Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Verlorene Domains, Offene Türen - Was Alte Behördendomains Verraten

media.ccc.de via YouTube

Overview

Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore the security vulnerabilities that arise when government domains expire and fall into private hands in this 40-minute conference talk from 39C3. Discover how expired domains from German federal ministries and agencies were acquired, revealing significant data streams and security risks within government networks. Learn about the months-long investigation that captured DNS queries from federal networks, demonstrating how such vulnerabilities could enable account takeovers, email signature validation manipulation, request redirection, and potentially code execution on government systems. Examine the technical and organizational weaknesses behind these incidents, including misconfigurations, bitsquatting, and typosquatting phenomena within administrative networks. Understand how operating a DNS server and acquiring domains like bund.ee (similar to bund.de through typosquatting/bitsquatting) enabled the reception of numerous DNS queries from servers of the Federal Ministry of the Interior (BMI) and other federal institutions. Analyze practical examples and data findings that reveal insights into state IT infrastructure through DNS details, while exploring why Germany lacks widespread adoption of standardized government domains like gov.uk, instead relying on individual ministry domains that may change with government transitions. Gain recommendations for preventing similar incidents in the future through responsible disclosure practices and improved domain management strategies.

Syllabus

39C3 - Verlorene Domains, offene Türen - Was alte Behördendomains verraten

Taught by

media.ccc.de

Reviews

Start your review of Verlorene Domains, Offene Türen - Was Alte Behördendomains Verraten

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.