| $ dig platform.twitter.com | |
| ; <<>> DiG 9.8.3-P1 <<>> platform.twitter.com | |
| ;; global options: +cmd | |
| ;; Got answer: | |
| ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23125 | |
| ;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 0 | |
| ;; QUESTION SECTION: | |
| ;platform.twitter.com. IN A | |
| ;; ANSWER SECTION: | |
| platform.twitter.com. 22 IN CNAME san.twitter.com.edgekey.net. | |
| san.twitter.com.edgekey.net. 9701 IN CNAME e5903.g.akamaiedge.net. | |
| e5903.g.akamaiedge.net. 12 IN A 23.50.177.224 | |
| ;; Query time: 49 msec | |
| ;; SERVER: 192.168.5.1#53(192.168.5.1) | |
| ;; WHEN: Mon Sep 23 12:53:31 2013 | |
| ;; MSG SIZE rcvd: 128 | |
| $ curl --verbose http://platform.twitter.com/widgets/tweet_button.html | |
| * About to connect() to platform.twitter.com port 80 (#0) | |
| * Trying 23.50.177.224... | |
| * connected | |
| * Connected to platform.twitter.com (23.50.177.224) port 80 (#0) | |
| > GET /widgets/tweet_button.html HTTP/1.1 | |
| > User-Agent: curl/7.24.0 (x86_64-apple-darwin12.0) libcurl/7.24.0 OpenSSL/0.9.8x zlib/1.2.5 | |
| > Host: platform.twitter.com | |
| > Accept: */* | |
| > | |
| < HTTP/1.1 200 OK | |
| < Cache-Control: no-cache | |
| < Last-Modified: Thu, 19 Sep 2013 23:54:42 GMT | |
| < ETag: "86e25ce34214e039e32bd33c7aaeefa6" | |
| < Content-Type: text/html; charset=utf-8 | |
| < Date: Mon, 23 Sep 2013 10:51:43 GMT | |
| < Transfer-Encoding: chunked | |
| < Connection: keep-alive | |
| < Connection: Transfer-Encoding | |
| < P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT" | |
| < | |
| <[redacted]* Closing connection #0 |
| $ dig platform.twitter.com | |
| ; <<>> DiG 9.8.3-P1 <<>> platform.twitter.com | |
| ;; global options: +cmd | |
| ;; Got answer: | |
| ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29545 | |
| ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0 | |
| ;; QUESTION SECTION: | |
| ;platform.twitter.com. IN A | |
| ;; ANSWER SECTION: | |
| platform.twitter.com. 1 IN CNAME cs107.wac.edgecastcdn.net. | |
| cs107.wac.edgecastcdn.net. 1733 IN A 68.232.35.139 | |
| ;; Query time: 394 msec | |
| ;; SERVER: 192.168.5.1#53(192.168.5.1) | |
| ;; WHEN: Mon Sep 23 12:53:30 2013 | |
| ;; MSG SIZE rcvd: 93 | |
| $ curl --verbose http://platform.twitter.com/widgets/tweet_button.html | |
| * About to connect() to platform.twitter.com port 80 (#0) | |
| * Trying 68.232.35.139... | |
| * connected | |
| * Connected to platform.twitter.com (68.232.35.139) port 80 (#0) | |
| > GET /widgets/tweet_button.html HTTP/1.1 | |
| > User-Agent: curl/7.24.0 (x86_64-apple-darwin12.0) libcurl/7.24.0 OpenSSL/0.9.8x zlib/1.2.5 | |
| > Host: platform.twitter.com | |
| > Accept: */* | |
| > | |
| < HTTP/1.1 200 OK | |
| < Accept-Ranges: bytes | |
| < Content-Disposition: attachment; filename=widgets/tweet_button.html.torrent; | |
| < Content-Type: application/x-bittorrent | |
| < Date: Mon, 23 Sep 2013 10:48:41 GMT | |
| < Last-Modified: Sun, 22 Sep 2013 15:21:48 GMT | |
| < P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT" | |
| < Server: ECS (ory/439A) | |
| < X-Cache: HIT | |
| < Content-Length: 301 | |
| < | |
| * Connection #0 to host platform.twitter.com left intact | |
| d8:announce42:http://tracker.amazonaws.com:6969/announce13:announce-listll42:http://tracker.amazonaws.com:6969/announceee4:infod6:lengthi66948e4:name25:widgets_tweet_button.html12:piece lengthi262144e6:pieces20:???? ,?aG??E????12:x-amz-bucket11:tfw-current9:x-amz-key25:widgets/tweet_button.htmlee* Closing connection #0 |
This comment has been minimized.
This comment has been minimized.
mauricesvay
commented
Sep 23, 2013
|
Happened to me a couple of times |
This comment has been minimized.
