find you on :butterfedy1: fediverse<p><span class="h-card"><a class="u-url mention" href="https://freesoftwareextremist.com/users/r" rel="nofollow noopener" target="_blank">@r</a></span> <span class="h-card"><a class="u-url mention" href="https://mastodon.social/@torproject" rel="nofollow noopener" target="_blank">@torproject</a></span> <span class="h-card"><a class="u-url mention" href="https://social.librem.one/@m0xee" rel="nofollow noopener" target="_blank">@m0xee</a></span> <span class="h-card"><a class="u-url mention" href="https://shitposter.world/users/jeffcliff" rel="nofollow noopener" target="_blank">@jeffcliff</a></span> <span class="h-card"><a class="u-url mention" href="https://social.hendrixgames.com/users/thendrix" rel="nofollow noopener" target="_blank">@thendrix</a></span> <span class="h-card"><a class="u-url mention" href="https://mk.gabe.rocks/@gabriel" rel="nofollow noopener" target="_blank">@gabriel</a></span> <span class="h-card"><a class="u-url mention" href="https://social.fbxl.net/users/sj_zero" rel="nofollow noopener" target="_blank">@sj_zero</a></span> <span class="h-card"><a class="u-url mention" href="https://freesoftwareextremist.com/users/Suiseiseki" rel="nofollow noopener" target="_blank">@Suiseiseki</a></span> The last time Tor browser crapped itself INSTANTLY was shortly after i loaded this ARCHIVED VERSION OF <a href="https://web.archive.org/web/20241010052745/https://thehackernews.com/2024/09/watering-hole-attack-on-kurdish-sites.html" rel="nofollow noopener" target="_blank">this page</a> (<span class="h-card"><a class="u-url mention" href="https://mastodon.archive.org/@internetarchive" rel="nofollow noopener" target="_blank">@internetarchive</a></span>). Someone on fedi shared the, iirc, non-archived version of this link and i was curious.</p><p><strong>I made a note of the browser crash in october, i must've had JS enabled because my note says "reqJs"</strong></p><p>I have only just in the past few days had a chance to READ the note and revisit the page. As a part-time "coincidence suspector" I find it interesting that loading that page caused my browser to die instantly.... it doesn't now (not that that means much). If i had a chance to read it in october i'd have had a good few things to say about so-called "(<a class="hashtag" href="https://wizard.casa/collections/tags/wateringhole" rel="nofollow noopener" target="_blank">#wateringHole</a>) attacks". I feel a *cough* coming on....</p><p>The following are mentioned in the atricle, as attacked sites (my notes in parenthesis):</p><p>- <a class="hashtag" href="https://wizard.casa/collections/tags/rojnews" rel="nofollow noopener" target="_blank">#rojnews</a> .news * COUGH* (<a class="hashtag" href="https://wizard.casa/collections/tags/cloudflare" rel="nofollow noopener" target="_blank">#cloudflare</a> (cf), not visited)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/hawarnews" rel="nofollow noopener" target="_blank">#hawarnews</a> .com (cf, not visited)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/targetplatform" rel="nofollow noopener" target="_blank">#targetplatform</a> .net (packed with youtube videos, seems westernized)</p><p>I'd be VERY interested to know whether the sites above were cf during/before this attack but either way this is quite concerning, if the site was cf before the attack that could address HOW those sites were breached in the first place. If cf during the attack, then cf has failed in its mission to protect from the <a class="hashtag" href="https://wizard.casa/collections/tags/cyberattack" rel="nofollow noopener" target="_blank">#cyberattack</a>. If the sites became cf after, then we must ask do sites immediately become cf'd when a problem emerges? Would Kurdish outlets knowingly have a policy like that? Do the site owners EVEN KNOW the site is cf? This is not as silly a question as it sounds.</p><p>Next i checked <a class="hashtag" href="https://wizard.casa/collections/tags/kurdish" rel="nofollow noopener" target="_blank">#kurdish</a> news sites found in my own searches (with notes):</p><p>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurditv" rel="nofollow noopener" target="_blank">#kurditv</a> .com * STILL COUGHING* (requires <a class="hashtag" href="https://wizard.casa/collections/tags/google" rel="nofollow noopener" target="_blank">#google</a> js(without integrity checks?!) to view videos!)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdistanobserver" rel="nofollow noopener" target="_blank">#kurdistanobserver</a> .com (on googl servers, not visited)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/thekurdishproject" rel="nofollow noopener" target="_blank">#thekurdishproject</a> .org (cf, not visited (NV))<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/infopig" rel="nofollow noopener" target="_blank">#infopig</a> .com (down at time of test)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/iranpressnews" rel="nofollow noopener" target="_blank">#iranpressnews</a> .com (cf, NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/ekurd" rel="nofollow noopener" target="_blank">#ekurd</a> .net (cf, NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdpa" rel="nofollow noopener" target="_blank">#kurdpa</a> .net (cf, NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/newslive" rel="nofollow noopener" target="_blank">#newslive</a> .com (cf NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdistan24" rel="nofollow noopener" target="_blank">#kurdistan24</a> .net (cf NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/basnews" rel="nofollow noopener" target="_blank">#basnews</a> .com (cf NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdistantv" rel="nofollow noopener" target="_blank">#kurdistantv</a> .net (cf NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/zagrosnews" rel="nofollow noopener" target="_blank">#zagrosnews</a> .net (cf NV)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdistanin" rel="nofollow noopener" target="_blank">#kurdistanin</a> .net (googl non-integrity checked js.... bunny, cf and amazon cloudfront resources)<br>- <a class="hashtag" href="https://wizard.casa/collections/tags/kurdistantribune" rel="nofollow noopener" target="_blank">#kurdistantribune</a> .com (fetches non-integrity checked statcounter (cf) js, which is blocked by uBlockOrigin if u use TorBrowser in TailsOS. Uses youtube, feedburner (cf), <a class="hashtag" href="https://wizard.casa/collections/tags/facebook" rel="nofollow noopener" target="_blank">#facebook</a> and #twitter/ <a class="hashtag" href="https://wizard.casa/collections/tags/fastly" rel="nofollow noopener" target="_blank">#fastly</a> fetches snitch on the EXACT articles u read(!!!), with twitter js not being integrity checked)</p><p><strong>WATERING HOLE ATTACK RATING = EXTREME</strong><br><strong>DIGITAL COLONIALISM INDEX = 99%?</strong></p><p>*END COUGH* <em>(yeah i spent a few good hours coughing this up like a bad furball)</em> :acat_chew:</p><p><strong>The article itself is not even very complete.... how are the supposed <a class="hashtag" href="https://wizard.casa/collections/tags/apk" rel="nofollow noopener" target="_blank">#APK</a> files/apps getting manually(?) approved and installed on peoples' devices?</strong> .... <span class="h-card"><a class="u-url mention" href="https://floss.social/@fdroidorg" rel="nofollow noopener" target="_blank">@fdroidorg</a></span> should be so lucky. Maybe the fdroid team need to take a feather from this hackers black hat? <strong>am i missing something here or does this story</strong> <em>SMELL</em> <strong>a bit?</strong></p><p>Thoughts?</p>