Important

This articles tangentially touches on animal abuse related themes. No images are shown and really I’m here to explain what the National Geographic tech team did wrong.

While browsing through the interwebs, I found out about a weird website hosted in a National Geographic page. Today I’ll talk about the contents of this page, and how such a weird page could be accessed by typing nationalgeographic.com in your browser.

Screenshot of the page, reading an article on “Usa Sexguide Michigan”, with flowery language

What’s on the page?

When looking deeper into the site, all of these articles are written by the same AI, called “Ashley”. This AI, features a profile picture taken by Mali Desha, a serbian photographer. Althought this photograhper likely has no involvement with the webpage.

The webpage features a wide range of topics, including ones like “Mr Hands Horse Video”, and other gruesome topics. Using flowery language to describe crimes (which is a tell-tale sign of AI-generated articles). For example, when talking about the “Mr Hands horse video”, it talks about using shock footage as advertisement material, as a way to “hook the viewer into engaging”.

Note that there are thousands of articles on this page. Literal thousands!!

Screenshot of the page, reading: “The impact of the Mr Hands Horse Video”, talking about the role of memes in digital communication, its ability of bring people together,

Oddities of the page

When inputting the webpage link (mumble.nationalgeographic.com) into a webarchiver such as archive.org, it shows up as https://cloud.teknodrem.com. Giving us the first clue to unravel this mistery.

Also, Note that the webpage has a very low rate limit. On less than 50 visits, I was already 24-hour blocked.

When trying to connect through a new IP address from the Netherlands, it redirects to “bing.com” (the Microsoft search engine). While on a nationalgeographic.com subdomain, we know that it is not hosted by Disney or National Geographic (Or Microsoft for that matter), but by a third party on AWS’ servers, on ec2-184-73-41-105.compute-1.amazonaws.com.

The webpage also links to a couple of domains, one being the aforementioned teknodrem.com, the other one being uptoyou.sbs. Both of these pages are in Indonesian and both host the same content. a static page showing the following: “BEK GADOH KALEN BOH GOP” Screenshot of the static page, just with that page and some shaders applied to make it look edgy and kinda retro

Being that mumble.nationalgeographic.com has a very strong domain, associated with a strong brand, its SEO score is very high. Producing very high ranks on search engines (I found this website as a first result on DuckDuckGo).

The sister domains are also not really connected. One of them is hosted with Cloudflare with the following nameservers:

While the other is registered with the Indonesias registrar “Rumahweb Indonesia”.

Enough information, what really happened?

What happened here is that National Geographic did not properly protect their DNS records! Someone (presumably someone from Indonesia) found a vulnerability in their DNS records and decided to highjack their domain. The vulnerability probably had something to do with their unsigned DNSSEC.

DNSSEC is a system that allows us to cryptographically sign a domain name. If this is not signed, pretty much anyone can highjack your domain. Someone on National Geographic forgot to sign it, and now everyone can claim their own subdomain :)

Conclusion

USE DNSSEC, OR I’LL GO HIGHJACK YOUR DNS

And that’s all, Let’s see how much time Disney waits for taking down the site (or taking down my blog, whatever happens next!)