@novet @atoponce it is taken down now and i think it will remain down until admins or IT folks at FreeBSD infra team finds out exact root causes and how much damaged is done so far.
;; ANSWER SECTION: www.freebsd.org. 10 IN CNAME web.geo.freebsd.org. web.geo.freebsd.org. 150 IN A 192.50.199.250 web.geo.freebsd.org. 150 IN A 210.231.212.93
@tk this is not the expected source from FreeBSD.org itself. Your link mirrors only this timeline here. So it has no more value . Authorized message from FreeBSD please @nixCraft
whatever I want to start gets destroyed. βΉοΈ π.. Was thinking to start Linux but now many distro going to implement age verification... Was thinking to use bluesky they Goin to use AI. Was thinking to use FreeBSD and shared video 2 days ago now this hacking news. Wath a lucky person I'm. π
Bill
in reply to nixCraft π§ • • •Neil E. Hodges likes this.
Aaron Toponce βοΈ:debian:
in reply to nixCraft π§ • • •nixCraft π§
in reply to Aaron Toponce βοΈ:debian: • • •pete
in reply to Aaron Toponce βοΈ:debian: • • •@atoponce the hack looks to just be a defacement currently. the defacement is just links to this repository:
https://github.com/cassbethany10-afk/test123
which just has some syn flooders and whatnot. unlikely to be anything sophisticated.
GitHub - cassbethany10-afk/test123
GitHubpete
in reply to pete • • •pete
in reply to pete • • •pete
in reply to pete • • •pete
in reply to pete • • •@atoponce looks like the forums are back down???
https://fosstodon.org/@xinayder/116319094022309675
^ this fedi post seems to imply (to me) it was just stored XSS?
Alex (@xinayder@fosstodon.org)
Fosstodonpete
in reply to pete • • •@atoponce forums are undergoing an "upgrade", which is hopefully a patch for whatever the attack was.
EDIT: actually, i'm not sure. my phone might be caching the page and giving me that. a different browser is saying the forums are down.
nixCraft π§
in reply to pete • • •TomAoki
in reply to nixCraft π§ • • •@novet @atoponce
Anyway, the DNS entry for forums.freebsd.org seems to be removed currently.
% drill forums.freebsd.org @1.1.1.1
;; ->>HEADER<<- opcode: QUERY, rcode: NOERROR, id: 46711
;; flags: qr rd ra ; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;; forums.freebsd.org. IN A
;; ANSWER SECTION:
forums.freebsd.org. 60 IN A 127.0.0.1
;; AUTHORITY SECTION:
;; ADDITIONAL SECTION:
;; Query time: 13 msec
;; SERVER: 1.1.1.1
;; WHEN: Tue Mar 31 03:04:59 2026
;; MSG SIZE rcvd: 52
The answer could be because of local_unbound (running at 127.0.0.1 [localhost]).
For some (running) others and parent entry:
% drill freebsd.org @1.1.1.1
;; ->>HEADER<<- opcode: QUERY, rcode: NOERROR, id: 40850
;; flags: qr rd ra ; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;; freebsd.org. IN A
;; ANSWER SECTION:
freebsd.org. 3600 IN A 96.47.72.84
;; AUTHORITY SECTION:
;; ADDITIONAL SECTION:
;; Query time: 18 msec
;; SERVER: 1.1.1.1
;; WHEN: Tue Mar 31 03:05:34 2026
;; MSG SIZE rcvd: 45
% drill bugs.freebsd.org @1.1.1.1
;; ->>HEADER<<- opcode: QUERY, rcode: NOERROR, id: 53700
;; flags: qr rd ra ; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;; bugs.freebsd.org. IN A
;; ANSWER SECTION:
bugs.freebsd.org. 60 IN CNAME web3.nyi.freebsd.org.
web3.nyi.freebsd.org. 3600 IN A 96.47.72.106
;; AUTHORITY SECTION:
;; ADDITIONAL SECTION:
;; Query time: 35 msec
;; SERVER: 1.1.1.1
;; WHEN: Tue Mar 31 03:06:29 2026
;; MSG SIZE rcvd: 73
% drill www.freebsd.org @1.1.1.1
;; ->>HEADER<<- opcode: QUERY, rcode: NOERROR, id: 36543
;; flags: qr rd ra ; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;; www.freebsd.org. IN A
;; ANSWER SECTION:
www.freebsd.org. 10 IN CNAME web.geo.freebsd.org.
web.geo.freebsd.org. 150 IN A 192.50.199.250
web.geo.freebsd.org. 150 IN A 210.231.212.93
;; AUTHORITY SECTION:
;; ADDITIONAL SECTION:
;; Query time: 174 msec
;; SERVER: 1.1.1.1
;; WHEN: Tue Mar 31 03:06:02 2026
;; MSG SIZE rcvd: 87
Neil E. Hodges
in reply to nixCraft π§ • •bazkie π©πΌβπ» bitplanes π΅
in reply to nixCraft π§ • • •Neil E. Hodges likes this.
ΤΡΞ·Ο ΠΊΞΉ, ζζγππ§β π β«βͺ
in reply to nixCraft π§ • • •Neil E. Hodges
in reply to ΤΡΞ·Ο ΠΊΞΉ, ζζγππ§β π β«βͺ • •If you go to the FreeBSD forums, you get this.
Neil E. Hodges
2026-03-30 16:59:23
ΤΡηυΠΊι, ζζγππ§β π β«βͺ likes this.
ΤΡΞ·Ο ΠΊΞΉ, ζζγππ§β π β«βͺ
in reply to Neil E. Hodges • • •this is not the expected source from FreeBSD.org itself. Your link mirrors only this timeline here. So it has no more value . Authorized message from FreeBSD please
@nixCraft
Neil E. Hodges doesn't like this.
nixCraft π§
in reply to ΤΡΞ·Ο ΠΊΞΉ, ζζγππ§β π β«βͺ • • •Neil E. Hodges
in reply to nixCraft π§ • •Ray McCarthy
in reply to nixCraft π§ • • •Oh dear. :(
Just the forums? The packages & manuals not affected?
Richard
in reply to nixCraft π§ • • •ΔΓKΓπ»π»β’
in reply to nixCraft π§ • • •cynical melomaniac :tux:
in reply to nixCraft π§ • • •caveknoll
in reply to nixCraft π§ • • •