news.volyx.in

MarkMonitor left 60k domains for the taking (ian.sh)

420 points by agwa · 1851 days ago · 99 comments on HN

Article summary

MarkMonitor, a domain registrar, left over 60,000 domains vulnerable to takeover by pointing them to Amazon S3 without creating the corresponding buckets. This allowed attackers to claim the buckets and potentially serve malicious content or obtain TLS certificates for the domains. The issue was discovered by a security researcher who was able to claim over 800 root domains during the brief window of vulnerability. The incident highlights the importance of proper domain management and security measures.

Main themes

  • Domain security
  • Cloud security
  • TLS certificates
  • DNS management
  • Security vulnerabilities
  • Cloud services responsibility

What commenters say

  • The vulnerability was not just a minor issue, but a significant risk that could have been exploited for phishing or other malicious activities.
  • The blame for the vulnerability lies not just with MarkMonitor, but also with AWS for not requiring domain verification for S3 buckets.
  • The incident highlights the need for better security measures, such as DNSSEC and TLS certificate logging, to prevent similar vulnerabilities in the future.
  • The fact that an attacker could obtain a TLS certificate for a domain even after the vulnerability was fixed is a major concern.
  • The use of CloudFront with domain verification could have prevented this issue.
  • The vulnerability was not just a technical issue, but also a result of MarkMonitor's business model and priorities.
  • The incident shows that even large and reputable companies can make mistakes that put their customers' security at risk.
  • The importance of monitoring and responding to security issues in a timely manner is crucial to preventing similar incidents.