> <strong>a bit?</strong></p><p>Thoughts?</p>