TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

A DNS hijacking experience and the status of ccTLDs in Latin America

2 点作者 matiasb大约 11 年前
An Iranian cracker broke into the paraguayan ccTLD registrar[0] (exploiting a security hole reported by me 6 years ago) and managed to point Google.com.py to its own nameserver. The DNS records were pointed to the same IP, serving a smiley face through HTTP[1].<p>SENATICS[2], the government ICT department, published a press release indicating that no attack was made and that everything was just a misunderstanding.<p>Later the attacker decided to leak private data from the server[3] (a complete database dump, containing over ~20000 items, including document number, e-mail, phone number, etc). This served as a pressure for government and they finally took the blame for the incident.<p>At the same time, the argentinian registrar[4] announced that they will start charging for the domains around 25 U$ per year (currently it’s still free, and it’s possible to register a domain by using your identity card). Just to give you an idea, in Paraguay we’re paying 45 U$ for a .py domain name, per year. And we’re currently dicussing if it’s worth paying that amount for a service with such big security issues (obviously this isn’t the first one, among several other irregularities).<p>[0] http:&#x2F;&#x2F;www.nic.py&#x2F;<p>[1] http:&#x2F;&#x2F;www.abc.com.py&#x2F;nacionales&#x2F;falla-seguridad-de-nicpy-1218433.html<p>[2] http:&#x2F;&#x2F;www.senatics.gov.py&#x2F;<p>[3] http:&#x2F;&#x2F;ha.cker.ir&#x2F;2014&#x2F;02&#x2F;www-nic-py-py-registrar-rce-vulnerablity&#x2F;, http:&#x2F;&#x2F;cker.ir&#x2F;leak&#x2F;nic-py&#x2F;<p>[4] https:&#x2F;&#x2F;nic.ar&#x2F;

暂无评论

暂无评论