We spent $20 to achieve RCE and accidentally became the admins of .mobi
labs.watchtowr.com
We spent $20 to achieve RCE and accidentally became the admins of .mobi
1–10 of 391 posts
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#2Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#3Let's add a few:
1. WHOIS isn't encrypted or signed, but is somehow suitable for verification (?)
2. DNS CAA records aren't protected by DNSSEC, as absence of a DNS record isn't sign-able (correction: NSEC is an optional DNSSEC extension)
3. DNS root & TLD servers are poorly protected against BGP hijacks (adding that DNSSEC is optional for CAs to verify)
4. Email, used for verification in this post, is also poorly protected against BGP hijacks.
I'm amazed we've lasted this long. It must be because if anyone abuses these issues, someone might wake up and care enough to fix them (:
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#4https://www.cloudflare.com/learning/security/what-is-remote-...
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#5Great write-up - the tip of the iceberg on how fragile TLS/SSL is. Let's add a few: 1. WHOIS isn't encrypted or signed, but is somehow suitable for verification (?) 2. DNS CAA records aren't protected by DNSSEC, as absence of a DNS record isn't sign-able (correction: NSEC is an optional DNSSEC extension) 3. DNS root & TLD servers are poorly protected against BGP hijacks (adding that DNSSEC is optional for CAs to veri…
NSEC does this.
> An NSEC record can be used to say: “there are no subdomains between subdomains X and subdomain Y.
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#6If only the naysayers had listened and fixed their parsing, the post authors might've been spared.
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#7Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#8I don't want to live on this planet anymore
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#9- Be inherently less trustworthy of more unique TLDs where this kind of takeover seems more likely due to less care being taken during any switchover.
- Don't use any "TLS/SSL Certificate Authorities/resellers that support WHOIS-based ownership verification."
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#10Great write-up - the tip of the iceberg on how fragile TLS/SSL is. Let's add a few: 1. WHOIS isn't encrypted or signed, but is somehow suitable for verification (?) 2. DNS CAA records aren't protected by DNSSEC, as absence of a DNS record isn't sign-able (correction: NSEC is an optional DNSSEC extension) 3. DNS root & TLD servers are poorly protected against BGP hijacks (adding that DNSSEC is optional for CAs to veri…
It took me 3 years of getting SSL certs from the same company through a convoluted process before I tried a different company. My domain has been with the same registrar since private citizens could register DNS names. That relationship meant nothing when trying to prove that I'm me and I own the domain name.
I went back to the original company because I could verify myself through their process.
My only point is that human relationships is the best form of verifying integrity. I think this provides everyone the opportunity to gain trust and the ability to prejudge people based on association alone.