PDA

View Full Version : Facebook down?



barstein
10-16-2009, 01:59 PM
http://i36.tinypic.com/10fq6is.png
http://i36.tinypic.com/evct1z.png

Guess someone's new wiki stepped on the main site's toes? Can't tell if this is regional or not.

Fugitive
10-16-2009, 02:03 PM
Marked as WORKSFORME.

What IP address do you get for www.facebook.com? (e.g., doing an "nslookup www.facebook.com" from a command prompt) I get values in the 69.63.187.x range.

barstein
10-16-2009, 02:07 PM
69.63.181.12

MatthewF
10-16-2009, 02:07 PM
http://downforeveryoneorjustme.com/

barstein
10-16-2009, 02:12 PM
http://downforeveryoneorjustme.com/

Result: "It's just you"

Daughter in the next room can reach it just fine (her nslookup reports 69.63.181.15), while I alternate between the Wikimedia page and a 404.

Fugitive
10-16-2009, 02:12 PM
69.63.181.12
That maps back to Facebook's range, so it could be a browser hijack attempt. See if there's anything in your HOSTS file (under \windows\system32\drivers\etc) that tries to redirect facebook.com to a different address. Scans with the usual malware tools couldn't hurt, either (it could be injected code as well).

barstein
10-16-2009, 02:19 PM
Malwarebytes scan in progress. Hosts file is clean. Thanks for the tips. Part of my difficulty is the crash-course in Windows 7 security auditing, although so far it's not too bad.

Edit: Basic Malwarebytes scan came back clean. Time to do some deeper scans.

Edit 2: Also, router went belly-up last Saturday and I had to do an emergency replacement with a unit I still haven't researched properly (Linksys WRT310N). Although it's generally locked down, I imagine there could be a setting in there I overlooked that opened up a hole of some kind, or perhaps the router itself has been compromised in some way.

barstein
10-16-2009, 02:43 PM
Deeper scan is nearly complete and hasn't found anything, but meanwhile FB has become accessible to me (nslookup now shows 69.63.186.38).

Fugitive
10-16-2009, 02:47 PM
Weird. Maybe you just caught a brief window where they accidentally served the IP address of an internal test site or something.