Due to a typo in the settings, attackers could substitute the DNS server for MasterCard.

A security researcher from Seralys discovered a vulnerability that allows for DNS server spoofing for the domain mastercard.com, which is used in the MasterCard payment system infrastructure. Since June 2020, there has been a typo in the DNS server list for the mastercard.com domain zone – instead of the host "a22-65.akam.net" (Akamai DNS service), the host "a22-65.akam.ne" was indicated. The root zone ".ne" is assigned to Niger, and the domain "akam.ne" was available for sale.

Thus, for four and a half years, anyone could buy a domain name "akam.ne", create the host "a22-65.akam.ne", deploy a DNS server on it, establish their own version of the DNS zone for mastercard.com, and redirect any subdomain of mastercard.com to their server. DNSSEC was not used for mastercard.com. Since the typo was made in the name of one of the five DNS servers, a successful attack could lead to control over at least 1/5 of the traffic. Coverage could be increased by setting a large TTL (Time To Live) for the spoofed zone, which would result in records being cached longer by public resolvers, such as those maintained by Cloudflare (1.1.1.1) and Google (8.8.8.8).

Due to a typo in the settings, attackers could substitute the DNS server for MasterCard.

In addition to intercepting traffic from existing hosts, a less noticeable attack could have been carried out, utilizing an initially absent subdomain for phishing purposes, such as creating the host "redemtion.mastercard.com" and using it in spam instead of the legitimate entry point "redemption.mastercard.com". Among other things, having control over one of the DNS servers serving the mastercard.com domain would allow for TLS certificate services that permit domain ownership verification via Web or DNS, such as Let’s Encrypt. Among the potential attack scenarios, creating a spoofed mail server to intercept correspondence with the email name@mastercard.com and organizing the interception of authentication data from the computers of employees using Windows is also mentioned.

The researcher who identified the issues purchased the domain "akam.ne" for $300 and launched a DNS sniffer to assess traffic volume. The analysis of the received queries showed that the case with MasterCard was not unique and that there are other domain zones whose DNS server list includes the host "akam.ne" instead of "akam.net". Moreover, it was found that from 2015 to 2018, the domain "akam.ne" was registered and likely used to conduct attacks. The assumption of attacks was made because the former owner of "akam.ne" also registered the domain "awsdns-06.ne", which mimics the DNS server "awsdns-06.net". The malfunction of one of the DNS servers due to a typo in the name may go unnoticed by administrators for a long time, as fault tolerance is ensured by specifying multiple DNS servers.

MasterCard initially ignored the report about the issue, but after being contacted by journalist Brian Krebs, it acknowledged and fixed the error, stating that it did not pose a threat to infrastructure. Following this, through the Bugcrowd platform, which allows for rewards for identifying vulnerabilities, the researcher was redirected to a request from MasterCard to remove the published note about the incident.

In response, the researcher stated that while he has an account with Bugcrowd, he did not submit any reward requests and directly notified MasterCard about the issue. The note was published to draw attention to the problem after MasterCard was no longer at risk and the domain "akam.ne" belonged to the researcher. As a result, MasterCard not only failed to reimburse the $300 spent on the domain but did not even express gratitude to the researcher verbally.

Regarding the claim that the error did not pose additional risks, the researcher provided statistics on the received DNS requests, which included domains *.az.mastercard.com, indicating operational components of MasterCard's infrastructure hosted on Microsoft's Azure cloud service. The compromise of such components apparently posed a critical security threat.

Due to a typo in the settings, attackers could substitute the DNS server for MasterCard.


Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster