Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/3578338.3593534acmconferencesArticle/Chapter ViewAbstractPublication PagesmetricsConference Proceedingsconference-collections
abstract

Detecting and Measuring Security Risks of Hosting-Based Dangling Domains

Published: 19 June 2023 Publication History

Abstract

Public hosting services offer a convenient and secure option for creating web applications. However, adversaries can take over a domain by exploiting released service endpoints, leading to hosting-based domain takeover. This threat has affected numerous popular websites, including the subdomains of microsoft.com. However, no effective detection system for identifying vulnerable domains at scale exists to date. This paper fills the research gap by presenting a novel framework, HostingChecker, for detecting domain takeovers. HostingChecker expands detection scope and improves efficiency compared to previous work by: (i) identifying vulnerable hosting services using a semi-automated method; and (ii) detecting vulnerable domains through passive reconstruction of domain dependency chains. The framework enables us to detect the subdomains of Tranco sites on a daily basis. It discovers 10,351 vulnerable subdomains under Tranco Top-1M apex domains, which is over 8× more than previous findings, demonstrating its effectiveness. Furthermore, we conduct an in-depth security analysis on the affected vendors (e.g., Amazon, Alibaba) and gain a suite of new insights, including flawed domain ownership validation implementation. In the end, we have reported the issues to the security response centers of affected vendors, and some (e.g., Baidu and Tencent) have adopted our mitigation. The full paper is provided in [2].

Supplemental Material

MP4 File
Presentation video - short version

References

[1]
2022. 114 DNS. https://www.114dns.com/
[2]
Mingming Zhang, Xiang Li, Baojun Liu, Jianyu Lu, Yiming Zhang, Jianjun Chen, Haixin Duan, Shuang Hao, and Xiaofeng Zheng. 2023. Detecting and Measuring Security Risks of Hosting-Based Dangling Domains. Proc. ACM Meas. Anal. Comput. Syst., Vol. 7, 1, Article 9 (mar 2023), 28 pages. https://doi.org/10.1145/3579440

Cited By

View all
  • (2023)Detecting and Measuring Security Risks of Hosting-Based Dangling DomainsACM SIGMETRICS Performance Evaluation Review10.1145/3606376.359353451:1(87-88)Online publication date: 27-Jun-2023
  • (2023)TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS AmplifiersProceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security10.1145/3576915.3616668(311-325)Online publication date: 15-Nov-2023

Index Terms

  1. Detecting and Measuring Security Risks of Hosting-Based Dangling Domains

    Recommendations

    Comments

    Information & Contributors

    Information

    Published In

    cover image ACM Conferences
    SIGMETRICS '23: Abstract Proceedings of the 2023 ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems
    June 2023
    123 pages
    ISBN:9798400700743
    DOI:10.1145/3578338
    • cover image ACM SIGMETRICS Performance Evaluation Review
      ACM SIGMETRICS Performance Evaluation Review  Volume 51, Issue 1
      SIGMETRICS '23
      June 2023
      108 pages
      ISSN:0163-5999
      DOI:10.1145/3606376
      Issue’s Table of Contents
    Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

    Sponsors

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    Published: 19 June 2023

    Check for updates

    Author Tags

    1. domain takeover
    2. public hosting service

    Qualifiers

    • Abstract

    Data Availability

    Funding Sources

    • National Natural Science Foundation of China

    Conference

    SIGMETRICS '23
    Sponsor:

    Acceptance Rates

    Overall Acceptance Rate 459 of 2,691 submissions, 17%

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • Downloads (Last 12 months)34
    • Downloads (Last 6 weeks)1
    Reflects downloads up to 02 Sep 2024

    Other Metrics

    Citations

    Cited By

    View all
    • (2023)Detecting and Measuring Security Risks of Hosting-Based Dangling DomainsACM SIGMETRICS Performance Evaluation Review10.1145/3606376.359353451:1(87-88)Online publication date: 27-Jun-2023
    • (2023)TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS AmplifiersProceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security10.1145/3576915.3616668(311-325)Online publication date: 15-Nov-2023

    View Options

    Get Access

    Login options

    View options

    PDF

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader

    Media

    Figures

    Other

    Tables

    Share

    Share

    Share this Publication link

    Share on social media