Alias Equals Zone? Large-Scale and Stealthy Takeover of Domain Hosting Service via CNAME-Following Cross-Domain Verification
Ruixuan Li, Xingyu Zhao, Yunyi Zhang, Baojun Liu, Jun Shao
摘要
CNAME records define alias relationships between domains and are widely used for service hosting and load balancing. We find that popular domain hosting providers misinterpret CNAME semantics during domain ownership verification. They accept DNS records after CNAME redirection as valid challenge tokens for alias domains, even though these domains do not configure any tokens. Based on this flaw, we propose ALIASLEAP, a novel domain takeover attack that enables hijacking hosting services of alias domains in CNAME chains. ALIASLEAP poses a serious threat in the real world: we identify four email and seven web hosting providers that are vulnerable, affecting over two million domains, including 200K in the Tranco Top 1M domain list. ALIASLEAP is highly stealthy because vulnerable CNAME chains are typically legitimate and long-lived: about half persist for more than 12 months, and up to 19,819 domains have been exposed for over 10 years. We propose mitigation strategies and responsibly disclose ALIASLEAP to 11 affected hosting providers, receiving confirmations from eight of them. We call on the Internet community to revisit the usage practices and capability boundaries of CNAME records.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS RecordsDaiping Liu, Shuai Hao, Haining WangCCS 2016 · 被引用 91 次
- Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern WebMarco Squarcina, Mauro Tempesta, Lorenzo Veronese, Stefano Calzavara 等USENIX Security 2021 · 被引用 30 次
- Cloudy with a Chance of Cyberattacks: Dangling Resources Abuse on Cloud PlatformsJens Frieß, Tobias Gattermayer, Nethanel Gelernter, Haya Schulmann 等NSDI 2024 · 被引用 5 次
- HADES Attack: Understanding and Evaluating Manipulation Risks of Email BlocklistsRuixuan Li, Chaoyi Lu, Baojun Liu, Yunyi Zhang 等NDSS 2025
相关 Paper
- Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting ReferralEihal Alowaisheq, Siyuan Tang, Zhihao Wang, Fatemah Alharbi 等CCS 2020 · 被引用 19 次
- Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS InfrastructureYunyi Zhang, Mingming Zhang, Baojun Liu, Zhan Liu 等USENIX Security 2024 · 被引用 3 次
- Rethinking the Security Threats of Stale DNS Glue RecordsYunyi Zhang, Baojun Liu, Haixin Duan, Min Zhang 等USENIX Security 2024 · 被引用 9 次
- Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS ServersFenglu Zhang, Baojun Liu, Eihal Alowaisheq, Jianjun Chen 等CCS 2023 · 被引用 3 次
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 被引用 2 次
