bk99.de entertain the web since 1997

DNSpionage: When the registrar becomes the attack path

Summary

Brian Krebs reconstructs an espionage campaign that manipulated registrar accounts and DNS records to intercept the email and VPN access of numerous organisations. Netnod confirmed that its registrar account had been compromised. The attackers obtained certificates for manipulated mail destinations.

Ideas

  • Stolen registrar credentials can bypass all downstream security controls.
  • Manipulated DNS records quietly redirect mail and VPN traffic to attackers.
  • Control of a domain gives attackers seemingly valid TLS certificates.
  • Short redirections are enough to collect many valuable credentials.
  • DNSSEC only limits manipulation if name resolution validates trust without gaps.
  • Captive portals can push devices out of a protected DNS configuration.

Insights

  • Domain management is part of every organisation’s security boundary.
  • Valid encryption does not prove that the endpoint reached is legitimate.
  • Exceptional mobile situations can undermine otherwise strong infrastructure controls.

Quotes

  • The two people who did get popped, both were traveling. – Bill Woodcock

Habits

  • Krebs correlates public attack indicators with interviews with affected infrastructure operators.

Facts

  • At PCH, DNSSEC blocked most of the attack described.

References

Critique

  • The attribution at the time was based on indicators and remained politically disputed.
  • DNSSEC helped in the case described but does not prevent a compromised authoritative operator.

Remarks

  • The article treats domains as critical infrastructure rather than mere marketing addresses.
  • Certificate transparency provides an additional layer for detecting unwanted issuances.

Recommendations

  • Secure registrar access with a hardware factor and separate administrator accounts.
  • Monitor DNS changes and Certificate Transparency logs continuously.
  • Test mobile clients behind captive portals for DNS and certificate deviations.

Read the original article

Search the Web Archive