This comment has been minimized.
tiernano
commented
Sep 23, 2013
|
Could this be an Amazon bug? Amazon allow distributing of anything on S3 as a Torrent by adding ?torrent to the end... |
This comment has been minimized.
This comment has been minimized.
zeisss
commented
Sep 23, 2013
|
Cannot reproduce. I have the same IP, but do not get the torrent file. Using Chrome from Germany, Europe. |
This comment has been minimized.
This comment has been minimized.
nicolsc
commented
Sep 23, 2013
|
More likely an AWS S3 bug d8:announce42:http://tracker.amazonaws.com:6969/announce13:announce-listll42:http://tracker.amazonaws.com:6969/announceee4:infod6:lengthi66948e4:name25:widgets_tweet_button.html12:piece lengthi262144e6:pieces20:≈˙ä��⁄� �,‹aG¢˝E¢éfiÕ12:x-amz-bucket11:tfw-current9:x-amz-key25:widgets/tweet_button.htmlee |
This comment has been minimized.
This comment has been minimized.
manuelbua
commented
Sep 23, 2013
|
You can reproduce it by pretending that the IP is "68.232.35.139", add this to your /etc/hosts file:
Now performing the request via cURL:
|
This comment has been minimized.
This comment has been minimized.
mRB0
commented
Sep 23, 2013
|
Getting it from 93.184.216.139 as well:
Opening this news article gives me two torrent downloads in Firefox & Safari (but not Chrome) which is unfortunate. |
This comment has been minimized.
This comment has been minimized.
momchenr
commented
Sep 23, 2013
|
Happened to me, too. This was the file contents:
|
This comment has been minimized.
This comment has been minimized.
dvkch
commented
Sep 23, 2013
|
Happened to me on a lot of blogspot website, OSX 10.8.5, latest safari for this OS |
This comment has been minimized.
This comment has been minimized.
potatono
commented
Sep 23, 2013
|
https does not have the cached torrent result. $ curl -v "https://platform.twitter.com/widgets/tweet_button.html"
< HTTP/1.1 200 OK |
This comment has been minimized.
This comment has been minimized.
alnjxn
commented
Sep 23, 2013
|
Confirmed on Chrome Version 29.0.1547.76, OS X 10.8.5. Example Link |
This comment has been minimized.
This comment has been minimized.
orclev
commented
Sep 23, 2013
|
I had that pop up the other night when I was viewing some website that I can't recall anymore. I believe it was on Windows 7 with the latest Firefox stable release. I suspected the site had simply been compromised in some way and that this was some new attempt at malware, but now I'm thinking it might be some kind of bug/exploit in either AWS or Twitter. Going to be interesting to find out what's actually causing this to happen. |
This comment has been minimized.
This comment has been minimized.
srs81
commented
Sep 23, 2013
|
Happened to me this morning on TechCrunch! |
This comment has been minimized.
This comment has been minimized.
entropymedia
commented
Sep 23, 2013
|
This just happened to me on ft.com |
This comment has been minimized.
This comment has been minimized.
killercup
commented
Sep 23, 2013
|
This just happened to me on businessinsider.com, I was wondering why Chrome downloaded a .torrent file. |
This comment has been minimized.
This comment has been minimized.
ramnathv
commented
Sep 23, 2013
|
Happened to me at a blog site. I was wondering too what caused the random torrent download. |
This comment has been minimized.
This comment has been minimized.
jturolla
commented
Sep 23, 2013
|
Happened to me at http://techcrunch.com/2013/09/22/hackathons-hyperbole-and-how-to-find-a-parking-spot-in-rio-de-janeiro/, reproduceable many times. |
This comment has been minimized.
This comment has been minimized.
thessalianpine
commented
Sep 24, 2013
|
Happened yesterday on www.spiegel.de and again just now at a random weblog. platform.twitter.com resolves to 68.232.35.139. Chrome 29.0.1547.76 m on Windows 8. |
This comment has been minimized.
This comment has been minimized.
roxlukas
commented
Sep 24, 2013
|
I have encountered the same on my Wordpress blog; all Twitter buttons cause this behaviour. |
This comment has been minimized.
This comment has been minimized.
bjporter
commented
Sep 24, 2013
|
This is still going on at a site I'm developing on as of 10:30 AM American/New_York EST time |
This comment has been minimized.
This comment has been minimized.
danbent
commented
Sep 24, 2013
|
File Name: widgets-tweet_button.html.torrent Contents: |
This comment has been minimized.
MichaelAz commentedSep 23, 2013
I can't seem to reproduce this. Could you post the torrent file returned?
If this can be consistently reproduced, this could be an interesting security threat.