• evidences@lemmy.world
    link
    fedilink
    English
    arrow-up
    101
    ·
    2 days ago

    Orphaned domains like this are interesting, there was a defcon talk, I think, where the presenter bought a bunch of blacklisted orphaned domains just to see if anything would try and connect to them. They got hit with so many botnet clients trying to phone home.

    • MysteriousSophon21@lemmy.world
      link
      fedilink
      English
      arrow-up
      44
      ·
      2 days ago

      Yeah those orphaned domains are a goldmine for security researchers, there was a similar talk at blackhat where they showed how expired domains from major companies still recieved auth tokens and sensitive data for months after expiry.

    • Maestro@fedia.io
      link
      fedilink
      arrow-up
      49
      arrow-down
      1
      ·
      2 days ago

      Orphaned IPs as well. If you have an IPv4 from your cloud provider and you want to retire it, you should thoroughly scrub your DNS and all other configs before doing so. Otherwise it’s trivial for someone else to spin up a machine on that IP address and abuse your domain.

      • dil@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        19 hours ago

        Basically, when you stop paying for hosting, also remove records from your domain, or itll link to the new person with your old hosting ips website and show that on your domain. I always forget when I swap hosting on my personal sites and haven’t updated the records, see some random dropshipping or local (not to me) business website on my domain lol