The domain corp.com is up for sale. It poses a risk to hundreds of thousands of corporate computers running Windows.

The domain corp.com is up for sale. It poses a risk to hundreds of thousands of corporate computers running Windows.
Data leak scheme through Web Proxy Auto-Discovery (WPAD) in the case of name collision (in this case, the collision of an internal domain name with that of one of the new gTLDs, but the essence remains the same). Source: study by the University of Michigan, 2016

Mike O’Connor, one of the oldest domain name investors, is selling the most dangerous and controversial lot in his collection: the domain corp.com for $1.7 million. In 1994, O’Connor purchased many simple domain names, such as grill.com, place.com, pub.com, and others. Among them was corp.com, which Mike has held for 26 years. The investor is now 70 years old and has decided to monetize his long-term investments.

The whole problem is that corp.com is potentially dangerous for at least 375,000 corporate computers due to negligent Active Directory settings during the construction of corporate intranets in the early 2000s based on Windows Server 2000, when the internal root was simply specified as 'corp'. Until the early 2010s, this was not an issue, but with the increase in laptops in the business environment, more and more employees began taking their work computers outside the corporate network. The features of Active Directory implementation lead to the situation where, even without a direct user request to \//corp, several applications (for example, email) ping the familiar address by themselves. But in case of an external connection to the network in a hypothetical café around the corner, this results in a data and request stream flooding to corp.com.

Currently, O’Connor is very hopeful that Microsoft will buy the domain and, in the best traditions of Google, bury it somewhere dark and inaccessible for outsiders so that the problem of such a fundamental vulnerability in Windows networks will be resolved.

Active Directory and name collision

In Windows corporate networks, the Active Directory directory service is used. It allows administrators to use group policies to ensure uniformity in user workspace settings, deploy software across multiple computers via group policies, perform authorization, etc.

The Active Directory service is integrated with DNS and operates over TCP/IP. It uses the Web Proxy Auto-Discovery (WPAD) protocol for discovering nodes within the network and the function DNS name devolution (built into Windows DNS Client). This feature simplifies the search for other computers or servers without the need to specify the full domain name.

For example, if a company manages an internal network named internalnetwork.example.com, and an employee wants to access a shared drive named drive1, there is no need to enter drive1.internalnetwork.example.com in Explorer, just typing \drive1 is enough — the Windows DNS client will automatically complete the name.

In earlier versions of Active Directory — for example, in Windows 2000 Server — the default value for the second level of the corporate domain was set to corp. Many companies retained the default value for their internal domain. Worse, many began to build extensive networks on top of this erroneous configuration.

In the era of desktop computers, this did not pose significant security issues because no one took these computers outside the corporate network. But what happens when an employee working in a company with a network path corp in Active Directory takes a corporate laptop — and logs into the local Starbucks? This is where the Web Proxy Auto-Discovery (WPAD) protocol and DNS name devolution come into play.

The domain corp.com is up for sale. It poses a risk to hundreds of thousands of corporate computers running Windows.

It is highly likely that some services on the laptop will continue to reach for the internal domain corp, but will not find it, and instead, requests are resolved to the corp.com domain from the open internet.

Practically, this means that the owner of corp.com may passively intercept private requests from hundreds of thousands of computers that accidentally go beyond the corporate environment using the designation corp for their domain in Active Directory.

The domain corp.com is up for sale. It poses a risk to hundreds of thousands of corporate computers running Windows.
Leaking WPAD requests in U.S. traffic. From a study by the University of Michigan in 2016, source

Why the domain has not yet been sold

In 2014, ICANN specialists published a large study on DNS name collisions. The study was partially funded by the U.S. Department of Homeland Security because leaks of information from internal networks threaten not only commercial companies but also government organizations, including intelligence services, spy agencies, and military units.

Mike wanted to sell corp.com last year, but researcher Jeff Schmidt convinced him to postpone the sale based on the aforementioned report. The research also revealed that 375,000 computers attempt to connect to corp.com daily without the owners' knowledge. The requests included attempts to access corporate intranets, networks, or file resources.

