S
S
Sap_ru2014-07-15 10:53:13
linux
Sap_ru, 2014-07-15 10:53:13

Why are pictures not displayed on Habré?

99% of images in posts are not displayed - they answer 404.
For example, from a fresh post , the first image leads to qrator.net/getpro/habr/post_images/4f6/cca/669/4f6... and answers:

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/1.4.4</center>
</body>
</html>
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->

Everything works on other sites.
The question is, what is it and how to find out what the problem is? In theory, I'm sitting through a proxy, but everything else works!
PS As good people suggest, links to pictures should actually lead to hstor.org. For me, it leads to qrator.net All other sites are displayed normally.
FFOX and Rekonq also lead to qrator. From a cell phone through the same network I see normal links. Those. either malware, or the provider is playing around, or something on our server. OS - Kubuntu latest.
PPS From under a clean virtual machine, everything works fine, i. ambush either on my machine or on the server. Unfortunately, there is no access to the server yet (there is no person responsible for it, and I don’t want to pick it myself unless absolutely necessary).
I checked several dozen popular sites - links to pictures are replaced only on Habré.
PPPS Miracles! I look at the source of the page - there are correct links. And on the screen - wrong.
hstor for any link returns 301 on qrator for my machine!
Found DNS spoofing via hosts.
And one more thing: Akhtung! When trying to add HTML code to the < blockquote > in the question, everything looks more than strange - is there a vulnerability there?

Answer the question

In order to leave comments, you need to log in

5 answer(s)
S
Sap_ru, 2014-07-15
@Sap_ru

Fake entries for habrastorage and several other Habr domains were found in etc/hosts (there was no change to the main domain).
In connection with the compromise, the system will have to be demolished, and all work over the past weeks will be checked and restored from version control. At the same time, damn it, now all computers that had access to need to be checked. It's a shame, sir.
But the very fact is surprising - a targeted attack on habrahabr ?!

D
Dmitry Entelis, 2014-07-15
@DmitriyEntelis

I have displayed.
Moreover, judging by the headers, they have nginx / 1.4. 7

A
Alexey, 2014-07-15
@Sterhel

All pictures are on hstor.org, check if you have this address blocked somewhere.
And whether a proxy is used.
From the post you specified - beta.hstor.org/getpro/habr/post_images/548/93c/520... you can see everything.
The problem is local.

S
serafims, 2015-06-11
@serafims

I had such garbage because of the HTTP Debugger program service. Apparently she could not work correctly with HTTPS. Killed the service and everything worked.

S
SinnerLike, 2015-07-29
@SinnerLike

in Google Chrome, this problem is created by the HTTPS Everywhere extension
, which opens sites via https if possible.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question