Attack on Fox-IT shows how a DNS hijack can break multiple layers of security

Posted by   Martijn Grooten on   Dec 14, 2017

Every company will, sooner or later, get hacked and we should judge them by how they respond. With that in mind, Fox-IT, which writes in great detail about how a DNS hijack was used to man-in-the-middle its customer portal, should be judged favourably. The company's report on the incident  also provides some important lessons, in particular when it comes to DNS security.

foxit_headquarters.jpg
Fox-IT headquarters in Delft. Source: "Paul2" at Wikipedia, CC BY-SA 4.0.

DNS is often described as 'the phonebook of the Internet', and while readers of this blog are probably more familiar with the concept of DNS than with phonebooks, what happened was the equivalent of an attacker managing to get the company's listed phone number changed, after which clients ended up calling the incorrect number and sharing some private data.

In particular, after some initial probing, the attackers managed to gain access to Fox-IT's account at its domain registrar. This allowed them to change the DNS settings for the company's client portal.

This in itself would not have been very damaging, as the company is, of course, using HTTPS on this portal. However, for a short period of time the DNS MX records were also changed, allowing the attackers to read emails received by the company. This way, they were able to obtain a valid SSL certificate for the domain.

Fox-IT says that two-factor authentication (2FA) was not offered by the registrar, which in 2017 is somewhat surprising, but it also shows that decisions made long ago (2FA was neither an option nor a consideration when the registrar was chosen 18 years ago) need to be revised every now and again.

It is worth noting, though, that 2FA doesn't necessarily prevent a rogue or hacked employee at the registrar making changes. Hence while 2FA is essential, it is not always good enough. 

It is also worth noting that DNSSEC would probably not have made a difference either: it guarantees that the DNS responses were not modified in transit, but doesn't do much to detect a rogue individual at the registrar making changes.

DNS hijacks are hardly a new phenomenon and have often been used by politically motivated hackers to take down prominent websites; a VB2017 paper  looked at this very subject. But though embarrassing, your website displaying a political slogan for a short period of time is relatively harmless. Fox-IT's attackers demonstrated how a single DNS hack could break the security of HTTPS. Should they have wanted to, they could also have done more harm with email, including sending emails on behalf of the company.

'The weakest link in the chain' is an overused metaphor in security, but this attack once again shows DNS to be a prime candidate. For advice on how to make your organization's DNS more secure, I recommend an article by Koen Rouwhorst, who writes about his experience securing the critical DNS of his employer Blendle.

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

VB2018 video: The Big Bang Theory by APT-C-23

Today, we release the video of the VB2018 presentation by Check Point researcher Aseel Kayal, who connected the various dots relating to campaigns by the APT-C-23 threat group.

VB2019 London - join us for the most international threat intelligence conference!

VB calls on organisations and individuals involved in threat intelligence from around the world to participate in next year's Virus Bulletin conference.

VB2018 paper: Tracking Mirai variants

Today, we publish the VB2018 paper by Qihoo 360 researchers Ya Liu and Hui Wang, on extracting data from variants of the Mirai botnet to classify and track variants.

VB2018 paper: Hide'n'Seek: an adaptive peer-to-peer IoT botnet

2018 has seen an increase in the variety of botnets living on the Internet of Things - such as Hide'N'Seek, which is notable for its use of peer-to-peer for command-and-control communication. Today, we publish the VB2018 paper by Bitdefender…

New paper: Botception: botnet distributes script with bot capabilities

In a new paper, Avast researchers Jan Sirmer and Adolf Streda look at how a spam campaign sent via the Necurs botnet was delivering the Flawed Ammyy RAT. As well as publishing the paper, we have also released the video of the reseachers' VB2018…

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.