Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Comment Hackable DNS (Score 1) 283

I don't know how many people knew this, but about 5 years ago there was an exploit for Internic where you could actually change the DNS entry via their web interface without being the owner of that domain.

The only catch at all was that once you'd changed the domain servers, the domain owner had an email letting them know. If they didn't spot this within 24 hours you could fully transfer ANY domain on the web.

Sadly I was just a dumb 16 year old when I figured this out, so didn't use it wisely, but I took over a bunch of domains (won't name names because I probably caused a lot of lost business) and pointed them at my own little site for about a month before anyone found me. I tried Microsoft.com too, but they saw the transfer going through, blocked it, and chased me up with some very threatening calls.

The funny thing is this exploit was so easy, but I've never heard of anyone else doing it. Was this ever known publicly?

Slashdot Top Deals

Consider the postage stamp: its usefulness consists in the ability to stick to one thing till it gets there. -- Josh Billings

Working...