HomeSecurityZero-Day bug in Verisign & IaaS services lets hackers create...

Zero-Day bug in Verisign & IaaS services lets hackers create fake domains

A critical zero-day bug that affected Verisign and many IaaS services such as Google, Amazon, and DigitalOcean let hackers register homograph domains (.com and .net).

Successfully registering these homograph domains resembles the same well-known domains and subdomains used to perform social engineering and insider attacks and is a similar process to the IDN homograph attack.

Researchers identified several homograph domains operating since 2017 with an HTTPS certificate that mimicked various domains that include finance, online shopping ,technology, and other Fortune 100 sites.

Matt Hamilton, a researcher from Soluble, found that several Generic top-level domains (gTLDs) can be registered using the Unicode Latin IPA Extension character and also managed to register the following homograph domains.

Zero-Day bug in Verisign & IaaS services lets hackers create fake domains

The above registered homograph domains look identical to the corresponding original domains but are essentially created using Unicode Latin IPA.

Similarly, the researcher examined around 300 important domains and the vulnerability is believed to be used only in social engineering that intend to install malware and steal sensitive data.

According to the detailed report “It appears that Verisign and other providers were unaware of the so‑called “homoglyphs” within the Unicode Latin IPA Extension character set”.

Register the homograph domain with a mix of Unicode and Latin characters

Basically, Verisign prevents users from registering domains that use mixed scripts like “gооgle.com” using Cyrillic “о”.

Biden

However, due to the zero-day bug, registering a domain with a combination of Unicode and Latin characters was possible, provided the Unicode characters were the same as in Latin.

“Companies like Verisign explicitly enforce anti-homograph measures (which prohibit mixed scripts) because they don’t want similar domains in the gTLD. Public services that exist under a shared root, such as “s3.amazonaws.com,” “storage.googleapis.com,” or other services that allow users to create arbitrary subdomains, should enforce the same restrictions,” the researcher said.

This bug did not affect only the gTLDs of VeriSign but is likely to affect any TLD that allows Latin IPA characters.

This vulnerability is considered a zero day, as multiple instances of HTTPS certificate logs were detected via Certificate Transparency, as well as an “unofficial” JavaScript library hosted on a “prominent domain.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS