4.9 • 696 Ratings
🗓️ 10 July 2017
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, July 11th, 2017 edition of the Sands and Storm Center's Stormcast. |
0:08.4 | My name is Johannes Ulrich, and I'm recording from Stockholm, Germany. |
0:13.0 | The dot-io top-level domain is often used for some of the more tech-savvy kind of webpages, |
0:20.3 | but nevertheless, apparently a few days ago, |
0:24.7 | the entire dot-io domain was ripe for a takeover given that the registrar responsible for dotio |
0:33.8 | did not renew some domain names that are used for name servers for this top level domain. |
0:42.7 | Matthew Prynd, who has made a name for himself in finding these kind of issues, realized that |
0:50.0 | NS-A1.I.O, NS-A-2 through a3.io, were available to be registered, and these domains are used for. |
1:02.6 | Dot-I.O. Name servers. So he went ahead and actually verified that his systems did receive queries for dotio domains. |
1:13.6 | He did not answer them, so all he did essentially was verify whether or not the vulnerability was real. |
1:21.6 | Kind of to add to this problem, he tried to notify the dotio registrar, but turned out that the address, |
1:30.9 | the contact email address that was published within Who is, was not valid. |
1:37.2 | Now based on his write-up, it looks like it took about a day for the dotio folks to realize |
1:44.0 | what happened and his registrations of course |
1:47.2 | were promptly revoked by his registrar. They essentially just told him there was an error |
1:54.3 | that these domains were available for registrations and they have it fixed now. As I mentioned, this isn't the first time that Matthew has run into this issue with major domains. |
2:06.6 | In the past, he has found a couple country level domains such that were affected by this. |
2:12.6 | I think dot I.O is probably the largest such domain that he has had this issue with for now. |
2:20.3 | Of course, this happens very often with corporate domains, so make sure you have control |
2:28.3 | over your name server records and the domains associated with your name servers. |
2:35.0 | And Malwarebytes came out with its quarterly Malware report. |
2:39.2 | Now, I don't usually cover every single report that the vendor comes up with. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.