news.mlab.sh
Back to the feed
threat-intel

Content Delivery Exploit Opens Websites to Brand Hijacking

High
Summary

This article details a new exploit, dubbed "Underminr," that leverages vulnerabilities in Internet infrastructure to allow attackers to hijack websites and conceal malicious activity. The technique, a successor to domain fronting, exploits the siloed nature of DNS and CDN systems, enabling attackers to route traffic through trusted websites while performing nefarious actions. Approximately 42% of websites globally are vulnerable, with a significant concentration of risk in the US and Eastern Europe.

The Underminr exploit represents a significant risk to online security due to its ability to bypass traditional security measures. Attackers utilize this technique by manipulating DNS and CDN requests to route traffic through legitimate websites, effectively masking their malicious intent. This is achieved by exploiting the lack of cross-referencing between DNS and CDN systems, allowing attackers to insert malicious destinations into the HTTP Host header and SNI fields during the TLS handshake. This manipulation is often undetected by protective DNS filters and CDN providers, leading to widespread vulnerability.

Read the full article at Dark Reading