My next class:

.NL Registrar Compromisse

Published: 2013-07-10. Last Updated: 2013-07-10 20:00:51 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)

Based on a note on the website of SIDN [1], as SQL injection vulnerability was used to compromisse the site and place malicious files in the document root. SIDN is the registrar for the .NL country level domain (Netherlands). As a result of the breach, updates to the zone file are suspended. There is no word as to any affects to the zone files, or if the attackers where able to manipulate them.

 

[1] https://www.sidn.nl/en/news/news/article/preventieve-maatregelen-genomen-2/

------
Johannes B. Ullrich, Ph.D.
SANS Technology Institute
Twitter

Keywords: dns nl registrar sidn
0 comment(s)
My next class:

Comments


Diary Archives