logo

How $20 and a lapsed domain allowed security pros to undermine internet integrity

ID: 4f899609-e758-55dd-b605-0f9537b41600

STIX ID: report--4f899609-e758-55dd-b605-0f9537b41600

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-09-11

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

watchTowr Labs bought an expired WHOIS host (whois.dotmobiregistry.net), ran a replacement WHOIS server, and observed >135,000 unique systems and >2.5M queries—many from security firms, registrars, certificate authorities, and government/military mail servers—that continued to query the expired host; the experiment demonstrates a systemic infrastructure trust vulnerability where an attacker could repurpose expired domains to spoof ownership data, potentially enabling fraudulent TLS/SSL certificate issuance, large-scale interception, or triggering remote code execution in vulnerable WHOIS clients.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.