As part of his own experiment, Schmidt, along with JAS Global, simulated the way files and requests are processed on corp.com, mimicking a Windows local network. In doing so, they effectively opened a portal to hell for any cybersecurity specialist:

It was awful. We stopped the experiment after 15 minutes and destroyed [all the collected] data. A well-known tester who advised JAS on the matter noted that the experiment was akin to a "rain of confidential information," and that he had never seen anything like it.

[We set up mail reception on corp.com] and about an hour later received over 12 million emails, after which we halted the experiment. While the overwhelming majority of the emails were automated, we discovered that some of them contained sensitive [security] information, so we destroyed the entire dataset without further analysis.

Schmidt believes that administrators worldwide have unknowingly been preparing the most dangerous botnet in history for decades. Hundreds of thousands of fully functional work computers globally are ready not only to become part of the botnet but also to provide confidential information about their owners and companies. All it takes to exploit it is to control corp.com. Any machine that was once connected to the corporate network, whose Active Directory was set up through //corp, becomes part of the botnet.

Microsoft 'ignored' the issue 25 years ago

If you think that MS was somehow unaware of the ongoing debacle surrounding corp.com, you're seriously mistaken. Mike was trolling Microsoft and Bill Gates personally back in 1997with a page like this, which beta users of FrontPage '97 encountered, where corp.com was listed as the default URL:

The domain corp.com is up for sale. It poses a risk to hundreds of thousands of corporate computers running Windows.

When Mike got completely fed up, corp.com started redirecting users to a sex shop website. In response, he received thousands of angry emails from users that he redirected through a copy of Bill Gates.

By the way, Mike also, out of curiosity, set up a mail server and received confidential emails at corp.com. He tried to solve these problems himself by contacting companies, but they simply didn't know how to fix the situation:

Immediately, I began receiving confidential emails, including draft corporate financial reports to the U.S. Securities and Exchange Commission, HR reports, and other alarming things. For a while, I attempted to correspond with corporations, but most of them didn't know what to do about it. So, eventually, I just turned off [the mail server].

From MS's side, no active measures were taken, and the company refuses to comment on the situation. Yes, Microsoft has released several updates to Active Directory over the years, which partially address the domain name collision issue, but there are several problems with them. The company has also released recommendations guides for setting up internal domain names, recommendations about owning second-level domains to avoid collisions, and other tutorials that are generally not read.

But the most important issues lie within the updates. First: to implement them, you need to completely take down the company's intranet. Second: some applications may start working slower, incorrectly, or may even stop working altogether after such updates. It is clear that most companies with established corporate networks will not take such risks in the short term. Moreover, many of them are not even aware of the full scale of the threat posed by redirecting everything to corp.com when taking the machine outside the internal network.

The height of irony is achieved when you view Schmidt's report on domain name collision research. According to his data, some requests to corp.com come from Microsoft’s intranet itself.

The domain corp.com is up for sale. It poses a risk to hundreds of thousands of corporate computers running Windows.

And what will happen next?

It seems that the solution to this situation is obvious and was described earlier in the article: let Microsoft buy Mike's domain and permanently ban it somewhere in a remote cupboard.

But it's not that simple. Microsoft had offered O'Connor to buy his toxic domain, harmful to companies worldwide, several years ago. The thing is, the giant offered only $20,000 to close such a gap in its own networks..

Now the domain is listed for $1.7 million. And even if Microsoft decides to buy it at the last moment — will they make it in time?

The domain corp.com is up for sale. It poses a risk to hundreds of thousands of corporate computers running Windows.

Only registered users can participate in the survey. Please log in, please.

What would you do if you were in O'Connor's position?

  • 59,6%Let Microsoft buy the domain for $1.7 million, or let someone else purchase it.

  • 3,4%I would sell it for $20,000; I don't want to go down in history as the person who let such a domain slip into the wrong hands.

  • 3,3%I would bury it myself and forever, if Microsoft can't make the right decision.

  • 21,2%I would deliberately sell the domain to hackers with the condition that they destroy Microsoft's reputation in the corporate world. They've known about the problem since 1997!

  • 12,4%I would raise a botnet and mail server myself and start shaping the world's destiny.

840 users voted. 131 users abstained.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster