March 2010 April 2010 May 2010 June 2010 July 2010
August 2010
September 2010 October 2010 November 2010 December 2010 January 2011 February 2011 March 2011 April 2011 May 2011 June 2011 July 2011 August 2011 September 2011 October 2011 November 2011 December 2011 January 2012 February 2012 March 2012 April 2012 May 2012 June 2012 July 2012 August 2012 September 2012 October 2012 November 2012 December 2012 January 2013 February 2013 March 2013 April 2013 May 2013 June 2013 July 2013 August 2013 September 2013 October 2013 November 2013 December 2013 January 2014 February 2014 March 2014 April 2014 May 2014 June 2014 July 2014 August 2014 September 2014 October 2014 November 2014 December 2014 January 2015 February 2015 March 2015 April 2015 May 2015 June 2015 July 2015 August 2015 September 2015 October 2015 November 2015 December 2015 January 2016 February 2016 March 2016 April 2016 May 2016 June 2016 July 2016 August 2016 September 2016 October 2016 November 2016 December 2016 January 2017 February 2017 March 2017 April 2017 May 2017 June 2017 July 2017 August 2017 September 2017 October 2017 November 2017 December 2017 January 2018 February 2018 March 2018 April 2018 May 2018 June 2018 July 2018 August 2018 September 2018 October 2018 November 2018 December 2018 January 2019 February 2019 March 2019 April 2019 May 2019 June 2019 July 2019 August 2019 September 2019 October 2019 November 2019 December 2019 January 2020 February 2020 March 2020 April 2020 May 2020 June 2020 July 2020 August 2020 September 2020 October 2020 November 2020 December 2020 January 2021 February 2021 March 2021 April 2021 May 2021 June 2021 July 2021 August 2021 September 2021 October 2021 November 2021 December 2021 January 2022 February 2022 March 2022 April 2022 May 2022 June 2022 July 2022 August 2022 September 2022 October 2022 November 2022 December 2022 January 2023 February 2023 March 2023 April 2023 May 2023 June 2023 July 2023 August 2023 September 2023 October 2023 November 2023 December 2023 January 2024 February 2024 March 2024 April 2024 May 2024 June 2024 July 2024 August 2024 September 2024 October 2024 November 2024 December 2024 January 2025
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
24
25
26
27
28
29
30
31
News Every Day |

MasterCard DNS Error Went Unnoticed for Years

The payment card giant MasterCard just fixed a glaring error in its domain name server settings that could have allowed anyone to intercept or divert Internet traffic for the company by registering an unused domain name. The misconfiguration persisted for nearly five years until a security researcher spent $300 to register the domain and prevent it from being grabbed by cybercriminals.

A DNS lookup on the domain az.mastercard.com on Jan. 14, 2025 shows the mistyped domain name a22-65.akam.ne.

From June 30, 2020 until January 14, 2025, one of the core Internet servers that MasterCard uses to direct traffic for portions of the mastercard.com network was misnamed. MasterCard.com relies on five shared Domain Name System (DNS) servers at the Internet infrastructure provider Akamai [DNS acts as a kind of Internet phone book, by translating website names to numeric Internet addresses that are easier for computers to manage].

All of the Akamai DNS server names that MasterCard uses are supposed to end in “akam.net” but one of them was misconfigured to rely on the domain “akam.ne.”

This tiny but potentially critical typo was discovered recently by Philippe Caturegli, founder of the security consultancy Seralys. Caturegli said he guessed that nobody had yet registered the domain akam.ne, which is under the purview of the top-level domain authority for the West Africa nation of Niger.

Caturegli said it took $300 and nearly three months of waiting to secure the domain with the registry in Niger. After enabling a DNS server on akam.ne, he noticed hundreds of thousands of DNS requests hitting his server each day from locations around the globe. Apparently, MasterCard wasn’t the only organization that had fat-fingered a DNS entry to include “akam.ne,” but they were by far the largest.

Had he enabled an email server on his new domain akam.ne, Caturegli likely would have received wayward emails directed toward mastercard.com or other affected domains. If he’d abused his access, he probably could have obtained website encryption certificates (SSL/TLS certs) that were authorized to accept and relay web traffic for affected websites. He may even have been able to passively receive Microsoft Windows authentication credentials from employee computers at affected companies.

