Expired anti-spam domain bites NZ's national stadium, Eden Park

By
Follow google news

Resurrected decommissioned domain told tales.

Key points

  • Eden Park's DNS configuration referenced an expired domain, spamcontrol.co.nz, letting consultant Alex Shakhov capture DMARC reports for a year.
  • Shakhov said the reports mapped Eden Park's infrastructure within 30 days and revealed 600 companies it communicates with, including sponsors and agents.
  • The stadium says no data was compromised and has now updated its DNS, while Fujitsu confirmed the domain belonged to a defunct anti-spam service it retired in June 2021.
Expired anti-spam domain bites NZ's national stadium, Eden Park

New Zealand's national stadium Eden Park for years did not notice that its email settings referenced an expired domain for an anti-spam service, making it possible for an attacker to silently capture potentially revealing message authentication reports.

United States-based email deliverability consultant Alex Shakhov discovered that the DMARC record in the domain name service (DNS) configuration for edenpark.co.nz contained a reference to spamcontrol.co.nz which had lapsed years ago.

That domain was used as part of the address to which message authentication reports from large email senders should be sent.

Shakhov registered the domain, set up email service for it and began to receive DMARC reports which he said provided insights into Eden Park's email infrastructure in a short period of time.

"It only took us 30 days to map their infrastructure and gain visibility into 600 companies they communicate with - sponsors, sports associations, event companies, celebrity agents," Shakhov said.

"That's the foundation for a targeted phishing campaign against every brand that trusts their brand," he wrote.

Shakhov said that multiple attempts to contact Eden Park over a year about the domain, spamcontrol.co.nz, failed.

"We spent the last 12 months reporting this to their security contacts, leadership, and IT managers through various channels, even leveraging personal connections at NZ MSPs.[managed service providers]," Shakhov said in his public disclosure on LinkedIn.

"If scammers had registered the domain, they would have known who handles their construction projects, who runs traffic control for events, which catering firm they use, how often they deal with government agencies, and who owns their sales and marketing."

The stadium confirmed the issue to iTnews but said no data was compromised.

“Eden Park takes the security of its IT systems and information seriously," the stadium's trust spokesperson Bronwynne Howse told iTnews.

"We have been in contact with the registered owner of spamcontrol.co.nz and are confident no data has been compromised.

"We have robust cybersecurity systems and processes in place, which are monitored 24/7 by our specialist IT team.

"We regularly review and update our security settings to ensure our systems continue to meet appropriate security standards and protect our information and communications," Howse added.

Eden Park has now updated its DNS to remove the reference to the expired domain following the public disclosure.

Howse did not say why the stadium did not acknowledge and act on Shakhov's earlier reports before the public disclosure took place.

A common DMARC misconfiguration

DMARC, short for domain-based message authentication, reporting and conformance, is a commonly used email security feature designed to protect domains from email spoofing.

As part of that, receiving email servers can use a reporting function to send back data on messages claiming to be from a domain, addressed to whoever published its DMARC record.

That record provides two fields, rua and ruf, for the email addresses reports should be sent to.

Forensic reports in particular can reveal sensitive data such as message content and addresses, information that could have been valuable to whoever controlled spamcontrol.co.nz, regardless of their intent.

A missing part of the puzzle was that there was no record showing who the former registrant of spamcontrol.co.nz was before Shakhov took control of the domain.

iTnews traced the expired domain name to Fujitsu's Australia and New Zealand operations through Internet searches that linked spamcontrol.co.nz email addresses to former and current staff at the technology giant.

Screenshots shared by Shakhov and sighted by iTnews show that some senior Fujitsu employees had named accounts on spamcontrol.co.nz, which to this day are sent messages from mailing lists.

As the name suggests, the domain was part of an anti-spam service that is now defunct, a spokesperson for Fujitsu Australia confirmed.

"We previously operated an email filtering service in New Zealand that was retired in June 2021 following a customer migration program," the spokesperson told iTnews.

"Customers still using the service were notified of its retirement and supported to move to alternative solutions before it was decommissioned," the spokesperson added.

The Fujitsu spokesperson said the company reviewed historical records relating to the retirement of the service and based on that, has not identified any evidence of impact to current customer systems.

Unrelated to Eden Park and spamcontrol.co.nz Shakhov said his automated scans picked up 86 domains across 20 organisations that showed a similar pattern of DMARC reports being pointed at external, expired endpoints.

A 2023 study [pdf] presented at the USENIX Security conference scanned 384 million domains and found that among the two million publishing DMARC records with external reporting addresses, 520,000, 26 percent, failed a required verification check: some because the destination domain no longer existed, others because it was missing the necessary authorisation record.

Shakhov said he would like to hand over the spamcontrol.co.nz domain to Fujitsu.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

NAB's CSO to move to ANZ Banking Group

NAB's CSO to move to ANZ Banking Group

Two Aussies alleged to be "principal participants" of TeamPCP hacking group

Two Aussies alleged to be "principal participants" of TeamPCP hacking group

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

ASD warns Australian TeamCity servers under attack

ASD warns Australian TeamCity servers under attack

Log In

  |  Forgot your password?