Skip to main navigation Skip to search Skip to main content

TheWolf of Name Street: Hijacking domains through their nameservers

  • Thomas Vissers
  • , Timothy Barron
  • , Tom Van Goethem
  • , Wouter Joosen
  • , Nick Nikiforakis
  • Interuniversitair Micro-Elektronica Centrum
  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

40 Scopus citations

Abstract

The functionality and security of all domain names are contingent upon their nameservers. When these nameservers, or requests to them, are compromised, all domains that rely on them are a.ected. In this paper, we study the exploitation of con.guration issues (typosquatting and outdated WHOIS records) and hardware errors (bitsquatting) to seize control over nameservers' requests to hijack domains.We perform a large-scale analysis of 10,000 popular nameserver domains, in which we map out existing abuse and vulnerable entities. We con.rm the capabilities of these attacks through realworld measurements. Overall, we. nd that over 12,000 domains are susceptible to near-immediate compromise, while 52.8M domains are being targeted by nameserver bitsquatters that respond with rogue IP addresses. Additionally, we determine that 1.28M domains are at risk of a denial-of-service attack by relying on an outdated nameserver.

Original languageEnglish
Title of host publicationCCS 2017 - Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery
Pages957-970
Number of pages14
ISBN (Electronic)9781450349468
DOIs
StatePublished - Oct 30 2017
Event24th ACM SIGSAC Conference on Computer and Communications Security, CCS 2017 - Dallas, United States
Duration: Oct 30 2017Nov 3 2017

Publication series

NameProceedings of the ACM Conference on Computer and Communications Security
ISSN (Print)1543-7221

Conference

Conference24th ACM SIGSAC Conference on Computer and Communications Security, CCS 2017
Country/TerritoryUnited States
CityDallas
Period10/30/1711/3/17

Keywords

  • Bitsquatting
  • DNS
  • Nameservers
  • Typosquatting

Fingerprint

Dive into the research topics of 'TheWolf of Name Street: Hijacking domains through their nameservers'. Together they form a unique fingerprint.

Cite this