Hacking root EPP servers to take control of zones
hackcompute.com
hackcompute.com
Apologies if I missed it, but were they testing from a trusted source, or are some registries that wide open?
Some registries are leaving their management systems open to the internet.
I recently tried reporting a security issue to a ccTLD. As a registrar thankfully I was able to reach out to ICANN for assistance, but even then the person who operated the TLD had just retired and there was no replacement.
Certificate issuance doesn't need to be perfect. We have Certificate Transparency, for example to catch missisuance and CAA records to restrict the process.
I'm not shocked? The website discusses audit responsibilities quite a bit, which seems like it mitigates tampering concerns. Sure I'd prefer something other than Salesforce too, but I'm not seeing a glaring issue here.
In addition, they seemed to have access to the source code, whereas the opensource version hasn't been updated in more than 8 years.
Maybe this is the result of a whitebox security audit?
Like @silisili said most of the registry operators require client certs and ips to go with the usernames but it is very possible that they are only checking that after getting a login.
CoCCA run by the tiny zones with no budgets. They are likely to be VERY vulnerable to this.
With exploitation of the right domains you would probably be able to extend this hack using stolen authentication information to take over basically the entire Internet.
Funny hack of my own once: a major web hosting company had a forum which failed to check uploaded profile pics were images, so I used it to upload a script so I could browse their entire filesystem. I eventually came across their root password stored in plaintext in a configuration file. The password? "internet" - all lowercase, just like that.
Can you send me info on this to mcilwain@google.com ? Thanks.
> We discovered that one of the maintainers of the .AI registry is a person named Vince.
I wonder if Vince lives in Nebraska: https://xkcd.com/2347/
Sure - taking the provider down is bad - but that happens due to unscheduled downtime every other day?
>> Speaking with Vince (the administrator of the .ai zone) over WhatsApp, we confirmed that compromising this server would give us full control over any .ai domain:
>> Once administrative access is gained to the CoCCA application, it is possible to control the nameservers for every domain for that ccTLD.
The point is to control domains in a ccTLD. Arbitrary domain hijacking is bad...
Looks like it was via the backup files: