Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Anyone can take over virtually any domain on the net...

Re: Anyone can take over virtually any domain on the net...

From: Jon Lewis <jlewis_at_LEWIS.ORG>
Date: Thu, 13 Jan 2000 13:55:36 -0500

On Wed, 12 Jan 2000, Thomas Reinke wrote:

> At first I thought this had to be a joke. After thinking
> about it, I realized that its no joke at all, and in
> fact quite easy to do.
>
> Step 1: Send a spoofed email to Network solutions requesting
> a DNS change to your own DNS server.
>
> Step 2: Wait for a short while (the amount of time it normally
> takes Network Solutions to send out a confirmation
> email request)
>
> Step 3: Send a second spoofed email confirming the request.

Steps 2 and 3 aren't even necessary if you're good at forging email. Just
send a properly forged message claiming to be either the admin or
technical contact for the domain being modified, and NetSlo will make it
so. If you care about your domains, you should switch to using either
crypt-pw or PGP. I'd heard their PGP system was often broken, so I've
been using crypt-pw for nearly a year.

----------------------------------------------------------------------
 Jon Lewis *jlewis_at_lewis.org*| Spammers will be winnuked or
 System Administrator | nestea'd...whatever it takes
 Atlantic Net | to get the job done.
_________http://www.lewis.org/~jlewis/pgp for PGP public key__________
Received on Jan 15 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos