Attempt to acquire TLS certificates for foreign mobi domains using an expired domain with a WHOIS service

Researchers from watchTowr Labs published the results of an experiment involving the capture of the outdated WHOIS service of the '.MOBI' domain registrar. The study was prompted by the registrar changing the WHOIS service address, moving it from the domain whois.dotmobiregistry.net to the new host whois.nic.mobi. As a result, the domain dotmobiregistry.net was no longer in use and was released in December 2023, becoming available for registration.

The researchers spent $20 to purchase this domain and then launched their own fake WHOIS service whois.dotmobiregistry.net on their server. They were surprised to find that many systems did not switch to the new host whois.nic.mobi and continued to use the old name. From August 30 to September 4 of this year, 2.5 million requests were recorded using the old name, coming from over 135,000 unique systems.

Among the request senders were representatives of state and military organizations checking email domains through WHOIS, security companies, and security assurance platforms (VirusTotal, Group-IB), as well as certification centers, domain checking services, SEO services, and domain registrars (e.g., domain.com, godaddy.com, who.is, whois.ru, smallseo.tools, seocheki.net, centralops.net, name.com, urlscan.io, and webchart.org). servers The ability to send any data in response to queries to the old WHOIS service of the '.MOBI' domain was leveraged to develop several types of attacks on the request senders. The first attack option was based on the assumption that if someone continued to send requests to a long-replaced service, they were likely doing so using outdated tools that contained vulnerabilities.

For instance, in phpWHOIS, a vulnerability (CVE-2015-5243) was discovered in 2015 that allowed an attacker to execute code when parsing specially crafted data returned by the WHOIS server. Another example is the vulnerability (CVE-2021-32749) found in the Fail2Ban package in 2021, which allowed external code to be executed when incorrect data was returned by the WHOIS service used in the process of generating block alerts (Fail2Ban identified the host administrator's email through WHOIS and included it when executing the mail command without properly escaping special characters).

For example, in phpWHOIS, a vulnerability labeled CVE-2015-5243 was discovered in 2015, allowing an attacker to execute code by parsing specially crafted data returned by the WHOIS server. Another instance is the vulnerability CVE-2021-32749 found in the Fail2Ban package in 2021, which permits the execution of external code when incorrect data is returned by the WHOIS service used to generate block notifications (Fail2Ban would identify the host administrator's email via WHOIS and include it in the mail command without proper escaping of special characters).

The second attack is based on the fact that some certificate authorities provide the ability to verify domain ownership through the email listed in the domain registrar's database, accessible via the WHOIS protocol. It turned out that several certificate authorities supporting this verification method continue to use the old WHOIS server for the .MOBI domain zone.

Thus, by gaining control over the whois.dotmobiregistry.net name, attackers can return their information, complete the verification, and obtain TLS certificate for any domain in the .MOBI zone. For example, in an experiment, researchers requested a GlobalSign TLS certificate for the domain microsoft.mobi, and the email "whois@watchTowr.com" returned by the fake WHOIS service was shown in the interface as available to send the domain ownership verification code.

Attempt to acquire TLS certificates for foreign mobi domains using an expired domain with a WHOIS service


Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster