How $20 and a lapsed domain allowed security pros to undermine internet integrity
ID: 4f899609-e758-55dd-b605-0f9537b41600
STIX ID: report--4f899609-e758-55dd-b605-0f9537b41600
Feed Name: The Register (Security)
watchTowr Labs bought an expired WHOIS host (whois.dotmobiregistry.net), ran a replacement WHOIS server, and observed >135,000 unique systems and >2.5M queries—many from security firms, registrars, certificate authorities, and government/military mail servers—that continued to query the expired host; the experiment demonstrates a systemic infrastructure trust vulnerability where an attacker could repurpose expired domains to spoof ownership data, potentially enabling fraudulent TLS/SSL certificate issuance, large-scale interception, or triggering remote code execution in vulnerable WHOIS clients.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
