Slashdot Mirror


Reports of IE Hijacking NXDOMAINs, Routing To Bing

Jaeden Stormes writes "We just started getting word of a new browser hijack from our sales force. 'Some site called Bing?' they said. Sure enough, since the patches last night, their IE6 and IE7 installations are now routing all NXDOMAINs to Bing. Try it out — put in something like www.DoNotHijackMe.com." We've had mixed results here confirming this: one report that up-to-date IE8 behaves as described. Others tried installing all offered updates to systems running IE6 and IE7 and got no hijacking.
Update: 08/11 23:24 GMT by KD : Readers are reporting that it's not Bing that comes up for a nonexistent domain, it's the user's default search engine (noting that at least one Microsoft update in the past changed the default to Bing). There may be nothing new here.

7 of 230 comments (clear)

  1. Bad Posts by Microlith · · Score: 5, Insightful

    Yet another stupid, linkless, flamebait article.

    Come the fuck on guys.

    1. Re:Bad Posts by jpmorgan · · Score: 5, Insightful

      Seriously, this is the stupidest article I've seen on slashdot in a while. I tried on IE8 on this computer and it sends me to a google search. Oh noes!!! Google and Microsoft have teamed up to hijack NXDOMAIN!

      No, IE is just sending you to your default search engine. If you never use IE you probably never changed its default selection of bing/live search. And this isn't NXDOMAIN hijacking! This is an application interpreting an NXDOMAIN response and acting on it in a sensible way.... the kind of behavior that NXDOMAIN hijacking breaks. Seriously, this is a fucking stupid post.

    2. Re:Bad Posts by GeckoAddict · · Score: 5, Insightful

      One word: kdawson

  2. Re:It is just trying to be helpful. by ojintoad · · Score: 5, Insightful

    Take them to kdawson and force him to explain why I can't tag this !story since it is clearly NOT a STORY.

  3. Re:Ridiculous by nine-times · · Score: 5, Insightful

    Well even more to the point IMO: IE isn't "hijacking" NXDOMAIN because IE is the program you're requesting the domain from. Saying IE is hijacking your domain query is a little like claiming the normal pilot of a plane is hijacking it whenever he flies. No, he's not, he's the pilot. It's kind of his job.

    What I mean is, if I dropped to the command prompt and typed "nslookup [whatever]", is IE changing the results that I get? If not, then it isn't really fair to say they're "hijacking" anything. If you're typing a domain into your address bar of your browser, and you want something to figure out what you're trying to type and possibly redirecting to a search engine, then the browser is the appropriate place for that to happen. The complaints about DNS "hijacking" is because it's being done by the DNS server and not the browser, but the browser is actually the right place for this to happen.

    Now maybe they should offer the option to turn this on or off, but really as long as they're respecting your choice in search engines, I don't think there's a problem. It's a little like complaining that Firefox's Awesome Bar tries to guess what sites you're trying to find.

  4. kdawson needs to go by kuzb · · Score: 5, Insightful

    Seriously, how many bad articles does this guy have to post before he gets thrown off the slashdot team?

    --
    BeauHD. Worst editor since kdawson.
  5. Re:Confusing the service with the client... by Bigjeff5 · · Score: 5, Insightful

    Here here!

    My god, this service has existed since they launched IE6, it is simply turned off by default.

    Hit the big "Search" button in the toolbar, and hit customize, and you can change what search provider the address bar search uses. You can disable/enable/change the address bar search option in Internet Options/Advanced.

    They obviously recently updated the list of service providers to replace Live search with Bing. My guess is they changed the default address bar search behavior also, and anybody who was using the defaults got changed over.

    Nobody seems upset that Chrome does this by default, or that FireFox can do this too. Frickin hypocrites.

    Seriously, get ahold of yourselves people, you're really getting upset that IE tries to find the website you were looking for instead of saying "Website not found"? And it's somehow DNS hijacking? Get a grip people!

    --
    Security is mostly a superstition... Avoiding danger is no safer in the long run than outright exposure. - Helen Keller