But the researcher said he didn’t attempt to do any of that. Instead, he alerted MasterCard that the domain was theirs if they wanted it, copying this author on his notifications. A few hours later, MasterCard acknowledged the mistake, but said there was never any real threat to the security of its operations.

“We have looked into the matter and there was not a risk to our systems,” a MasterCard spokesperson wrote. “This typo has now been corrected.”

Meanwhile, Caturegli received a request submitted through Bugcrowd, a program that offers financial rewards and recognition to security researchers who find flaws and work privately with the affected vendor to fix them. The message suggested his public disclosure of the MasterCard DNS error via a post on LinkedIn (after he’d secured the akam.ne domain) was not aligned with ethical security practices, and passed on a request from MasterCard to have the post removed.

MasterCard’s request to Caturegli, a.k.a. “Titon” on infosec.exchange.

Caturegli said while he does have an account on Bugcrowd, he has never submitted anything through the Bugcrowd program, and that he reported this issue directly to MasterCard.

“I did not disclose this issue through Bugcrowd,” Caturegli wrote in reply. “Before making any public disclosure, I ensured that the affected domain was registered to prevent exploitation, mitigating any risk to MasterCard or its customers. This action, which we took at our own expense, demonstrates our commitment to ethical security practices and responsible disclosure.”

Most organizations have at least two authoritative domain name servers, but some handle so many DNS requests that they need to spread the load over additional DNS server domains. In MasterCard’s case, that number is five, so it stands to reason that if an attacker managed to seize control over just one of those domains they would only be able to see about one-fifth of the overall DNS requests coming in.

But Caturegli said the reality is that many Internet users are relying at least to some degree on public traffic forwarders or DNS resolvers like Cloudflare and Google.

“So all we need is for one of these resolvers to query our name server and cache the result,” Caturegli said. By setting their DNS server records with a long TTL or “Time To Live” — a setting that can adjust the lifespan of data packets on a network — an attacker’s poisoned instructions for the target domain can be propagated by large cloud providers.

“With a long TTL, we may reroute a LOT more than just 1/5 of the traffic,” he said.

The researcher said he’d hoped that the credit card giant might thank him, or at least offer to cover the cost of buying the domain.

“We obviously disagree with this assessment,” Caturegli wrote in a follow-up post on LinkedIn regarding MasterCard’s public statement. “But we’ll let you judge— here are some of the DNS lookups we recorded before reporting the issue.”

Caturegli posted this screenshot of MasterCard domains that were potentially at risk from the misconfigured domain.

As the screenshot above shows, the misconfigured DNS server Caturegli found involved the MasterCard subdomain az.mastercard.com. It is not clear exactly how this subdomain is used by MasterCard, however their naming conventions suggest the domains correspond to production servers at Microsoft’s Azure cloud service. Caturegli said the domains all resolve to Internet addresses at Microsoft.

“Don’t be like Mastercard,” Caturegli concluded in his LinkedIn post. “Don’t dismiss risk, and don’t let your marketing team handle security disclosures.”

One final note: The domain akam.ne has been registered previously — in December 2016 by someone using the email address um-i-delo@yandex.ru. The Russian search giant Yandex reports this user account belongs to an “Ivan I.” from Moscow. Passive DNS records from DomainTools.com show that between 2016 and 2018 the domain was connected to an Internet server in Germany, and that the domain was left to expire in 2018.

This is interesting given a comment on Caturegli’s LinkedIn post from an ex-Cloudflare employee who linked to a report he co-authored on a similar typo domain apparently registered in 2017 for organizations that may have mistyped their AWS DNS server as “awsdns-06.ne” instead of “awsdns-06.net.” DomainTools reports that this typo domain also was registered to a Yandex user (playlotto@yandex.ru), and was hosted at the same German ISP — Team Internet (AS61969).

