It's Way Too Easy to Get a .gov Domain Name
krebsonsecurity.com
It's Way Too Easy to Get a .gov Domain Name
1–10 of 184 posts
Re: It's Way Too Easy to Get a .gov Domain Name
#2Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs had gone off at polling stations in Democrat-leaning districts. Such a hoax could well decide the fate of a close national election.
Why the need to specify "Democrat" strongholds? Doesn't this attack work for any other political-party strongholds as well? Seems like an unnecessarily partisan position to take.
Re: It's Way Too Easy to Get a .gov Domain Name
#3Re: It's Way Too Easy to Get a .gov Domain Name
#4Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…
Re: It's Way Too Easy to Get a .gov Domain Name
#5The title reminds me when someone reported that it was just as easy to get fully-automatic firearms and other military gear from homeland security for free by pretending to be a police department (fake website) and a simple form.
Re: It's Way Too Easy to Get a .gov Domain Name
#6Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…
Re: It's Way Too Easy to Get a .gov Domain Name
#7Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…
Re: It's Way Too Easy to Get a .gov Domain Name
#8Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…
It could be criticized regardless of the characters chosen.
Re: It's Way Too Easy to Get a .gov Domain Name
#9Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…
But once you have the domain, somebody who knows what they're doing with DNS and SMTP absolutely could set up proper email services on it (forward-confirmed rDNS, SPF, DKIM signing, DMARC), and send spam with it. It's functionally equivalent to any other domain. Particularly if the intention was to be a one-shot approach that would "burn" both the domain and the hosting services, such as in the days leading up to an election.
A really smart bad actor would use some IP space from an ISP that traditionally has not been a source of spam. Eg: Not an ISP with a lot of low-dollar-value VPS/VM/hosting customers.
There's still some totally "clean" /24 IP blocks out there in the various RBLs and spam listing services if you go searching.
If I were an evil person and did this, I'd try to get the domain at least a few weeks in advance and try to generate a moderate volume of totally legit looking emails, destined for the top 20 major destinations (office365, gmail, etc) and verify from a bunch of sockpuppet accounts that the mail was actually getting delivered. Then I'd turn loose the fire hose.
Should a person want to be really evil, they'd do something like the reverse of what happened to the City of Baltimore with the cryptolocker trojan. Find a list of municipal (water, sewer, gas, electrical, property tax) bill payers and email each of them a plausible looking invoice, with cryptolocker attached. The likelihood of people opening it would be high.
Re: It's Way Too Easy to Get a .gov Domain Name
#10Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…