About Us | Contact Us
View Cart

New Top Level Domains Could Expose Companies To Risk

By Vigilize | Wednesday, June 15, 2016 - Leave a Comment

An article review.


Opportunistic hackers could register new TLDs hoping to prey on misdirected internal traffic


ServIcons_ITAudit_01

 

The US Computer Emergency Readiness Team (US-CERT) recently issued a statement for organizations who use top level domain names to route internal traffic, warning that misconfigured proxy servers could route requests for those names to newly registered external domains.

The potential attack is linked to the Web Proxy Auto-Discovery (WPAD) service in Windows, which attempts to standardize web proxy configurations across a network by downloading settings from a central server. Domain name requests intended for WPAD have been observed reaching servers on the open internet in the past, potentially leading to a situation where internal network traffic gets routed to a domain specifically selected to try and catch these requests for malicious purposes.

Considering the increase in top level domain names from less than a dozen to over 1,200 it’s impossible to know what formerly unused names could become live in the future, so security experts suggest companies either use names they’ve registered themselves or make certain no internal DNS requests can make it to the outside.


Original article by US-CERT.


same_strip_012513


 

Latest News
    The One Test… …Is there a Test that Covers 9/11’s of the Battle? Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Twenty years ago two geek-friends and I debated the following question:  “Is there an Audit Test that covers 9/11’s of the battle?” This […]
    PRESS RELEASE – FOR IMMEDIATE RELEASE BUSINESS NEWS NEW EMPLOYEE FOR INFOTEX infotex has just hired Tanvee Dhir, to be a new Data Security Analyst. “Tanvee is an outstanding addition to the team, bringing a new skillset we are eager to utilize.” says Chad Smith, NOC Manager of infotex. “I am really excited to be […]
    While we’re not a news service, we often use current events to comment on trends and our services. This blog is intended to get people thinking about topics and trends in Technology Risk Management, through our article reviews, as well as through original blog articles about current events and our MSSP services (such as our […]
    Seven Trends . . . that small bank Information Security Officers face in 2021 Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Welcome to the Magnificent Seven, my annual predictive article about the seven trends in technology that will impact the Information Security Officers of […]
    Top Seven Risks . . . that small bank Information Security Officers face in 2021 Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Once again, I compile this list in preparation for updating our normal board of directors awareness training PowerPoints and movies and such. […]