Reply to post: How did the crims create the sub-domain?

Trend Micro: Internet scum grab Let's Encrypt certs to shield malware

Chris Robinson

How did the crims create the sub-domain?

"the attackers compromised an unnamed web server, created their own subdomain for the server's website"

For them to create a sub-domain they would need to also compromise the authoritative name server, unless the DNS was hosted on that same web server that they rooted - which is a bad idea anyway. The DNS should be separate and independent.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon