Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Many Hijacked Subdomains #740

Open
3 tasks done
TPS opened this issue Feb 7, 2024 · 6 comments
Open
3 tasks done

Many Hijacked Subdomains #740

TPS opened this issue Feb 7, 2024 · 6 comments

Comments

@TPS
Copy link

TPS commented Feb 7, 2024

Prerequisites

  • I checked the documentation and found no answer;
  • I checked to make sure that this issue has not already been filed;
  • This is not an ad/bug report.

Problem description

N.B.: Reposting AdguardTeam/AdGuardSDNSFilter#572 from 3ya (!) for increased visibility.

According to another in a long-term series of articles, various subdomains of a number of Microsoft-owned domains have been hijacked.

Seizing subdomains. How I took over Microsoft subdomains and how to perform such attackshttps://github.com/EdOverflow/can-i-take-over-xyz has quite a lot of details re: & especially combatting this. Some of the problem involves CNAME hacking.

Hard lists of such seem difficult to find, but https://www.google.com/search?q=hijacked%20microsoft%20domains seems to give more pieces to the puzzle. (Perhaps whenever DNSSEC is widely deployed this'll no longer be an issue.)

Proposed solution

🤷🏾‍♂️ I'm hoping you experts can come up w/ a good solution.

Additional information

Thanks to @DandelionSprout for reminding me to followup on this.

@Alex-302
Copy link
Member

Alex-302 commented Feb 7, 2024

Do you have examples?

@TPS
Copy link
Author

TPS commented Feb 8, 2024

The "Proofs" @ https://github.com/EdOverflow/can-i-take-over-xyz/issues are the best I can point to. As those issues state, it's quite difficult to list or mitigate such domains.

@Alex-302
Copy link
Member

Alex-302 commented Feb 9, 2024

It describes a domain hijacking scenario. How should a DNS server prevent this from happening?

@TPS
Copy link
Author

TPS commented Feb 9, 2024

Prevent, no. Detect & block such hijacked domains from access, maybe?

@Alex-302
Copy link
Member

Alex-302 commented Feb 9, 2024

In any case, it's the wrong repository.
Better write here https://github.com/AdguardTeam/AdGuardDNS/issues

@Alex-302 Alex-302 closed this as completed Feb 9, 2024
@TPS
Copy link
Author

TPS commented Feb 10, 2024

@Alex-302 Would you mind having this issue moved there, please?

@Alex-302 Alex-302 transferred this issue from AdguardTeam/AdguardFilters Feb 12, 2024
@Alex-302 Alex-302 reopened this Feb 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants