TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability

117 点作者 mandatory超过 8 年前

4 条评论

tyingq超过 8 年前
This is an interesting article, but it keeps using the phrase &quot;taking over domains&quot;, which isn&#x27;t really what&#x27;s happening.<p>It&#x27;s really &quot;squatting on the domain ONLY in the space of a specific provider&quot;.<p>And, this isn&#x27;t new. For example, you can do this on most shared hosting plans...add a domain, and they don&#x27;t ask for any kind of verification.<p>The only thing this seems to accomplish is lock you, the legitimate domain owner, from using a specific service until you open a support ticket and hash it out with them. You still control the domain, so it&#x27;s fairly easy to prove control&#x2F;ownership.<p>That&#x27;s not good, of course, but it&#x27;s not the same thing as &quot;taking over a domain&quot;. Your WHOIS records still point at your DNS servers, which still return the correct records.<p>Edit: It could, I suppose, be used to take over a mostly &quot;abandoned&quot; domain, where the WHOIS records still point at a provider with this issue, but the underlying account is gone. Again, an issue, but if the domain is abandoned, it&#x27;s not the same thing as taking over arbitrary, in-use domains.
评论 #13119170 未加载
评论 #13119117 未加载
评论 #13119417 未加载
评论 #13120125 未加载
评论 #13118946 未加载
评论 #13119039 未加载
评论 #13118952 未加载
tedunangst超过 8 年前
This should be fairly obvious to anyone who has ever moved DNS from one provider to another. Or even from one account to another. Anybody can stand up a server that&#x27;s &quot;authoritative&quot; for a domain. It doesn&#x27;t matter until the registrar points the domain&#x27;s NS there. In fact, how else would you move from your registrar&#x27;s nameserver to something like route53? Nobody is going to point their NS at an empty zone and populate it after the fact.
评论 #13119394 未加载
strictnein超过 8 年前
&gt; &quot;Rackspace (~44K Domains Affected, Won’t Fix)&quot;<p>Remember when Rackspace was a premium host that you happily paid more money to because they handled things the right way?
homero超过 8 年前
So what did Google do