Attack on Fox-IT shows how a DNS hijack can break multiple layers of security

Posted by   Martijn Grooten on   Dec 14, 2017

Every company will, sooner or later, get hacked and we should judge them by how they respond. With that in mind, Fox-IT, which writes in great detail about how a DNS hijack was used to man-in-the-middle its customer portal, should be judged favourably. The company's report on the incident  also provides some important lessons, in particular when it comes to DNS security.

foxit_headquarters.jpg
Fox-IT headquarters in Delft. Source: "Paul2" at Wikipedia, CC BY-SA 4.0.

DNS is often described as 'the phonebook of the Internet', and while readers of this blog are probably more familiar with the concept of DNS than with phonebooks, what happened was the equivalent of an attacker managing to get the company's listed phone number changed, after which clients ended up calling the incorrect number and sharing some private data.

In particular, after some initial probing, the attackers managed to gain access to Fox-IT's account at its domain registrar. This allowed them to change the DNS settings for the company's client portal.

This in itself would not have been very damaging, as the company is, of course, using HTTPS on this portal. However, for a short period of time the DNS MX records were also changed, allowing the attackers to read emails received by the company. This way, they were able to obtain a valid SSL certificate for the domain.

Fox-IT says that two-factor authentication (2FA) was not offered by the registrar, which in 2017 is somewhat surprising, but it also shows that decisions made long ago (2FA was neither an option nor a consideration when the registrar was chosen 18 years ago) need to be revised every now and again.

It is worth noting, though, that 2FA doesn't necessarily prevent a rogue or hacked employee at the registrar making changes. Hence while 2FA is essential, it is not always good enough. 

It is also worth noting that DNSSEC would probably not have made a difference either: it guarantees that the DNS responses were not modified in transit, but doesn't do much to detect a rogue individual at the registrar making changes.

DNS hijacks are hardly a new phenomenon and have often been used by politically motivated hackers to take down prominent websites; a VB2017 paper  looked at this very subject. But though embarrassing, your website displaying a political slogan for a short period of time is relatively harmless. Fox-IT's attackers demonstrated how a single DNS hack could break the security of HTTPS. Should they have wanted to, they could also have done more harm with email, including sending emails on behalf of the company.

'The weakest link in the chain' is an overused metaphor in security, but this attack once again shows DNS to be a prime candidate. For advice on how to make your organization's DNS more secure, I recommend an article by Koen Rouwhorst, who writes about his experience securing the critical DNS of his employer Blendle.

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

VB2019 paper: Operation Soft Cell - a worldwide campaign against telecommunication providers

Today we publish the VB2019 paper by Cybereason researchers Mor Levi, Amit Serper and Assaf Dahan on Operation Soft Cell, a targeted attack against telecom providers around the world.

VB2019 paper: A study of Machete cyber espionage operations in Latin America

At VB2019 in London a group of researchers from the Stratosphere Lab at the Czech Technical University in Prague presented a paper in which they analysed and dissected the cyber espionage activities of an APT group in Latin America through the…

VB2019 paper: The push from fiction for increased surveillance, and its impact on privacy

In a paper presented at VB2019 in London, researchers Miriam Cihodariu (Heimdal Security) and Andrei Bogdan Brad (Code4Romania) looked at how surveillance is represented in fiction and how these representations are shaping people's attitudes to…

VB2019 paper: Oops! It happened again!

At VB2019 in London industry veterans Righard Zwienenberg and Eddy Willems took a detailed look at the relationship between past and current cyber threats. Today, we publish both their paper and the recording of their presentation.

Job vacancy at VB: Security Evangelist

Virus Bulletin is recruiting for a person to be the public face of the company

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.