logo

For Just $20, Researchers Seize Part of Internet Infrastructure

ID: 5bc13b2e-d1c3-50ff-bb37-8125c65edf01

STIX ID: report--5bc13b2e-d1c3-50ff-bb37-8125c65edf01

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-09-12

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Security researchers registered an expired WHOIS hostname previously used by the .mobi TLD and unexpectedly received millions of queries from tens of thousands of systems (including registrars, government mail servers, and security services). Their experiment showed that some Certificate Authorities rely on WHOIS data for domain control validation, allowing an attacker controlling an outdated WHOIS host to supply arbitrary administrative contact information and obtain fraudulent TLS/SSL certificates or perform passive traffic analysis. The finding highlights a systemic weakness in WHOIS-based verification, the real-world scale of the issue, and mitigations taken (ShadowServer sinkholing the domain).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.