Skip to content

Nachrichtenagentur Radio Utopie

Nachrichten weltweit direkt von der Quelle. News worldwide directly from the source. Deutsch, English. Democracy first!
  • Start
  • Nachrichten / News
  • Ticker
  • Archiv
  • Status
  • … the FAQ?!
  • Support Radio Utopie
  • Hauptseite / Main Site
30.06.2022 - 09:45 [ Wiz.io ]

Black Hat 2021: DNS loophole makes nation-state level spying as easy as registering a domain

(Aug 4, 2021)

We have no way of knowing whether the loophole has already been exploited: Anyone could have collected data undetected for over a decade.

We do know this is still an active threat vector – while two major DNS providers (Amazon and Google) have fixed the issue, others may still be vulnerable. As a result, millions of devices are potentially vulnerable.

(…)

After analyzing it, we learned it was dynamic DNS traffic from Windows machines that were querying the hijacked name server about itself. Dynamic DNS keeps DNS records automatically up to date when an IP address changes. It’s traditionally been used in large networks that host internal services, and use their own internal servers. In short, the traffic we received contained sensitive information that was never supposed to leave an organizations internal network.

The dynamic DNS traffic we “wiretapped” came from over 15,000 organizations, including Fortune 500 companies, 45 U.S. government agencies, and 85 international government agencies. The data included a wealth of valuable intel like internal and external IP addresses, computer names, employee names and office locations.

Nachrichten Kategorie: Kontrollmechanismen / control mechanisms. Nachrichten Schlagwörter: (internet service) providers (ISPs), (Massen-)Identifikation / Durchleuchtung / Profile / (mass-)identification / screening / profiling, Amazon Inc. / Amazon Web Services (monopolies), Blitzdings-Opfer / Recht auf Vergessen / neuralyzer victims / little reminders, Daten – Beschaffung / Raub / Speicherung / Banken / Analyse / Handel / Netzwerke / data – procurement / theft / storage / banks / analysis / trade / networks, Domain Name System (DNS) / Synonym „Metadaten“ / „metadata“ / invented in 1983 by Paul Mockapetris (later IETF) for Pentagon ARPANET, elektronische Kolonien / Datenabbaugebiete / elektronischer Kolonialismus / Feudalismus / electronic colonies / data mining zones / electronic colonialism / feudalism, elektronische Spionage / Kriegführung / Ortung / Zentren / Programme / Industrien / electronic espionage / warfare / locating / centers / industries / programs / „scanning“ / „signal intelligence“, Hacks (real oder fiktiv) / (real or fictitious), Informationen / Zugang / Kontrolle / Operationen / Kriegführung / information / access / clearances / control / operations / warfare, Internet Infrastruktur / Server / Kontrolle / Filter / Zensur / Sperren / Abschaltung / internet infrastructure / server / control / filter / blocking / censorship / shutdowns, Monopole / Kartelle / digitale Monopole und „soziale Medien“ / monopolies / cartels / digital monopolies and „social media“ / Silicon Valley, mosquitos / bitf*cker Inc. / spies / international spy complex / secret police / state / non-state / contractors / corporations / data brokers, Staat (Machthaber / Regime / Regierungen / Struktur / Exekutive) / state (rulers / regimes / governments / structure / executive branch), Technik / Techniker / Programmierer / technicians / technics / programmers, time / money / data / democracy / peace / life robbers on steroids, User Datagram Protocol (UDP), Verzögerungen / Hinhaltetaktik / Verschleppung / Schweigen / Nichtstun / bürokratischer Widerstand / delay / stalling / inaction / silence / retardation / bureaucratic resistance / tactics, Windows (operating system), World Wide Web on the internet (screened plebs-class internet of today / invented by Tim Berners-Lee at CERN and gifted to the world in 1993), YouTube / Google LLC / Alphabet Inc. (monopolies), zombie parliaments / Zombie-Parlamente, und Zusammenarbeit / Kooperationen / Kollaborationen / cooperations / collaborations.

Post navigation

← 3 things I wish from @github: – faster website (also in the actions tab) – nixos support for actions as first level citizen – TLS 1.3 in github actions Verschlüsseltes DNS (DoT) mit der FritzBox nutzen →

status reports:

  • technical updates 3. Mai 2026
  • Note: this News Agency stands at over 250.000 news entries 28. April 2026

search the archive dating back to 2010:

Impressum
Datenschutzerklärung

our news feed:

RSS Feed / Atom Feed

^

Guess what - we are using cookies.
Mehr Informationen