Home / Blogs

Identity Theft of Root Name Servers, Reason Unknown

Earl Zmijewski

There have been a number of attacks on the root name servers over the years, and much written on the topic. (A few references are here, here and here.) Even if you don't know exactly what these servers do, you can't help but figure they're important when the US government says it is prepared to launch a military counterattack in response to cyber-attacks on them.

This posting is about an attack on one such root name server. Actually, "attack" isn't really an appropriate term. It was not really an attack or a hijack or even identity theft. For one thing, these terms imply the existence of both a victim and a villain. In this story, the villains are not obvious and there might not have been any victims. And as we will see, you can't really steal something you own. All we can say for certain is that many of you, if not most, probably used an unauthorized root name server over the past few months and were blissfully unaware of it. These bogus servers may have acted just like a normal root server, providing the correct answers to your queries without logging your requests. But since these servers are now shut down, we can no longer investigate what they were doing. And we can only guess at the motivations of those who set them up.

The following graph shows, over the past six months, the percentage of Renesys peers selecting each of these four competing choices for old L root name servers.

Written by Earl Zmijewski, VP and General Manager, Internet Data Services. Visit the blog maintained by Earl Zmijewski here.

Related topics: DNS, Security

Get a weekly summary of postings to CircleID:

 Master Feed (more feeds)      Twitter      Mobile
Bookmark / Email This Post

Comments

Re: Identity Theft of Root Name Servers, Reason Unknown Bill Manning  –  May 19, 2008 11:57 AM PST

there was agreement between root operators to collect data on some retired addresses for DITL-2008.  the reasons for collecting that data was to check for correlation on querying nodes. The problems have been identified in NANOG presentations and at WIDE/CAIDA workshops over the
years… http://www.caida.org/workshops/wide/0611/ has one of my contributions there.
It is likely that an analysis of the 2008 data will be published later this year.

I understand that ISC is running a data collection service (SIE) and has asked for permission to
collect this type of data on an ongoing basis.

So its not as "nasty" as your title suggests. A little unorthodox, yes.

Re: Identity Theft of Root Name Servers, Reason Unknown Martin Hannigan  –  May 19, 2008 8:43 PM PST

Hyperbole.

Best Regards,

Martin

Re: Identity Theft of Root Name Servers, Reason Unknown Edward Lewis  –  May 20, 2008 6:13 AM PST

Title says: "Identity Theft of Root Name Servers, Reason Unknown".  Then inside the article it says "This posting is about an attack on one such root name server. Actually, 'attack' isn’t really an appropriate term. It was not really an attack or a hijack or even identity theft." So, the title was completely wrong?  Was there a point being made here or just a grab for attention?

Re: Identity Theft of Root Name Servers, Reason Unknown Earl Zmijewski  –  May 20, 2008 6:36 AM PST

Edward Lewis said:

Title says: "Identity Theft of Root Name Servers, Reason Unknown".  Then inside the article it says "This posting is about an attack on one such root name server. Actually, 'attack' isn’t really an appropriate term. It was not really an attack or a hijack or even identity theft." So, the title was completely wrong?  Was there a point being made here or just a grab for attention?

This was the closest term that seemed to fit.  If you went to the old IP during this time, you were implicitly assuming it was a legitimate root name server and the act of running a server on this IP assured that you would continue to do so.  If someone assumes your identity, does it really matter if they give the correct answers to questions about you?

Re: Identity Theft of Root Name Servers, Reason Unknown David Conrad  –  May 20, 2008 8:47 AM PST

http://blog.icann.org/?p=309

Re: Identity Theft of Root Name Servers, Reason Unknown Bill Manning  –  May 20, 2008 9:58 AM PST

Earl Zmijewski said:

Edward Lewis said:

Title says: "Identity Theft of Root Name Servers, Reason Unknown".  Then inside the article it says "This posting is about an attack on one such root name server. Actually, 'attack' isn’t really an appropriate term. It was not really an attack or a hijack or even identity theft." So, the title was completely wrong?  Was there a point being made here or just a grab for attention?

This was the closest term that seemed to fit.  If you went to the old IP during this time, you were implicitly assuming it was a legitimate root name server and the act of running a server on this IP assured that you would continue to do so.  If someone assumes your identity, does it really matter if they give the correct answers to questions about you?

I think you are half right.  ICANN had no authorization from EP.NET to announce the route,
so they had been assuming EP.NET identity. 

That said, there was agreement to announce the route and collect data for DITL between ICANN and EP.NET.  You did not do your homework and it appears there are "chinese walls" inside ICANN, where one party is not talking to another.

Re: Identity Theft of Root Name Servers, Reason Unknown Martin Hannigan  –  May 20, 2008 2:54 PM PST

That said, there was agreement to announce the route and collect data for DITL between ICANN and EP.NET.  You did not do your homework and it appears there are “chinese walls” inside ICANN, where one party is not talking to another.

The references noted for the article were also fairly out of date. There are other issues that seem more important though. Like root server data privacy.

-M<

To post comments, please login or create an account.

Related Blogs

Related News

Other Topics

Access Providers Broadband Censorship Cloud Computing Cyberattack Cybercrime Cybersquatting Data Center DNS DNSSEC Domain Names Domain Registries Email Enum ICANN Internet Governance Internet Protocol IP Addressing IPTV IPv6 Law Malware Mobile Multilinguism Net Neutrality P2P Policy & Regulation Privacy Regional Registries Security Spam Telecom Top-Level Domains VoIP Web White Space Whois Wireless



Industry Updates – Sponsored Posts

ICANN and Cybersecurity: Hot Topics at The First Ever .ORG Forum

Neustar Releases UltraDNS Report Center

Neustar Implements DNS Security Extensions in the .US Registry

Neustar Launches Initiative to Enhance DNS With Faster, More Secure Updates

Registry Stakeholder Group Comments on Latest ICANN Policies

Open Phishing Season

Nominum Announces "DNSSEC Made Easy" Solutions

.ORG Highlighted for Success in Fighting Phishing

Afilias' Matt Pounsett Elected Director-at-Large for DNS-OARC

.ORG Wins WebAward for Website Redesign and Selected as a Finalist for the NonProfit PR Awards

SEO Poisoning: A Persistent Malware Threat Targeting High-Profile Brands

NeuStar Expands UltraDNS Network Infrastructure in Europe

Nominum CEO: Commercial vs. Open Source - Let Customers Choose

Pharmaceutical Brandjacking for Popular Drug Brands on the Rise

Nominum Broadens Intelligent DNS Impact With SKYE Cloud Services

Afilias Managed DNS Services Adds SiteCertain to Keep Watch on Your Web Site

DNSstuff.com Launches Industry's First Mail Server Test Center

Afilias Seeks New TLD Partners

Growing Global Adoption of Nominum's Intelligent DNS Spells Obsolescence for Legacy DNS Systems

Nominum's Intelligent DNS Gives Service Providers Commanding Advantage Against Internet Threats