Computers

Google: Attackers Hijacked 3 ccTLDs to Forge TLS Certificates

Google says attackers abused control of .gh, .sl and .as authoritative DNS records to obtain unauthorized certificates for its domains, and Chrome now blocks them.

Google disclosed that attackers hijacked three country code top-level domains — .gh, .sl and .as — and modified authoritative DNS records for selected domains, according to Ars Technica.

The attackers used that DNS control to pass automated domain control validation checks, which allowed them to obtain unauthorized TLS certificates for several Google domains and for domains belonging to other organizations.

Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to revoke the unauthorized certificates for Google properties.

What domain owners are advised to do

Google advised domain owners to monitor certificate transparency logs and to publish restrictive Certification Authority Authorization DNS records.

Quick answers

Which domains did the attackers hijack?

Google said the attackers hijacked the .gh, .sl and .as country code top-level domains and modified authoritative DNS records for selected domains.

What did Google do about the unauthorized certificates?

Google updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to revoke the unauthorized certificates for Google properties.

How can domain owners protect themselves?

Google advised domain owners to monitor certificate transparency logs and publish restrictive Certification Authority Authorization DNS records.

Source