MikeFarb @mikefarb1
#unhackthevote
Follow Up To Our Trump Server Thread!!
The Trump Organization Subdomains. Hacked? Compromised? Or Complicit?
Thread
twitter.com/mikefarb1/status/926221599522648064
A few days ago our team reported that more than 250 Trump Organization subdomains directed to servers in Russia.
Several publications picked up this story including Mother Jones.
In their article they assert that the Trump domain registry had been hacked by a third party. Lets take a closer look.
How could these 250 subdomains have gone unnoticed for four whole years?
Since they are using Go Daddy’d DNS Servers Any Changes Would Have To Be Made Through The Trump Organizations Go Daddy Account.
In an attempt to understand this better, we registered a new domain at GoDaddy:
toomanyfuckingcoincidences.com/
Then we had a look at the DNS records. This is what fresh, unspoiled DNS records look like. [I haven't included pictures - they're on the twitter thread]
So we added a few subdomains. Now look:
We tried to point one of our subdomains to the Russian IP that the Trump subdomains use, GoDaddy wouldn't let us due to security concerns.
Here's where it gets more interesting.
In 2015 Brad Parscale Comes in and Changes Were Made.
In 2015 the DNS for the domain name 721fifth.com was changed to point to a new host - trump2.parscalecloud.com .
Did no one notice that there were two suspicously named subdomains in that DNS record?