pwshub.com

Russia takes aim at Sitting Ducks domains, bags 30,000+

Dozens of Russia-affiliated criminals are right now trying to wrest control of web domains by exploiting weak DNS services.

The crooks have already hijacked an estimated 30,000 domains since 2019, by using a technique dubbed Sitting Ducks by cybersecurity outfits Infoblox and Eclypsium.

The flaw at the heart of the matter has been known since at least 2016, when security researcher Matt Bryant detailed the takeover of 120,000 domains using a DNS vulnerability at major cloud providers such as AWS, Google, and Digital Ocean. It resurfaced in 2019 at internet service provider GoDaddy, leading to bomb threats and sextortion attempts.

The fact that Sitting Ducks remains a viable avenue for seizing domains is a testament to the difficulty of addressing vulnerabilities that arise from shoddy business processes, rather than coding bugs. The technique is difficult to detect or distinguish from credential theft, and is very damaging for those shot down by it.

"Eight years after it was first published, the attack vector is largely unknown and unresolved," said Infoblox in a write-up lamenting the ease of domain hijacking.

"Sitting Ducks is easier to perform, more likely to succeed, and harder to detect than other well-publicized domain hijacking attack vectors, such as dangling CNAMEs. At the same time, Sitting Ducks is being broadly used to exploit users around the globe. Our analysis showed that the use of Sitting Ducks has grown unabated over several years and unrecognized in the security industry."

Conducting a successful Sitting Ducks attack requires four conditions, according to an Eclypsium advisory:

This gap in administrative controls – allowing criminals to add or alter domain records without validating the identity of the requester – turns out to be rather common. According to a paper [PDF] published in 2020, about 14 percent of 49 million domains evaluated were affected by lame delegations of some kinds.

The security crew at Infoblox and Eclypsium say they discovered the latest round of attacks in June and have been coordinating with police and national CERTs to deal with the damage since then.

  • Just one bad packet can bring down a vulnerable DNS server thanks to DNSSEC
  • Attacks abuse Microsoft DHCP to spoof DNS records and steal secrets
  • DigiCert gives unlucky folks 24 hours to replace doomed certificates after code blunder
  • Infoseccers claim Squarespace migration linked to DNS hijackings at Web3 firms

The Sitting Ducks vulnerability affects not only the owners of domains that get taken over but those interacting with those sites online. Hijacked domains, Infoblox warns, have been used for phishing, scams, spam, porn distribution, and command-and-control servers for attacks like Cobalt Strike.

Infoblox and Eclypsium argue that DNS misconfigurations can be mitigated with some effort from domain owners, domain registrars, and DNS providers. And they also urge government organizations, regulators, and standards bodies to explore long-term solutions that minimize the DNS attack surface.

"Without cooperation and active effort, Sitting Ducks attacks will continue to rise," Infoblox argues. "This attack already plays a part in cybercrime targeting dozens of countries around the world, costing consumers an untold amount of money and loss of privacy." ®

Source: theregister.com

Related stories
2 weeks ago - International efforts to rein in online surveillance tools are being systematically skirted, researchers say.
1 month ago - The AI company found its tools used for websites and social media posts trying to increase polarization in the U.S. election. The posts did not gain widespread traction, OpenAI said.
1 month ago - The takedown may be small but any ransomware gang sent to the shops is good news in our book The Dispossessor ransomware group is the latest to enter the cybercrime graveyard with the Feds proudly laying claim to the takedown.…
1 month ago - A new Google update will also push explicit fake content further down in search results.
1 week ago - YouTube “terminated” Tenet Media and other channels run by Lauren Chen, who was accused by the DOJ Wednesday of using Russian government money to pay right-wing influencers.
Other stories
2 minutes ago - After California passed laws cracking down on AI-generated deepfakes of election-related content, a popular conservative influencer promptly sued,...
26 minutes ago - Act fast to grab this high-performing mesh router for less than $500, keeping you connected while saving some cash too.
26 minutes ago - If the old-school PlayStation is dear to your heart, you can soon relive those totally sweet 1990s memories. Sony is releasing a series of products...
26 minutes ago - If you've got an old phone to part with, T-Mobile is offering both new and existing customers the brand-new Apple iPhone 16 Pro for free with this trade-in deal.
26 minutes ago - Who doesn't want the best for their beloved pooch? Grab some of these tasty treats to make your dog feel special.