Analysis of the incident involving a loss of control over the domain perl.com has been published

Brian Foy, the founder of the Perl Mongers organization, has published a detailed analysis of the incident in which the domain perl.com was hijacked by unauthorized parties. The domain takeover did not affect the project's server infrastructure and was carried out at the level of changing ownership and replacing DNS server settings with the registrar. It is claimed that the computers responsible for the domain were also not compromised and the attackers employed social engineering methods to mislead the registrar Network Solutions and alter the ownership information, using fake documents to validate their ownership claims.

Among the factors contributing to the attack, the disabling of two-factor authentication in the registrar’s interface and the use of a contact email stating the same are also mentioned. domainThe domain was hijacked back in September 2020, in December the domain was transferred to the Chinese registrar BizCN, and in January for obfuscation was passed to the German registrar Key-Systems GmbH.

Until December, the domain remained with Network Solutions in accordance with ICANN's requirements prohibiting the transfer of the domain to another registrar within 60 days of changing contact information. If the information about the domain takeover had been revealed before December, the process of reclaiming the domain would have been significantly simplified, which is why the criminals did not change the DNS servers for a long time, and the domain continued to operate without raising suspicion, which hindered the timely detection of the attack. The issue only surfaced at the end of January when the fraudsters redirected traffic to their server and attempted to sell the domain on Afternic for $190,000.

Among the events related to the Perl language, it is also noteworthy that the CPAN module archive has abandoned the use of mirrors in favor of implementing a content delivery network, which reduces the load on the main server. In June, the list of mirrors is planned to be completely cleared, leaving only one entry — www.cpan.org. The possibility for manual configuration of the CPAN client to operate through a specified mirror will remain.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster