Possible Honeypot in Latest Wikileaks Tweet

Ok. So I just happened to open up wikileak's twitter a few minutes ago, just in time to see two tweets go live. The first is a repost of the earlier picture, with a caption. The second is a link to a "Statement by wife Susan Benn on the death of her husband & WikiLeaks board member, Prof Gavin MacFadyen," with a link.

Here's where it gets fucking weird. I, of course, clicked the link. It hung. That's when I noticed it wasn't an https. So I edited it, and imagine my surprise when firefox gave an SSL certificate warning. The certificate is issued to logancij.com, not tcij.org.

So I pulled it up in Tor. Added an exception for the certificate. That's when it got really scary, see pic 3. I denied the pull request and waited. Nothing, except a page not found header. No 404 page or anything ever loaded. I'm sure as hell not permitting a canvas pull, and this is all definitely a little weird.

Discuss and dig, or sage. there's too many threads going nowhere today.

Other urls found in this thread:

archive.is/LLbIq
blog.fox-it.com/2015/04/20/deep-dive-into-quantum-insert/
twitter.com/wikileaks/status/789989007048511488
en.wikipedia.org/wiki/Room_641A
8ch.net/pol/res/7950054.html#7951268
8ch.net/pol/res/7938405.html
twitter.com/SFWRedditImages

one single bump.

this looks an awful lot like an identification attempt to launch a payload against a specific target, as described in the snowden documents
they probably hijacked the redirect link to the statement by his wife
the nsa is probably trying to locate the keys, hoping the keyholders will be complacent enough to click a link they believed trusted

tell wikileaks about this, they can try to delete the dangerous tweet or at least see what it does

yeah that is fucked (didn't go to the site, went to whois). Was thinking possibly some idiot repeated the same cert for two sites. They didn't and second site owner (the one where the cert is) has hidden ownership.


THIS
I don't have twitter or I would.

I really have no fucking idea what's going on with wikileaks. I've ran into people that I trust talking about how they think that saying wikileaks is compromised is the newest shill tactic which makes sense but at the same time there's definitely suspicious activity going on from them.

OP here. I don't have a twitter.

The link is wrapped by twitter's t.co, we were suspicious that was compromised days ago. I've managed to locate a google snapshot of the page, it's a legitimate statement by his wife. However something really, really, REALLY fucked is going on with the traffic there.

bump

Bumb

So it's been compromised after all?

Holy fuuk thats creepy shit. Bump

It's a man in the middle attack

fuuuck, I don't have a twitter either
someone transmit them the info in this thread as soon as possible? pretty please?

I don't know what to believe anymore. I honestly don't think it's a shill tactic, I think it's just something that caught on among us. Or maybe it really is disinfo. I really don't know anymore.

This doesn't prove wikileaks is compromised, the statement is real and the guy was probably disappeared. But some of twitter's t.co traffic is definitely being intercepted, that much is pretty certain at this point.

So Julian is a satanist, ok.

Spookey.

Sage this thread.

If JA is not hoffa 2 right now then why nothing but ct. Cucks it's 3 weeks out, this is shit or get off the pot time. This drama is just a distraction and you are spooning it down your throat.

...

SOMEBODY WITH A TWITTER TELL WIKILEAKS TCIJ.ORG's TRAFFIC IS BEING INTERCEPTED.

Sock it to him, forever, Gavin?
-JA?
Did Julian ever talk like that?

...

I can tweet at them who knows if they'll see/respond

Wouldn't it have to generate something in the canvas tag first?

Wouldn't it be better to email them? Finding someone with a twitter here seems to be as easy as finding an honest man in Tel Aviv.

just logged in to say I don't have a twitter either

I see 2 possibilities
either their communication chanels are hijacked an an unreachable level
and as WL can't afford not to communicate, they can't stop hostiles from sending messages in their name
if (((these hostiles))) went too far, WL would send a debunk message and would have to cease using twitter, but this would cause other problems, namely making the key release way more difficul
or
they've begun sending more noise in their tweets to mask (or allow) the release of codewords to keyholders, so their tweets seem to have changed in tone and style

This might be unrelated, but I noticed wikileaks deleting several twitter posts earlier. Is that normal?

dude i don't know. I'm a mechanic, not a script kiddie. I have no idea what I'm looking at except that it stinks to high heaven

i tweeted them a couple times

They're similar sites that most likely have the same people involved.

What you're describing isn't enough to say this is a honeypot.

bot detekted

Team Clinton is getting despite, Trump gets in and a lot of people are going to jail for treason.

Don't think so. I don't think they've ever deleted twitter posts until the past week or two.

I wouldn't call it a honeypot necessarily

Maybe the server is compromised somehow? Part of ops against anyone involved with wikileaks who might have the keys?

you're right, they're definitely related. Honeypot is the wrong word for what's going on.

That's what my initial thought was. That some admin who runs both sites jimmied up the cert. Possibility they are bost hosted off the same server / ip. Could be a misconfig, but doesn't really reinforce good opsec for Wikileaks board members (deceased or not).

