How I hijacked the top-level domain of a sovereign state
labs.detectify.com
labs.detectify.com
>On January 7th, I reached out to the Administrative and Technical contacts listed for .cd on [https://www.iana.org/domains/root/db/cd.html].
Seems odd to wait a week to make contact if this was purely a white-hat exercise.
He definitely acted decently overall (and did reach out to the people you mention afterwards). But I can empathize with the author for simply thinking "pending renewal? alright whatever" and later on "pending DELETE? shit I should make sure they're OK!".
I guess there's always what's best in hindsight and what's actually done.
The reason I think this is problematic is that there are already more than enough people in the security community who will either say "fuck it, I'm not gonna bother with that" or "let's sell it to the highest bidder".
We should appreciate more when people are trying to do the right thing and worry more about the people doing clearly the wrong thing and less about whether the people doing overall the right thing did it perfectly.
Wonder if that means they're investigating a "legal response" to his report?
eg the old "shoot the messenger" approach :/
.cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously.
I bought one a few years ago for 80 Euros / year. Aren't there a lot of TLDs that are way more expensive?
Many gTLDs are expensive due to their target demographics or to dissuade bad actors (eg .auto, .bank).
Good decision making on the DRC in the end. Well Done.
This was not a false alarm.
And yes, many scammers out there send postcards to businesses offering to assist for $1,000 on the renewals - and many people pay. So people do send out "alerts" the way you ask - most commonly exploitive and at least I give the advice to ignore ALL such renewal alerts. If you are telling people to respond to those you are sending people down scam ally.
DNS stops resolving because the domain is pending deletion. At that point it's not a renewal, it's a restore (which costs a lot more money). Refer to the brown "Domain no longer in zone" section of ICANN's lifecycle chart: http://archive.icann.org/en/registrars/gtld-lifecycle.jpg If people are actually regularly using restores instead of renews then they're unnecessarily throwing away lots of money.
> I've seen govt agencies use this as their reminder to renew.
What TLDs were these government agencies using? gTLDs have uniform policies but ccTLDs and special purpose TLDs like .gov do not (and you cannot generalize your experience there to gTLDs). But the expired nameserver domain registration under discussion in this article is a .com, which is a gTLD, so it goes through the standard lifecycle of 30 day redemption grace period + 5 day pending delete period, and during these its DNS is yanked.
Source: I've been in the domains industry for 7 years and run 44 TLDs.
As to govt agencies - sure, many use .org and .com domains routinely. These do not get special treatment - and I do generalize my experience from .com and .org to these govt run websites without hesitation.
Despite ideas - just because a public agency is using these domains does not make them magic.
to pick two domains within 10 seconds.
I'm going to stop here. Despite your claims that folks don't go into pending deletion - they do. I am responding to top comment - people fail to renew their domains on time routinely. I've seen it happen with some surprise in govt agencies (ie, someone in a dept spins up a website, and renews when someone complains its not working and they get permission to spend the money to renew - which is not instantaneous even for small purchases) as well.
All my points stand and I remain unconvinced by your claims that these govt agency websites can't expire (they do routinely), that pending deletion is a black swan event (it is not) or that folks don't fail to renew on a timely basis (they do frequently).
Wouldn't most of these be mitigated if that ccTLD used DNSSEC (according to dnsviz, it currently doesn't)? The hijacked DNS servers wouldn't be able to provide correctly-signed DNS records, so the fake answers would be rejected by all validating resolvers.
It would also be less effective unless that TLD was using .cd for ALL of it's NS records.
Interesting that it wasn't drop-catched, as .com names tend to be. I suppose it didn't have any metrics that'd qualify it for automatic registration.
Not even for 'domain tasting', though I guess it depends on drop catchers setups, which I imagine is just interested in any traffic on port 80/443.
The DRC has a lot of problems (to say the least) at the moment and has had for a while and this is pretty low priority in their scheme of things. Countries with weird residual TLDs for non-sovereign territory (e.g. .as or .ac) surely pay more attention to these trivial domains than anyone in the DRC can.
Which is all to say the amount of effort expended on any task, or the amount of knowledge brought to bear on a task, is only sometimes correlated with its value. Ever worked hard on a company that failed?
I felt I needed to put the first line in because my comment on your question could have been misinterpreted as criticism of the hacker.
That applies to most of us.
It also doesn’t change the fact that there is very little money available in the DRC.
s/distort/extort/I don't know if "Big Internet" (ICANN, IANA, IETF, RIRs) does not have its own security group like the Commercial companies do (Project Zero, various EH companies). RFC3013???
We have to depend on people who can take time to look for exploits in exchange for reputation.