Google announced an incident in which attackers were able to obtain TLS certificates for specific Google domains (for example, google.as), online services, and major companies in the zones ".gh", ".sl", and ".as". The attack occurred through the compromise of registrars of national top-level domains — ".gh" (Ghana), ".sl" (Sierra Leone), and ".as" (American Samoa), allowing them to replace the DNS servers for domains in these zones and redirect requests to the attackers’ servers. By redirecting traffic, the attackers were able to confirm ownership of the domains and obtain TLS certificates, as after changing the data in DNS, validation requests from certificate authorities were sent not to the real, but to the spoofed hosts and processed there.
Unauthorized certificate issuance was discovered as a result of analyzing Certificate Transparency logs, in which certificate authorities reflect all issued and revoked certificates. Google blocked the illegitimate certificates obtained during the attack using the CRLSets mechanism in the Chrome browser and also succeeded in revoking these certificates from the certificate authorities. It is not yet revealed for which specific domains the fraudulent certificates were issued and which companies were affected by the attack.
To minimize risks of similar incidents recurring, domain owners are advised to establish continuous monitoring of public CT (Certificate Transparency) logs to detect unauthorized certificate issuance. It's recommended to add CAA (Certification Authority Authorization) records in DNS, defining the list of certificate authorities authorized to issue certificates for the specified domain. Setting a CAA DNS record will not protect against certificate requests after DNS spoofing, but after regaining control over DNS, it will prevent the reissuing of certificates by attackers using cached domain ownership verification data.
Source: opennet.ru
