By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Over 1 Million Domains at Risk of ‘Sitting Ducks’ Domain Hijacking Technique
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Over 1 Million Domains at Risk of ‘Sitting Ducks’ Domain Hijacking Technique
Tech News

Over 1 Million Domains at Risk of ‘Sitting Ducks’ Domain Hijacking Technique

By Viral Trending Content 4 Min Read
Share
SHARE

Aug 01, 2024Ravie LakshmananVulnerability / Threat Intelligence

Domain Hijacking Technique

Over a million domains are susceptible to takeover by malicious actors by means of what has been called a Sitting Ducks attack.

The powerful attack vector, which exploits weaknesses in the domain name system (DNS), is being exploited by over a dozen Russian-nexus cybercriminal actors to stealthily hijack domains, a joint analysis published by Infoblox and Eclypsium has revealed.

“In a Sitting Ducks attack, the actor hijacks a currently registered domain at an authoritative DNS service or web hosting provider without accessing the true owner’s account at either the DNS provider or registrar,” the researchers said.

“Sitting Ducks is easier to perform, more likely to succeed, and harder to detect than other well-publicized domain hijacking attack vectors, such as dangling CNAMEs.”

Cybersecurity

Once a domain has been taken over by the threat actor, it could be used for all kinds of nefarious activities, including serving malware and conducting spams, while abusing the trust associated with the legitimate owner.

Details of the “pernicious” attack technique were first documented by The Hacker Blog in 2016, although it remains largely unknown and unresolved to date. More than 35,000 domains are estimated to have been hijacked since 2018.

“It is a mystery to us,” Dr. Renee Burton, vice president of threat intelligence at Infoblox, told The Hacker News. “We frequently receive questions from prospective clients, for example, about dangling CNAME attacks which are also a hijack of forgotten records, but we have never received a question about a Sitting Ducks hijack.”

At issue is the incorrect configuration at the domain registrar and the authoritative DNS provider, coupled with the fact that the nameserver is unable to respond authoritatively for a domain it’s listed to serve (i.e., lame delegation).

It also requires that the authoritative DNS provider is exploitable, permitting the attacker to claim ownership of the domain at the delegated authoritative DNS provider while not having access to the valid owner’s account at the domain registrar.

In such a scenario, should the authoritative DNS service for the domain expire, the threat actor could create an account with the provider and claim ownership of the domain, ultimately impersonating the brand behind the domain to distribute malware.

“There are many variations [of Sitting Ducks], including when a domain has been registered, delegated, but not configured at the provider,” Burton said.

The Sitting Ducks attack has been weaponized by different threat actors, with the stolen domains used to fuel multiple traffic distribution systems (TDSes) such as 404 TDS (aka Vacant Viper) and VexTrio Viper. It has also been leveraged to propagate bomb threat hoaxes and sextortion scams.

“Organizations should check the domains they own to see if any are lame and they should use DNS providers that have protection against Sitting Ducks,” Burton said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

File read flaw in Smart Slider plugin impacts 500K WordPress sites

TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials

Why cybersecurity needs to adapt in the age of AI

A School District Tried to Help Train Waymos to Stop for School Buses. It Didn’t Work

Google Pixel 10a Review: This is Fine

TAGGED: Cyber Security, Cybercrime, Cybersecurity, DNS Vulnerability, Domain Security, Eclypsium, hacking, Infoblox, Internet, Malware, Online Safety, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article Dead Cells’ Final Content Update Launches on August 19th
Next Article Wisconsin Judge Denies Request to Halt Order Allowing Ballots Be Emailed to Disabled Voters
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

File read flaw in Smart Slider plugin impacts 500K WordPress sites
Tech News
Closing the ‘deterrence gap’: German military association calls for war economy
Business
Chelsea problems on the pitch are clear in recent stats lists – opinion
Sports
Market trading guide: Buy ACME Solar and Dalmia Bharat on Monday for short-term gains up to 16%. Here’s why
Business
EU ministers weigh oil price cap and windfall tax to rein in soaring energy costs
World News
Ethereum builders propose ‘economic zone’ to tackle L2 fragmentation
Crypto
Crypto Donations Face Ban As Canada Steps Up Election Security Measures
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Chelsea problems on the pitch are clear in recent stats lists – opinion

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Chelsea problems on the pitch are clear in recent stats lists – opinion
March 29, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?