The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability
thehackerblog.com
thehackerblog.com
It's really "squatting on the domain ONLY in the space of a specific provider".
And, this isn't new. For example, you can do this on most shared hosting plans...add a domain, and they don't ask for any kind of verification.
The only thing this seems to accomplish is lock you, the legitimate domain owner, from using a specific service until you open a support ticket and hash it out with them. You still control the domain, so it's fairly easy to prove control/ownership.
That's not good, of course, but it's not the same thing as "taking over a domain". Your WHOIS records still point at your DNS servers, which still return the correct records.
Edit: It could, I suppose, be used to take over a mostly "abandoned" domain, where the WHOIS records still point at a provider with this issue, but the underlying account is gone. Again, an issue, but if the domain is abandoned, it's not the same thing as taking over arbitrary, in-use domains.
The main idea of this post is to be informational/raise awareness since I'd argue a large majority of users don't expect this behavior to occur.
- The original owner made that specific service the authoritative server for the domain with their registrar
- They then either never added the domain to the service, or added it, and later removed it...or killed the entire account.
As I mentioned, this is certainly an issue. But, the domain is basically abandoned. It's very similar to letting it expire. Something that should be fixed, for sure, but not a way to take over an actually functioning website.
The idea would be that a user has simply deleted/released the zone for a specific domain under their account. This could have happened because they plan on moving it later or because a lack of payment/service termination has occurred. This allows an attacker to obtain thousands of fresh domains easily with very little effort and likely no payment at all which can be used in malware campaigns/etc. Some common things I saw were indeed older unused domains, domain portfolio's of domain resellers/squatters, and even domains in restricted TLD spaces such as .gov, .edu, etc. These would certainly have value despite no longer being used.
Let me know if I've been unclear or am missing something here.
The author would therefore have complete control over the orphaned domains after the takeover.
- By definition, his method of finding domains only finds domains that aren't in active use. (domain servers in the ns records return fail/refused).
- It uses the terminology "taking over", and you're saying "complete control". However, if the real owner of the domain wanted control back, they would simply log into their registrar and change the NS records...very low effort.
a) With control of a domain's name servers you can set up working mail handling for a domain.
b) At least some HTTPS cert providers allow verification of domain ownership using email. eg click on a link in a mail they send to (say) postmaster@targetdomain.com
With those two in place, you can generate HTTPS certs for the domain. I'm not yet familiar with LetsEncrypt, but if they allow domain verification through email then this would even be a cost free exercise.
One day, they run out of money and close up shop. Their Amazon AWS accounts get shut down. The domain gets wiped from Route 53.
You come along and add foo.com as a hosted zone in Route 53. You point MX RRs towards a machine you control and begin reading the mail sent to $users@foo.com that will continue to arrive for the next several years. Perhaps you even use your new access to all @foo.com addresses to do some password resets on long forgotten accounts.
Typically, I wait until a domain hasn't been used legitimately for e-mail for at least one year (i.e. I'll set "null" MX records or point them to a non-existent host) before I repurpose them. You might be surprised at the types of e-mails that start flowing right back in after pointing the MX RR back to a real host: lots of it is crap (spam), but I've received travel itineraries, notifications from AmEx, appointment reminders from medical facilities, and all kinds of good stuff.
Unfortunately we now live in a world where control of DNS is proof of ownership. Look at the entire mess that is Domain Validated SSL certs and how CloudFlare has abused this to get certs for domains that have never pushed SSL traffic over their network.
We have never lived in a world where "control" of the Domain Name System was not equivalent to control of the domain name.
Let's face it, being able to serve content on a website at all is enough to prove you own it these days.
Google apps verification only asks the nameservers designated by the registrar for the domain.
Remember when Rackspace was a premium host that you happily paid more money to because they handled things the right way?