For Just $20, Researchers Seize Part of Internet Infrastructure
ID: 5bc13b2e-d1c3-50ff-bb37-8125c65edf01
STIX ID: report--5bc13b2e-d1c3-50ff-bb37-8125c65edf01
Feed Name: Dark Reading
Security researchers registered an expired WHOIS hostname previously used by the .mobi TLD and unexpectedly received millions of queries from tens of thousands of systems (including registrars, government mail servers, and security services). Their experiment showed that some Certificate Authorities rely on WHOIS data for domain control validation, allowing an attacker controlling an outdated WHOIS host to supply arbitrary administrative contact information and obtain fraudulent TLS/SSL certificates or perform passive traffic analysis. The finding highlights a systemic weakness in WHOIS-based verification, the real-world scale of the issue, and mitigations taken (ShadowServer sinkholing the domain).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
