Black Hat 2021: DNS loophole makes nation-state level spying as easy as registering a domain
ID: 737c9e9e-bc4e-59f1-b19e-9024d8a6dbdf
STIX ID: report--737c9e9e-bc4e-59f1-b19e-9024d8a6dbdf
Feed Name: Wiz Blog
Researchers discovered and demonstrated a vulnerability in managed DNS services (notably AWS Route53) where registering specially named domains that match shared name servers caused Windows dynamic DNS update traffic from millions of endpoints across roughly 15,000 organizations — including Fortune 500 companies and government agencies — to be routed to attacker-controlled servers, leaking internal IPs, hostnames, employee names and office locations; AWS and Google have mitigated the issue in part, but other providers may still be vulnerable and Microsoft characterizes the behavior as a misconfiguration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
