<?xml version="1.0" encoding="utf-8"?>
<feed
    xmlns="http://www.w3.org/2005/Atom"
    xmlns:at="http://www.sixapart.com/ns/at"
    xmlns:icbm="http://postneo.com/icbm"
    xmlns:rvw="http://purl.org/NET/RVW/0.2/"
    xml:lang="en">
    <title>till&#39;s blog</title>
    <link rel="self" type="application/atom+xml" title="till&#39;s blog (Atom)" href="http://till.vox.com/library/posts/tags/hijack/page/1/atom.xml" />
    <link rel="alternate" type="text/html" title="till&#39;s blog" href="http://till.vox.com/library/posts/tags/hijack/page/1/"/> 
    <link rel="service.post" type="application/atom+xml" title="till&#39;s blog" href="http://www.vox.com/services/atom/svc=post/collection_id=6a00c2251d8a1b549d00c2251e7add8e1d" /> 
    <link rel="service.subscribe" type="application/atom+xml" title="till&#39;s blog" href="http://till.vox.com/library/posts/tags/hijack/atom.xml" />   
    <link rel="last" type="application/atom+xml" title="till&#39;s blog" href="http://till.vox.com/library/posts/tags/hijack/page/1/atom.xml" />  
    <category term="hijack" scheme="http://till.vox.com/tags/hijack/?_c=feed-atom-full" label="hijack" /> 
    <generator uri="http://www.vox.com/">Vox</generator>
    <updated>2008-05-06T12:59:33Z</updated> 
    <author>
        <name>till</name>
        <uri>http://till.vox.com/?_c=feed-atom-full</uri>
    </author> 
    <id>tag:vox.com,2006:6p00c2251d8a1b549d/tags/hijack/</id>  
    
    <entry>
        <title>Hijacking DNS with everydns.net</title>   
        <link rel="alternate" type="text/html" title="Hijacking DNS with everydns.net" href="http://till.vox.com/library/post/hijacking-dns-with-everydnsnet.html?_c=feed-atom-full" />  
        <link rel="service.post" type="application/atom+xml" title="Hijacking DNS with everydns.net" href="http://till.vox.com/library/post/hijacking-dns-with-everydnsnet.html?_c=feed-atom-full#comments" /> 
        <link rel="service.edit" type="application/atom+xml" title="Hijacking DNS with everydns.net" href="http://www.vox.com/atom/svc=post/asset_id=6a00c2251d8a1b549d00f48cf52e4c0003" />          <id>tag:vox.com,2008-05-05:asset-6a00c2251d8a1b549d00f48cf52e4c0003</id>
        <published>2008-05-05T18:12:34Z</published>
        <updated>2008-05-06T12:59:33Z</updated>
    
        <author>
            <name>till</name>
            <uri>http://till.vox.com/?_c=feed-atom-full</uri>
        </author>
    
        
        <content type="html" xml:base="http://till.vox.com/?_c=feed-atom-full">
            <![CDATA[
                <div xmlns="http://www.w3.org/1999/xhtml" xmlns:at="http://www.sixapart.com/ns/at">
        <p>Last night a friend noticed that using his domain there were a couple spamhosts floating around on the Internet promoting the usual (porn, cialis and the like). We host(ed) his DNS through <a href="http://www.everydns.net">everydns.net</a>&#39;s free service (which aside from one downtime and this incident has been outstanding over maybe six or eight years). It&#39;s a free service, powered by donations.<br /><span style="font-size: 1.25em;"><br /><strong>Here is the run-down</strong></span></p><p>The DNS (Domain Name System) is used to map fancy hostnames to IP addresses, so for example whenever you go to <em>www.google.com</em>, the name servers <a href="http://whois.domaintools.com/google.com">listed on google.com</a> make sure that you are send to the correct <em>computer</em> so you can do your search.</p><p>My client&#39;s domain: example.org<br />The spam host: freejoin.example.org</p><p><strong><span style="font-size: 1.25em;">How did it happen?</span></strong></p><p>Everydns.net treats all domains equal, so when we put ns1 through ns4.everydns.net on the domain as authoritative nameservers, the abuser added freejoin.example.org to his account on everydns.net and added a dozen of hosts &quot;beneath&quot; it to advertise their services.</p><p>I am surprised that no one had noticed anything like that before.</p><p><strong><span style="font-size: 1.25em;">Solution</span></strong></p><p>In this case we moved the DNS to another server and that fixed the situation for us.</p><p><a href="http://david.ulevitch.com/">David Ulevitch</a>, the owner/founder of everydns.net, was notified (2008/05/04) prior to writing this blog post and he let me know that the bug is being fixed.<br /></p>   <p style="clear:both;"> 
    <a href="http://till.vox.com/library/post/hijacking-dns-with-everydnsnet.html?_c=feed-atom-full#comments">Read and post comments</a>   |   
    <a href="http://www.vox.com/share/6a00c2251d8a1b549d00f48cf52e4c0003?_c=feed-atom-full">Send to a friend</a> 
</p>

                </div>
            ]]>
        </content> 
    <category term="spam" scheme="http://till.vox.com/tags/spam/" label="spam" /> 
    <category term="security" scheme="http://till.vox.com/tags/security/" label="security" /> 
    <category term="hijack" scheme="http://till.vox.com/tags/hijack/" label="hijack" /> 
    <category term="abuse" scheme="http://till.vox.com/tags/abuse/" label="abuse" /> 
    <category term="dns" scheme="http://till.vox.com/tags/dns/" label="dns" /> 
    </entry> 
</feed>


