Live data from Hacker News

How I hijacked the top-level domain of a sovereign state

labs.detectify.com

21–30 of 65 posts

Re: How I hijacked the top-level domain of a sovereign state

#21
post #15
post #4

Could this be leveraged to hijack additional TLDs? If any other TLD uses a ".cd" NS, like .cd used a ".com" NS...? (Are there any?)

Yes, although it's hard to imagine any TLD using .cd for NS. It would also be less effective unless that TLD was using .cd for ALL of it's NS records.

Maybe you could find a cluster of TLDs delegating to each other in a loop. Combined with huge TTLs you might be able to bootstrap a full takeover of a subset of all DNS?

Re: How I hijacked the top-level domain of a sovereign state

#22
> Although one of the contacts replied and delegated to their colleague, as of this writing, I haven’t received any follow-up confirmation that they fixed the issue.

Wonder if that means they're investigating a "legal response" to his report?

eg the old "shoot the messenger" approach :/

Re: How I hijacked the top-level domain of a sovereign state

#23
post #13

Shouldn't he have acted when he noticed the soonish expiration instead of hoping to be the only one watching for expiration?

It's not uncommon for organisations to be late with renewing their domains and you probably don't want to send false alarms.

Once it's in the redemption grace period the domain is already on the way to deletion. That's not part of the normal domain lifecycle; that's part of the deletion lifecycle.

This was not a false alarm.

Re: How I hijacked the top-level domain of a sovereign state

#24
post #3

It pisses me off that for something of this magnitude this guy will probably only be paid no more than a couple thousand dollars, if at all. He still has no response.

It seems more likely that the OP even lost money buying a useless domain name that no one will pay for. Most probably not even a "Thank You" they will give.

Re: How I hijacked the top-level domain of a sovereign state

#25
> If I had operated with malicious intent, I could have also [...]

Wouldn't most of these be mitigated if that ccTLD used DNSSEC (according to dnsviz, it currently doesn't)? The hijacked DNS servers wouldn't be able to provide correctly-signed DNS records, so the fake answers would be rejected by all validating resolvers.

Re: How I hijacked the top-level domain of a sovereign state

#26
post #16
post #11

Earlier quoted context omitted.

I work for a few a cities in Europe, and happen to know one of the cities had a site with an sql injection issue. An external person found and let the city know but didn't want to reveal the specifics before getting money. The city has no bounty program and for some people in the City it came across as if the guy was distorting them. The guy probably felt like he didn't get money for his work. Probably both have a po…

The guy has no reason to expect a reward if the city has no bug bounty program. They could just sue him.

What are their damages? He's not required to disclose their security vulnerabilities to them. It's his work not theirs.

Re: How I hijacked the top-level domain of a sovereign state

#27
post #3

It pisses me off that for something of this magnitude this guy will probably only be paid no more than a couple thousand dollars, if at all. He still has no response.

It may not directly pay but his reputation as Security Expert is enhanced. I don't know if "Big Internet" (ICANN, IANA, IETF, RIRs) does not have its own security group like the Commercial companies do (Project Zero, various EH companies). RFC3013??? We have to depend on people who can take time to look for exploits in exchange for reputation.

Getting paid in exposure is not getting paid.

Re: How I hijacked the top-level domain of a sovereign state

#28
post #16
post #11

Earlier quoted context omitted.

I work for a few a cities in Europe, and happen to know one of the cities had a site with an sql injection issue. An external person found and let the city know but didn't want to reveal the specifics before getting money. The city has no bounty program and for some people in the City it came across as if the guy was distorting them. The guy probably felt like he didn't get money for his work. Probably both have a po…

The guy has no reason to expect a reward if the city has no bug bounty program. They could just sue him.

if he was smart, then he said nothing that sounds like blackmail. but you could say, for example, that I have to settle the expense of reproducing it and writing it down properly or something similar.

Re: How I hijacked the top-level domain of a sovereign state

#29
post #20

The most ethical move would have been to write to people listed at https://www.iana.org/domains/root/db/cd.html and put IANA in copy (likely ROOT-MGMT@IANA.ORG as listed in the public document: 24x7 Emergency Process Step-by-Step Description).

Quoting the article:

>On January 7th, I reached out to the Administrative and Technical contacts listed for .cd on [https://www.iana.org/domains/root/db/cd.html].

Re: How I hijacked the top-level domain of a sovereign state

#30
post #17

I had a gut feeling it will be '.cd' before clicking on the article and I was right. Dealing with the state entity (SCPT) that manages this TLD is quite a pain. It's so painful that I've given up managing all the .cd domains I used to own. .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously.

> .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously.

I bought one a few years ago for 80 Euros / year. Aren't there a lot of TLDs that are way more expensive?

Post reply on HN