SlideShare a Scribd company logo
DNS Hijacking
Michael Smith, CISSP-ISSEP
APJ Security CTO
mismith@akamai.com
©2016 AKAMAI | FASTER FORWARDTM
DNS Hierarchy
Root/”The Dot”
.sg.
.com.sg.
.foo.com.sg.
www.foo.com.sg.
DNS
Resolver
Registrar
©2016 AKAMAI | FASTER FORWARDTM
Whois akamai.com
$ whois akamai.com | grep ’^Name Server'
Name Server: A1-66.AKAM.NET
Name Server: A11-66.AKAM.NET
Name Server: A13-66.AKAM.NET
Name Server: A28-66.AKAM.NET
Name Server: A16-66.AKAM.NET
Name Server: A7-66.AKAM.NET
……
These are
all glue
records
©2016 AKAMAI | FASTER FORWARDTM
Glue Record TTL
$dig +trace www.akamai.com
. 56955 IN NS f.root-servers.net.
com. 172800 IN NS e.gtld-servers.net.
akamai.com. 172800 IN NS a5-66.akam.net.
©2016 AKAMAI | FASTER FORWARDTM
Case Study 1: Oops, Premature Expiration
• Marketing and adware company
• Catch expired domains and kite them
• Registrar expires domains early
• ~1500 Domains hijacked
• Chaos ensues
• Multiple mitigation streams
©2016 AKAMAI | FASTER FORWARDTM
Basic CDN and DNS Operation
©2016 AKAMAI | FASTER FORWARDTM
The Magic of DNS CNAMEs and TTLs
$ dig www.akamai.com
;; ANSWER SECTION:
www.akamai.com. 20 IN CNAME wwwsecure2.akamai.com.edgekey.net.
wwwsecure2.akamai.com.edgekey.net. 1576 IN CNAME e8921.dscx.akamaiedge.net.
e8921.dscx.akamaiedge.net. 6 IN A 23.74.224.166
©2016 AKAMAI | FASTER FORWARDTM
Case 2: SEA Brings us “Hacksgiving”
©2016 AKAMAI | FASTER FORWARDTM
Case 3: Lizard Squad
©2016 AKAMAI | FASTER FORWARDTM
Whois => Spear Phishing
$ whois akamai.com | grep @
Registrar Abuse Contact Email: domainabuse@tucows.com
Reseller: hostmaster@akamai.com
Registrant Email: hostmaster-billing@akamai.com
Admin Email: hostmaster-billing@akamai.com
Tech Email: hostmaster-billing@akamai.com
Akamai Technologies, hostmaster@akamai.com
©2016 AKAMAI | FASTER FORWARDTM
The Phish
Akamai Technologies
Your domain, akamai.com is due to expire. Please <a
href=www.wecaptureyourlogin.net>login to renew this domain</a>
Thank you
--Your Registrar
©2016 AKAMAI | FASTER FORWARDTM
Prevention
• Lock your domains, lock your domains, lock your domains
• Whois privacy
• site:github.com dns monitoring
• 2FA on registrars and other providers
• Anti-phishing training for IT admins
• Ready to disable third-party content
• 2FA on email, VPN
©2016 AKAMAI | FASTER FORWARDTM
Domain Hijacking Countermeasures
DNS Locking – Two Levels
ClientUpdateProhibited
ClientTransferProhibited
ClientDeleteProhibited
ServerUpdateProhibited
ServerTransferProhibited
ServerDeleteProhibited
©2016 AKAMAI | FASTER FORWARDTM
Akamai-Specific
• Forward to Origin SSL
• Alerts for minimum traffic level
• Edge server DNS purge
• Content purging
• AkaRegistrar
• Portal 2-factor/SAML/ACL access control
DNS hijacking - null Singapore

More Related Content

PDF
Three things that rowhammer taught me by Halvar Flake
PPTX
PPTX
Humla workshop on Android Security Testing - null Singapore
PPT
iOS Application Pentesting
PDF
Null Singapore - Can We secure the IoT - Chadi Hantouche
PPTX
Identifying XSS Vulnerabilities
PPTX
News Bytes - December 2015
Three things that rowhammer taught me by Halvar Flake
Humla workshop on Android Security Testing - null Singapore
iOS Application Pentesting
Null Singapore - Can We secure the IoT - Chadi Hantouche
Identifying XSS Vulnerabilities
News Bytes - December 2015

Viewers also liked (10)