Москва

Суд приостановил производство по делу бывшего ухажера Волочковой Дюрана

Trump pardons Silk Road operator Ross Ulbricht

PFL chairman Donn Davis expects Francis Ngannou to return to boxing, still fight MMA in 2025

Ellie Scotney vs Mea Motu: Start time, TV channel, live stream, undercard for massive world title fight

‘Sack every Championship official’ blast fans as goal is ‘given’ then ruled out WITHOUT VAR as Sky Sports pundits fume

Ria.city






Read also

‘BLKNWS: Terms & Conditions’ Pulled From Sundance and Berlin Over Director’s Alleged ‘Secret’ Cut

A New Day in Federal Anti-Discrimination Law

I took my kids to Venice for the first time. Our trip would've been better if we'd avoided these 5 mistakes.

News, articles, comments, with a minute-by-minute update, now on Today24.pro

News Every Day

PFL chairman Donn Davis expects Francis Ngannou to return to boxing, still fight MMA in 2025

Today24.pro — latest news 24/7. You can add your news instantly now — here


News Every Day

The Best Movies From Every Genre On Hulu (Jan 20 – 31)



Sports today


Новости тенниса
Australian Open

Д. Шнайдер вышла в третий раунд Открытого чемпионата Австралии в парном разряде



Спорт в России и мире
Москва

Завершен первый этап благоустройства территории около станции Кусково МЦД-4



All sports news today





Sports in Russia today

Москва

Завершен первый этап благоустройства территории около станции Кусково МЦД-4


Новости России

Game News

GDC's annual State of the Game Industry survey reveals 1/3 of 'triple-A developers' are working on live service games


Russian.city


Москва

Ремикс Песни. Создание ремикса Песни. Создание Хитового ремикса песни.


Губернаторы России
Домодедово

В городском округе Домодедово проведена агитационно-разъяснительная работа с населением о сохранности имущества.


В 2024 году 283,4 тысячи женщин и новорожденных Московского региона получили услуги по родовым сертификатам

Звук, который дает преимущество: новая игровая гарнитура Bloody G565

Александр Петров показал Москву мексиканской актрисе Барбаре де Рехиль

С начала 2024 года Отделение СФР по Москве и Московской области оплатило пособия по временной нетрудоспособности 2,9 млн жителей региона


Баста — о съемках нового сезона шоу «Голос»: «Я бы не пришел на конкурс как участник»

На должность директора Уссурийского локомотиворемонтного завода назначен Александр Корчемлюк

К 100-летию со дня рождения Ираиды Утретской в Мариинке пройдет показ балета «Бахчисарайский фонтан»

Денис Мацуев: “Музыка невероятно развивает мозг”


Джокович: Это был один из самых эпичных матчей, которые я проводил

Джокович не дал Алькарасу собрать карьерный Большой шлем в 2025-м

Маск поддержал бойкот интервью Джоковичем на Australian Open

Алькарас: Уезжаю из Австралии с гордо поднятой головой



С начала 2024 года Отделение СФР по Москве и Московской области оплатило пособия по временной нетрудоспособности 2,9 млн жителей региона

С начала 2024 года Отделение СФР по Москве и Московской области оплатило пособия по временной нетрудоспособности 2,9 млн жителей региона

В Подмосковье сотрудники Росгвардии задержали подозреваемого в краже денежных средств с чужой банковской карты

Стамбульский мажор на перевоспитании: Радио Romantika рекомендует «Холоп. Великолепный век»


Гандболисты в Москве проиграли ЦСКА

Театр "Модерн" вновь покажет пронзительную драму «Человек с глазами Моцарта»

Сергей Собянин: Благотворительная деятельность не имеет формальных границ

Уборка снега в Южно-Сахалинске 20 января - список улиц


SHOT: суд обязал Блиновскую вернуть банку 569 млн рублей

Русско-испанский разговорный клуб объединил подростков из стран Латинской Америки и Европы

Объём закупок на портале поставщиков превысил 120 млрд рублей в 2024 году

Эксперт Гущин: Сирия потребовала от России деньги за присутствие в Тартусе



Путин в России и мире






Персональные новости Russian.city
Анастасия Волочкова

«Простили друг другу обиды»: Анастасия Волочкова рассказала о здоровье отца и зависти матери



News Every Day

PFL chairman Donn Davis expects Francis Ngannou to return to boxing, still fight MMA in 2025




Friends of Today24

Музыкальные новости

Персональные новости