I just sent @wikileaks a DM on Twitter. Why not.

There was another thread about this over at cuckchan. They described it as a Man in the Middle Attack (MITM). archive.is/LLbIq

They deleted the one where they mentioned the use of ((()))

Similar activity was happening with an ozzy poster trying to connect to twitter. IC cert. Out of my expertise.

Confirming that the link has been stripped of HTTPS for me also.

This indicates MITM orchestrated at a state level, no?

During yesterdays DDOS***

If relevant, also connecting via proxy in Australia.

you do fucking realize that whatever that green tag is next to all those links is tracking every website you go to reading and sending forwards all links and everything you search is being sent to their servers "for comparison" is stored and can be sold forwards
you are giving away everything your browsing

unless you trust your (((antivirus company))) >9000% to not exploit/sell/nasa that info i would uninstall whatever that plugin is

Ok, so what are the consequences of clicking on that link?

Holla Forums here. No, everything is fine. Sometimes web admins are too retarded to setup their certificates which may look like spoof attempts to browsers. It also happens when cert directories fuck up for a given public key.

If this site would be an attack vector, they would have substituted a cert and shat on you instead of what you suppose. Canvas calculation is not always malicious or identifying attempts, depending on how the website was setup. Most (legit) sites use canvas fingerprinting for ads.

Figured it was a misconfiguration. I always figured hardcore MitM attack be nearly invisible to the end client? Still shitty opsec.

It depends. If the logancij.com domain is legit, and the certificate is the same for both domains the admin only made a mistake. But if the certificate is different, or logancij is not owned by the same guy then there's something very wrong.

MacFadyen passed away after a short illness on October 22 2016.

WTF, Clinton killed any other person

It can be invisible if the attacker has access to a legit CA (certificate authority, the guys who emit the certs). If any of the dozens of CAs your browser trusts gives them a cert you'll access their server, see their cert, it matches, and go your way as if everything was fine. There have been a few cases where CAs either fucked up big time or were doing something shady.

I met a guy a while ago at a Bitcoin party that had couch-surfed at Assange's prior to WL becoming a big thing. He said all that shit about Julian being a cunt was bullshit btw. Apparently a really good guy.

I think he also mentioned that he did some campaign work for him. Have hit him with a message to see if he knows anyone that might be able to give more info.

Will let you guys know if I get a response.

Make sure you don't post or say anything that breaks opsec - NSA types are hunting down anyone connected with wikileaks who might have the insurance keys.

This is being covered in mentioned thread, but the real concern with this website might be a quantum insert attack, which a HTTPS connection can at least help mitigate:
blog.fox-it.com/2015/04/20/deep-dive-into-quantum-insert/

Someone want to visit the suspicious page and do some packet sniffing to see if you get duplicate packets with suspicious-looking payloads?

here's the tweet

twitter.com/wikileaks/status/789989007048511488

checking those dubs

He will not have any keys, I am sure of this.

His affiliation was very loose. He might have someone we can contact though.

it was just an illness silly boys…

fuck, this is too real

I saw an old post on Holla Forums about this David Brock chat that was reportedly leaked. Maybe this has something to do with it?

I'd like to add that any alphabets reading any of this should defy or defect immediately.

You are betraying your people.

this you fucks, you should be ashamed!

Right now, I think a lot of them are trying to justify it to themselves as doing what needs to be done to keep us out of world war / civil war.

Best of intentions with the worst of results.

I should add that a fair number are of course sociopaths/psychopaths who don't care so long as they've got money.

...

theres nothing fucky going on IMO

just an idiot admin who runs both sites has the https set with the wrong cert ala he had no intention of having https working on lcij.org but hes copied over the webserver configs from logancij.com

...

Your anti-tracking add-on could tell you something, possibly highlight irregularities.

No.

I'm pretty sure Assange is dead at this point, and TPTB are maintaining a (poor) illusion he's still alive. Probably completely on purpose to spread confusion on places like 8ch.

The most important thing now is to check the hashes of every email in the leaks from the day Assange's internet was cut onwards. Try and find any fakes that have been inserted or edited emails. If they exist, the next big issue will be proving the releases have been corrupted by alphabet soup before the MSM gets their claws into this.

If they're actually compromised, I fully expect to see completely made up stuff "exposing" Trumps ties to Russia.

Too obvious. It'd be subtle shit, like that "our supporters are DDOSing the US" tweet.

I think they've learned their lesson about subtlety, I fully expect they'll do just enough to discredit WikiLeaks as a trustworthy source in the eyes of Joe Public and leave it at that.

Assange went silent so he could distance himself from the whole charade. I have a sneaking suspicion that dare i say it the WHOLE internet is compromised

you mean the "joe public" who isn't reading about these leaks in (((msm))) anyway?
you mean the "joe public" who can be distracted with internet porn and sportball?
go concern troll somewhere else

Done

I think he's enroute to Russia.