PPTX
PDF
Stegano Secrets - Python
PPTX
INTELLIGENT FACE RECOGNITION TECHNIQUES
PDF
Managing third party libraries
PPT
Firewall Penetration Testing
PDF
Pentesting RESTful WebServices v1.0
PPTX
Pentesting ReST API
PPTX
Getting Started with API Security Testing
Stegano Secrets - Python
INTELLIGENT FACE RECOGNITION TECHNIQUES
Managing third party libraries
Firewall Penetration Testing
Pentesting RESTful WebServices v1.0
Pentesting ReST API
Getting Started with API Security Testing
Ad

Similar to DNS hijacking - null Singapore (20)

PDF
Edge 2016 acme - lets encrypt your origin
PPTX
Velocity 2013: Resolution For A Faster Site
PDF
The CAA-Record for increased encryption security
PDF
New DNS Traffic Analysis Techniques to Identify Global Internet Threats
PDF
Edge 2016 barbarians at the gateway
PPTX
Resolution for a Faster Site
PDF
Fighting Abuse with DNS
PDF
The DNSSEC KSK of the root rolls
PDF
DNS как линия защиты/DNS as a Defense Vector
PDF
Edge 2016 h2 in the real world
PDF
Real world experiences with HTTP/2 (Michael Gooding, Javier Garza from Akamai)
PPTX
Self-Serviceability- Taking it Up a Notch!
PDF
Anycast Authoritative DNS Service of MMIX.pdf
PDF
Anycast Authoritative DNS Service of MMIX.pdf
PDF
Anycast Authoritative DNS Service of MMIX.pdf
PPTX
PyCon Russia 2014 - Auto Scale in the Cloud
PDF
DNSSEC Tutorial, by Champika Wijayatunga [APNIC 38]
PDF
ウェブサイト最適化101 - 正しく測ろうあなたのサイト -
PDF
Query-name Minimization and Authoritative Server Behavior
Edge 2016 acme - lets encrypt your origin
Velocity 2013: Resolution For A Faster Site
The CAA-Record for increased encryption security
New DNS Traffic Analysis Techniques to Identify Global Internet Threats
Edge 2016 barbarians at the gateway
Resolution for a Faster Site
Fighting Abuse with DNS
The DNSSEC KSK of the root rolls
DNS как линия защиты/DNS as a Defense Vector
Edge 2016 h2 in the real world
Real world experiences with HTTP/2 (Michael Gooding, Javier Garza from Akamai)
Self-Serviceability- Taking it Up a Notch!
Anycast Authoritative DNS Service of MMIX.pdf
Anycast Authoritative DNS Service of MMIX.pdf
Anycast Authoritative DNS Service of MMIX.pdf
PyCon Russia 2014 - Auto Scale in the Cloud
DNSSEC Tutorial, by Champika Wijayatunga [APNIC 38]
ウェブサイト最適化101 - 正しく測ろうあなたのサイト -
Query-name Minimization and Authoritative Server Behavior
Ad

More from n|u - The Open Security Community (20)

PDF
Hardware security testing 101 (Null - Delhi Chapter)
PPTX
SSRF exploit the trust relationship
PDF
PDF
Api security-testing
PDF
Introduction to TLS 1.3
PDF
Gibson 101 -quick_introduction_to_hacking_mainframes_in_2020_null_infosec_gir...
PDF
Talking About SSRF,CRLF
PPTX
Building active directory lab for red teaming
PPTX
Owning a company through their logs
PPTX
Introduction to shodan
PDF
Detecting persistence in windows
PPTX
Frida - Objection Tool Usage
PDF
OSQuery - Monitoring System Process
PDF
DevSecOps Jenkins Pipeline -Security
PDF
Extensible markup language attacks
PPTX
PDF
Hardware security testing 101 (Null - Delhi Chapter)
SSRF exploit the trust relationship
Api security-testing
Introduction to TLS 1.3
Gibson 101 -quick_introduction_to_hacking_mainframes_in_2020_null_infosec_gir...
Talking About SSRF,CRLF
Building active directory lab for red teaming
Owning a company through their logs
Introduction to shodan
Detecting persistence in windows
Frida - Objection Tool Usage
OSQuery - Monitoring System Process
DevSecOps Jenkins Pipeline -Security
Extensible markup language attacks

Recently uploaded (20)

PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
project resource management chapter-09.pdf
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PDF
WOOl fibre morphology and structure.pdf for textiles
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPTX
Tartificialntelligence_presentation.pptx
PDF
Mushroom cultivation and it's methods.pdf
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
A novel scalable deep ensemble learning framework for big data classification...
PPTX
OMC Textile Division Presentation 2021.pptx
PDF
Hybrid model detection and classification of lung cancer
PDF
Zenith AI: Advanced Artificial Intelligence
PPTX
A Presentation on Artificial Intelligence
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
Enhancing emotion recognition model for a student engagement use case through...
Accuracy of neural networks in brain wave diagnosis of schizophrenia
project resource management chapter-09.pdf
Assigned Numbers - 2025 - Bluetooth® Document
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
WOOl fibre morphology and structure.pdf for textiles
cloud_computing_Infrastucture_as_cloud_p
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Tartificialntelligence_presentation.pptx
Mushroom cultivation and it's methods.pdf
Group 1 Presentation -Planning and Decision Making .pptx
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
A novel scalable deep ensemble learning framework for big data classification...
OMC Textile Division Presentation 2021.pptx
Hybrid model detection and classification of lung cancer
Zenith AI: Advanced Artificial Intelligence
A Presentation on Artificial Intelligence

DNS hijacking - null Singapore

  • 1. DNS Hijacking Michael Smith, CISSP-ISSEP APJ Security CTO mismith@akamai.com
  • 2. ©2016 AKAMAI | FASTER FORWARDTM DNS Hierarchy Root/”The Dot” .sg. .com.sg. .foo.com.sg. www.foo.com.sg. DNS Resolver Registrar
  • 3. ©2016 AKAMAI | FASTER FORWARDTM Whois akamai.com $ whois akamai.com | grep ’^Name Server' Name Server: A1-66.AKAM.NET Name Server: A11-66.AKAM.NET Name Server: A13-66.AKAM.NET Name Server: A28-66.AKAM.NET Name Server: A16-66.AKAM.NET Name Server: A7-66.AKAM.NET …… These are all glue records
  • 4. ©2016 AKAMAI | FASTER FORWARDTM Glue Record TTL $dig +trace www.akamai.com . 56955 IN NS f.root-servers.net. com. 172800 IN NS e.gtld-servers.net. akamai.com. 172800 IN NS a5-66.akam.net.
  • 5. ©2016 AKAMAI | FASTER FORWARDTM Case Study 1: Oops, Premature Expiration • Marketing and adware company • Catch expired domains and kite them • Registrar expires domains early • ~1500 Domains hijacked • Chaos ensues • Multiple mitigation streams
  • 6. ©2016 AKAMAI | FASTER FORWARDTM Basic CDN and DNS Operation
  • 7. ©2016 AKAMAI | FASTER FORWARDTM The Magic of DNS CNAMEs and TTLs $ dig www.akamai.com ;; ANSWER SECTION: www.akamai.com. 20 IN CNAME wwwsecure2.akamai.com.edgekey.net. wwwsecure2.akamai.com.edgekey.net. 1576 IN CNAME e8921.dscx.akamaiedge.net. e8921.dscx.akamaiedge.net. 6 IN A 23.74.224.166
  • 8. ©2016 AKAMAI | FASTER FORWARDTM Case 2: SEA Brings us “Hacksgiving”
  • 9. ©2016 AKAMAI | FASTER FORWARDTM Case 3: Lizard Squad
  • 10. ©2016 AKAMAI | FASTER FORWARDTM Whois => Spear Phishing $ whois akamai.com | grep @ Registrar Abuse Contact Email: domainabuse@tucows.com Reseller: hostmaster@akamai.com Registrant Email: hostmaster-billing@akamai.com Admin Email: hostmaster-billing@akamai.com Tech Email: hostmaster-billing@akamai.com Akamai Technologies, hostmaster@akamai.com
  • 11. ©2016 AKAMAI | FASTER FORWARDTM The Phish Akamai Technologies Your domain, akamai.com is due to expire. Please <a href=www.wecaptureyourlogin.net>login to renew this domain</a> Thank you --Your Registrar
  • 12. ©2016 AKAMAI | FASTER FORWARDTM Prevention • Lock your domains, lock your domains, lock your domains • Whois privacy • site:github.com dns monitoring • 2FA on registrars and other providers • Anti-phishing training for IT admins • Ready to disable third-party content • 2FA on email, VPN
  • 13. ©2016 AKAMAI | FASTER FORWARDTM Domain Hijacking Countermeasures DNS Locking – Two Levels ClientUpdateProhibited ClientTransferProhibited ClientDeleteProhibited ServerUpdateProhibited ServerTransferProhibited ServerDeleteProhibited
  • 14. ©2016 AKAMAI | FASTER FORWARDTM Akamai-Specific • Forward to Origin SSL • Alerts for minimum traffic level • Edge server DNS purge • Content purging • AkaRegistrar • Portal 2-factor/SAML/ACL access control