this post was submitted on 01 Aug 2024
2 points (100.0% liked)

Hacker News

2171 readers
2 users here now

A mirror of Hacker News' best submissions.

founded 1 year ago
MODERATORS
top 1 comments
sorted by: hot top controversial new old
[–] [email protected] 1 points 1 month ago

The researchers say Sitting Duck domains all possess three attributes that makes them vulnerable to takeover:

1) the domain uses or delegates authoritative DNS services to a different provider than the domain registrar;
2) the authoritative name server(s) for the domain does not have information about the Internet address the domain should point to;
3) the authoritative DNS provider is “exploitable,” i.e. an attacker can claim the domain at the provider and set up DNS records without access to the valid domain owner’s account at the domain registrar

List of vulnerable: https://github.com/indianajson/can-i-take-over-dns