[AusNOG] DNS Devolution targeting the .com.au space - should we be worried?

Nick Marsham nick at c2conline.com.au
Thu Jun 1 15:51:37 EST 2017


DNS devolution in AD domains in all supported versions of Windows doesn't proceed past the FQDN of the forest root domain, so the only way you could get into this exact scenario is by your FRD configured as "com.au", or to have a global search suffix list configured which includes the suffix "com.au", since global search suffix lists override devolution.

If you're able to provide me an example of how devolution could actually cause the scenario you suggest in Windows 7/Server 2008R2 or newer, I'd be very interested.

It's also important to note that the owner com.com.au is not explicitly "registering" A records in order to catch big-name companies: Their DNS server simply has a 'catchall' which returns a landing page.

From: AusNOG [mailto:ausnog-bounces at lists.ausnog.net] On Behalf Of Benjamin Ricardo
Sent: Thursday, 1 June 2017 3:36 PM
To: 'Ausnog' <ausnog at lists.ausnog.net>
Subject: [AusNOG] DNS Devolution targeting the .com.au space - should we be worried?

HI All,
Looking for thoughts on something that we uncovered today in the wild (heard about it years ago but never seen it) regarding internal company domains that are using public .com.au domain suffixes and whether there's something that should be done here.

The issue is caused by Microsofts Primary DNSSuffix Devolution and the potential for legitimate traffic to be redirected to the owner of the domain "com.com.au." if your machine has a domain name of "somehostname.somedomainname.com.au"
It is possible in this situation for a non-qualified query to do the following:

ibm.com.somehostname.somedomainname.com.au     (NXDOMAIN)
ibm.com.somedomainname.com.au                                      (NXDOMAIN)
ibm.com.com.au                                                                              (NOERROR)

You can see the vulnerability.
The problem is now that it appears that the owner of the domain "com.com.au" has started to register A records for big name domains such as .ibm.com in the hope of catching non-fully qualified queries to these addresses.

I can only think that this is going to end badly for people.
Is this the sort of thing that could be flagged as abuse?

Appreciate any comments.

Ben

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ausnog.net/pipermail/ausnog/attachments/20170601/3401f2ee/attachment.html>


More information about the AusNOG mailing list