Bugs in Managed DNS Services Cloud Let Attackers Spy on DNS Traffic

Bugs in DNS Services
Share It On:

12th August 2021, Kathmandu

Cybersecurity researchers have disclosed an incipient class of susceptibilities impacting major DNS-as-a-Accommodation (DNSaaS) providers that could sanction assailers to exfiltrate sensitive information from corporate networks.

“We found a simple loophole that sanctioned us to intercept a portion of ecumenical dynamic DNS traffic going through managed DNS providers like Amazon and Google,” researchers Shir Tamari and Ami Luttwak from infrastructure security firm Wiz verbalized.

Calling it a “bottomless well of valuable intel,” the treasure trove of information contains internal and external IP addresses, computer denominations, employee names and locations, and details about organizations’ web domains. The findings were presented at the Ebony Hat USA 2021 security conference last week.

“The traffic that leaked to us from internal network traffic provides maleficent actors all the intel they would ever need to launch a prosperous attack,” the researchers integrated. “More than that, it gives anyone a bird’s ocular perceiver view on what’s transpiring inside companies and regimes. We liken this to having nation-state level spying capability – and getting it was as facile as registering a domain.”

The exploitation process hinges on registering a domain on Amazon’s Route53 DNS accommodation (or Google Cloud DNS) with the same name as the DNS name server — which provides the translation (aka resolution) of domain names and hostnames into their corresponding Internet Protocol (IP) addresses — resulting in a scenario that efficaciously breaks the isolation between tenants, thus sanctioning valuable information to be accessed.

In other words, by engendering an incipient domain on the Route53 platform inside AWS name server with the same moniker and pointing the hosted zone to their internal network, it causes the Dynamic DNS traffic from Route53 customers’ endpoints to be hijacked and sent directly to the rogue and same-denominated server, thus engendering a facile pathway into mapping corporate networks.

“The dynamic DNS traffic we wiretapped emanated from over 15,000 organizations, including Fortune 500 companies, 45 U.S. regime agencies, and 85 international regime agencies,” the researchers verbally expressed. “The data included a wealth of valuable intel like internal and external IP addresses, computer denominations, employee designations, and office locations.”

While Amazon and Google have since patched the issues, the Wiz research team has additionally relinquished an implementation to let companies test if their internal DDNS updates are being leaked to DNS providers or malevolent actors.


Share It On:

Recent Posts

Gaur’s Bajaj Mileage Champion: A Testament to Platina’s Fuel Efficiency

Gaur’s Bajaj Mileage Champion: A Testament to Platina’s Fuel Efficiency

Share It On:26th November 2024, Kathmandu The Bajaj Mileage Champion event was successfully concluded in Gaur, Rautahat, bringing together Bajaj

Melaka ICT Holdings Awarded (MICTH) Asia’s Most Promising SMEs for Smart City & Digital Transformation Leadership

Melaka ICT Holdings Awarded (MICTH) Asia’s Most Promising SMEs for

Share It On:Melaka ICT Holdings Sdn Bhd (MICTH), a key player in enhancing the digital and telecommunications landscape of Melaka,

Airple Revolutionizes Aircon Maintenance with New Website & App – Book, Track, and Manage Services Effortlessly

Airple Revolutionizes Aircon Maintenance with New Website & App –

Share It On:26th November 2024, Kathmandu On October 4, 2024, Airple, a leader in air conditioning installation, repair, and aircon

“Medical Elite: Regenerative Medicine” – Discover Stem Cell Therapy’s Potential on Discovery Channel

“Medical Elite: Regenerative Medicine” – Discover Stem Cell Therapy’s Potential

Share It On:26th November 2024, Kathmandu A riveting new documentary, Medical Elite: Regenerative Medicine, featuring Japan’s premier STEMCELL Co., Ltd,

Robert Walters Digital Salary Survey 2025: Insights on Hong Kong Job Market, In-Demand Roles, and Salary Trends

Robert Walters Digital Salary Survey 2025: Insights on Hong Kong

Share It On:26th November 2024, Kathmandu Hong Kong’s job market has experienced significant challenges over the past year, with layoffs

CNI Appoints Birendra Raj Pandey as Senior Vice President

CNI Appoints Birendra Raj Pandey as Senior Vice President

Share It On:26th November 2024, Kathmandu Birendra Raj Pandey has been appointed as the Senior Vice President of the Confederation