(((our supporters))) is how i've been thinking about it

this was a "leak" from RealTrueNews, which is notorious for making shit up for clicks

If it was a legit WL post, my thought was that it could be to demonstrate that WL have the capability to black out controlled centers, thus killing alphabet's entertainment/distraction ability.

This is a bit of a stretch though. The post itself is very suspicious.

the whole internet has been compromised for a while fam

en.wikipedia.org/wiki/Room_641A

I wouldn't trust an 'official' post on any mainstream social network.

I see you're evolving, CTR.

thought you were clever, didn't you, kike?

I'd expect them to put out a bullshit one that's obviously faked. Then MSM "exposes" how wikileaks was caught lying in an attempt to poison the well and discredit all the previous leaks.

Do me a favour and point out where exactly I said that. Oh, that's right. I didn't.

In fact I said the exact opposite, keep reading them and check their hashes for authenticity.

It's really cute how you think if you try to call out shills the way we've done to you for the past year or more people will fall for it. Gotta make sure there's some (((parenthesis))) and a sage in your post, oh and don't forget to call someone a kike!

Or in your own parlance:

WEW
Your computer is already spying on you faggot.

Not to mention sending keystrokes back to Murkysoft.

More than dubs…

Fuck off CTR shills.

I have a thread on this already. It's a tool to grab your ip and then hit you with quantum insert. see my thread here: 8ch.net/pol/res/7950054.html#7951268

Actually no, it's a MoTS attack. look up foxacid and quantum insert.

we're fucked.

the post, other posts, Assange's radio silence, the timing of, well everything else right now…it would be somewhat interesting if WL's supporters were that 'vocal' about the compromise, but all of it really is just suspicious, like i-got-a-bad-feeling-in-my-gut suspicious, and the coincidences are piling up. gavin macfadyen's passing just today. i don't know. whatever's going on isn't good, and wikileaks is definitely going through some shit right now. this much we know.

you don't have to say it out loud
counting on Holla Forums paranoia
nice reddit spacing btw

I remember the tcig thing from the group that tried to frame Assange as pedophile, let me try to find the post.

Heard the term alphabet a lot, what does it refer to?

Alphabet agency like
fbi cia nsa

Found this, I think Wikileaks tweeted it.

Wrong thread.

...

Eh nevermind. It was icij.org, not tcij.org

Although… It's rather close.

Would a VPN protect against this?

Honest question - why doesn't Trump sue them like 8ch.net/pol/res/7938405.html

Surely using leaked government hacking tools (typically referred to WMDs of cybersecurity by anyone discussing them, "cyberweapons" at the least) is violating multiple federal laws.

At the very least it would shit down CTR instantly and stop them from ganging up on people.

Nervously loading my SKS magazine

...

Trump will shut them down when he's president. SuperPACs need to go.

its purpose usually isn't to get your IP so no.

Onto the filter list you go.

I think it's their way of saying they hope he's in hell. This stuff is incredibly creepy.

MODS BANNED THE LAST user WHO TRIED TO WARN EVERYONE

Careful OP

Unfortunately, not much available on this front.

He's aware of the internet cut, etc, but hasn't heard anything else from anyone direct.

He said he'll let me know if he gets any info.

Why can't I find it on the board log?

Nevermind, I found it.
It was the mod Heil.

Because your mods are dirtier than you think.

I can understand.
People are on edge because of ctr and for all we know the guy that got banned could have actually had a disruptive post history.
They hadn't even made the tweet when the thread was made.

When do we hang these faggots?

Sounds fake.

>I'm pretty sure Assange is dead at this point, and TPTB are maintaining a (poor) illusion he's still alive.

That speculation again.


What if you're the one doing that on purpose by claiming Wikileaks is now compromised and we have to "check the hashes of every email" which will probably slow down the process of finding good e-mails? If you think checking the hashes of every email is really important than start a thread specifically about that and then explain clearly what tools we need to do it and how to use them.

bump

Because the mods are paid shills, faggot. How new are you?

As soon as someone manages to doxx them.

Press f
Rip ja.

May tdotr come soon

and yea, every mod is a Jew. Whole site is owned by Jews. Just call them kikey if u want unban

?

...

He spoke to a conference visit phone just yesterday.

for the technically challenged that is

At this point it's not really important either way whether they're compromised or not. Act like they aren't as long as they keep hitting Clinton, act like they are if they start hitting Trump.

If they falsify something obviously we already have a working theory on how they got subverted.

Which reminds me, where the hell did that Korean sticky go? The one about Choi sun sil and Megalia. Was there with hundreds of replies one minute and gone the next.

Which reminds me, where the hell did that Korean sticky go? The one about Choi sun sil and Megalia. Was there with hundreds of replies one minute and gone the next.

Damage controlling faggot.

This is a little spooky

Molenjew mentioned the hoeypot theory with Weiner, which I never even thought of. If you are the FSB (or esp. the Mossad) and this crazed jew is sending dick pictures to any skank who contacts him, and he has access to sec. of state…my fear (but hope) is that Mossad got him and they'll have to tell the world.

pls fam, the reddit spacing meme is as transparent a d&c as "italians aren't white".