Backdooring Your Backdoors – Another $20 Domain, More Governments

labs.watchtowr.com

234 points by mooreds 7 hours ago


Lammy - 6 hours ago

To avoid my comment being entirely a terminology nitpick I will say this is very cool work that I would be too afraid of CFAA to ever attempt. Especially funny to see four parasites on one government domain. Do skiddies not excise other skiddies' backdoors when pwning systems so they can have them all to themselves?

> We then hooked that up to the AWS Route53 API, and just bought them en-masse. Honestly, it’s $20, and we’ve done worse with more.

> We’re incredibly grateful for the support of The Shadowserver Foundation, who have agreed yet again to save us from our own adventures and to take ownership of the domains implicated in this research and sinkhole them.

I wish we could collectively stop using the terms “buy” and “own” with regard to domains. Try “leased” or “rented”. If they could be bought then they wouldn't have been available again for this exercise.

fn-mote - 2 hours ago

I loved this write up. Light-hearted. Conscious of the impact of any disclosure. Everything substantiated, but not taking themselves too seriously. Enjoying read, and at the same time talking about a serious issue.

Thorrez - 4 hours ago

I wonder what would happen if they exploited these webshells' backdoors to delete the webshells...

busymom0 - 3 hours ago

Slightly off topic but what's going on with the font for the "y" character in this article? It sticks out like a sore thumb.

Its_Padar - 6 hours ago

Technically this is a dupe as this has been submitted twice before in the last week

https://news.ycombinator.com/item?id=42658405

https://news.ycombinator.com/item?id=42633273