{"id":339557,"date":"2020-02-20T10:49:45","date_gmt":"2020-02-20T08:49:45","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=339557"},"modified":"2020-02-20T10:51:30","modified_gmt":"2020-02-20T08:51:30","slug":"beware-microsoft-subdomains-are-being-hijacked","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/339557-beware-microsoft-subdomains-are-being-hijacked.html","title":{"rendered":"Beware &#8211; Microsoft subdomains are being hijacked"},"content":{"rendered":"<p>Security researcher Michel Gaschet said Microsoft has been ignoring his reports that Microsoft subdomains are being hijacked.<\/p>\n<p>Speaking with <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-has-a-subdomain-hijacking-problem\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>ZDNet<\/strong><\/a>, Gaschet said he reported a total of 142 misconfigured Microsoft.com subdomains last year, as well as a further 21 msn.com subdomains in 2017.<\/p>\n<p>A separate list of 117 Microsoft.com subdomains was also reportedly shared with ZDNet &#8211; which were also reported to Microsoft in 2019.<\/p>\n<p>He said that Microsoft largely ignored his reports while silently fixing some of the subdomains.<\/p>\n<h3 class=\"my-4\"><strong>How it works<\/strong><\/h3>\n<p>Security researcher Szymon Gruszecki explained to <a href=\"https:\/\/labs.detectify.com\/2014\/12\/08\/hijacking-of-abandoned-subdomains-part-2\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Detectify<\/strong><\/a> how this hijacking works in 2014.<\/p>\n<p>&#8220;Last year [I] performed a scan on [the] top 5,000 domain names from Alexa global rank and discovered 49 subdomains of different domains (that is ~1% of all ones) that point in CNAME records to not registered, forgotten domains or their subdomains,&#8221; said Gruszecki.<\/p>\n<p>&#8220;So in this case, if you want to own [a] not used subdomain just simply buy an expired domain name and configure its DNS zone.&#8221;<\/p>\n<p>He also showed an example where he implemented this with one such domain &#8211; racing.msn.com.<\/p>\n<div id=\"attachment_339561\" style=\"width: 650px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/02\/racinmsncom.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-339561\" class=\"wp-image-339561 size-large\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/02\/racinmsncom-640x383.png\" alt=\"racinmsncom\" width=\"640\" height=\"383\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/02\/racinmsncom-640x383.png 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/02\/racinmsncom-600x359.png 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/02\/racinmsncom-768x460.png 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/02\/racinmsncom.png 942w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><p id=\"caption-attachment-339561\" class=\"wp-caption-text\">Image via Detectify<\/p><\/div>\n<p>&#8220;Since the registration of msnbrickyardsweeps.com has expired, he could buy it and suddenly racing.msn.com starts showing his content since racing.msn.com has a CNAME record pointing to msnbrickyardsweeps.com,&#8221; explained Detectify.<\/p>\n<p>The exploit allows the new owner to set up emails using the racing.msn.com domain, and they can also receive all emails sent to addresses that use this domain.<\/p>\n<p>The new owner can also set up an SSL certificate on the subdomain &#8211; making the website appear more legitimate.<\/p>\n<h3 class=\"my-4\">Exploited in the wild<\/h3>\n<p>While this practice has been around for years, it is only recently that this exploit has been used against Microsoft in the wild.<\/p>\n<p>Gaschet highlighted on <a href=\"https:\/\/twitter.com\/Michel_Gaschet\/status\/1229773153481691143\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Twitter<\/strong><\/a> that an Indonesian Poker website was using this exploit.<\/p>\n<p>&nbsp;<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\"><a href=\"https:\/\/t.co\/XAJfbsE4ht\">https:\/\/t.co\/XAJfbsE4ht<\/a><\/p>\n<p>This kind of stuff, this is what you get by putting subdomain takeover out of scope, and don&#8217;t fix critical subdomain takeover from good peoples, rarely thanks them and generally not respond to them. Great job, <a href=\"https:\/\/twitter.com\/msftsecresponse?ref_src=twsrc%5Etfw\">@msftsecresponse<\/a> &#x1f44f;<\/p>\n<p>\u2014 Michel Gaschet (@Michel_Gaschet) <a href=\"https:\/\/twitter.com\/Michel_Gaschet\/status\/1229773153481691143?ref_src=twsrc%5Etfw\">February 18, 2020<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>According to Gaschet, at least three other legitimate Microsoft domains were also found being used to run ads for Indonesian poker casinos.<\/p>\n<p>These casinos seek to boost the &#8220;reputation&#8221; of their spam by hosting it on a reputable domain, said Gaschet.<\/p>\n<p>Microsoft said the issue regarding these poker websites have been fixed and recommended that users be careful when clicking on links or opening unknown files.<\/p>\n<h3 class=\"my-4\">Microsoft&#8217;s hijacking problem<\/h3>\n<p>This isn&#8217;t the first report in recent times that malicious parties have been exploiting unprotected Microsoft subdomains, however.<\/p>\n<p>In November 2019, Microsoft fixed a <a href=\"https:\/\/mybroadband.co.za\/news\/security\/331280-microsoft-login-bug-allowed-account-hijacking.html\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>vulnerability<\/strong><\/a> in its login systems which allowed malicious parties to hijack user accounts.<\/p>\n<p>Cybersecurity company CyberArk found that by using one of numerous unregistered Microsoft subdomains, malicious parties could trick users into clicking on their links.<\/p>\n<p>Clicking these links allowed malicious parties to steal one of the user&#8217;s account tokens.<\/p>\n<p>These tokens are mostly used to allow users to remain logged into websites and give them access to third-party apps or websites without using their passwords.<\/p>\n<p>\u201cWe resolved the issue with the applications mentioned in this report in November and customers remain protected,\u201d said a Microsoft spokesperson.<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/software\/339567-android-11-revealed-everything-you-need-to-know.html\" rel=\"bookmark\">Android 11 revealed \u2013 Everything you need to know<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Security researcher Michel Gaschet said Microsoft has been ignoring his reports that Microsoft subdomains are being hijacked.<\/p>\n","protected":false},"author":341039,"featured_media":77036,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[28563,123,63235],"class_list":["post-339557","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-hijacking","tag-microsoft","tag-subdomain"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/339557"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341039"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=339557"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/339557\/revisions"}],"predecessor-version":[{"id":339581,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/339557\/revisions\/339581"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/77036"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=339557"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=339557"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=339557"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}