Live data from Hacker News

How I hijacked the top-level domain of a sovereign state

labs.detectify.com

11–20 of 65 posts

Re: How I hijacked the top-level domain of a sovereign state

#11
post #3

It pisses me off that for something of this magnitude this guy will probably only be paid no more than a couple thousand dollars, if at all. He still has no response.

I work for a few a cities in Europe, and happen to know one of the cities had a site with an sql injection issue. An external person found and let the city know but didn't want to reveal the specifics before getting money. The city has no bounty program and for some people in the City it came across as if the guy was distorting them. The guy probably felt like he didn't get money for his work. Probably both have a point. In the end it got resolved.

Re: How I hijacked the top-level domain of a sovereign state

#13

Shouldn't he have acted when he noticed the soonish expiration instead of hoping to be the only one watching for expiration?

It's not uncommon for organisations to be late with renewing their domains and you probably don't want to send false alarms.

Re: How I hijacked the top-level domain of a sovereign state

#14
post #3

It pisses me off that for something of this magnitude this guy will probably only be paid no more than a couple thousand dollars, if at all. He still has no response.

It may not directly pay but his reputation as Security Expert is enhanced.

I don't know if "Big Internet" (ICANN, IANA, IETF, RIRs) does not have its own security group like the Commercial companies do (Project Zero, various EH companies). RFC3013???

We have to depend on people who can take time to look for exploits in exchange for reputation.

Re: How I hijacked the top-level domain of a sovereign state

#15
post #4

Could this be leveraged to hijack additional TLDs? If any other TLD uses a ".cd" NS, like .cd used a ".com" NS...? (Are there any?)

Yes, although it's hard to imagine any TLD using .cd for NS.

It would also be less effective unless that TLD was using .cd for ALL of it's NS records.

Re: How I hijacked the top-level domain of a sovereign state

#16
post #11
post #3

It pisses me off that for something of this magnitude this guy will probably only be paid no more than a couple thousand dollars, if at all. He still has no response.

I work for a few a cities in Europe, and happen to know one of the cities had a site with an sql injection issue. An external person found and let the city know but didn't want to reveal the specifics before getting money. The city has no bounty program and for some people in the City it came across as if the guy was distorting them. The guy probably felt like he didn't get money for his work. Probably both have a po…

The guy has no reason to expect a reward if the city has no bug bounty program. They could just sue him.

Re: How I hijacked the top-level domain of a sovereign state

#17
I had a gut feeling it will be '.cd' before clicking on the article and I was right. Dealing with the state entity (SCPT) that manages this TLD is quite a pain. It's so painful that I've given up managing all the .cd domains I used to own.

.cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously.

Re: How I hijacked the top-level domain of a sovereign state

#18
Of course, the moral of the story goes beyond TLDs and for nameserver hostnames in general.

Interesting that it wasn't drop-catched, as .com names tend to be. I suppose it didn't have any metrics that'd qualify it for automatic registration.

Not even for 'domain tasting', though I guess it depends on drop catchers setups, which I imagine is just interested in any traffic on port 80/443.

Re: How I hijacked the top-level domain of a sovereign state

#19

Shouldn't he have acted when he noticed the soonish expiration instead of hoping to be the only one watching for expiration?

Exactly what I thought. It would have been more ethical to write to them the day BEFORE the expiration (and still buy the domain if they didn't act fast enough).
Post reply on HN