3 pointsby alexshakhov5 hours ago1 comment
  • alexshakhov4 hours ago
    Last year I scanned DNS zones of NZ organizations, and figured out there were a few companies with unregistered domains sitting under DMARC rua/ruf tags. The Eden Park national stadium was the biggest find, so I went ahead to report it to their team same week.

    I use multiple channels to get in touch with anyone at Eden Park, but nobody has ever responded to me. A few people from the leadership team connected with me on LinkedIn, but DMs remained ignored too.

    To confirm the exposure, I set up a catch-all email address and implemented the external destination verification record to be able to receive DMARC reports for edenpark.co.nz at spamcontrol.co.nz.

    A month later, I mapped their infrastrucure, got a list of tools and IPs they use, as well as the companies they communicate with (through the envelope-to tag, that Microsoft adds to aggregate reports).

    Then I added a content compliance policy on the server, to block all inbound traffic hitting spamcontrol.co.nz.

    A year later I posted about it on Linkedin and the post went viral. Eden Park fixed the DMARC within the 24 hours, and a journalist reached out.

    He helped to identify the original owner of spamcontrol.co.nz - it turned out it was Fujitsu NZ, and they were responsible for Eden Park security a few years ago. One day they decided to sunset the domain, but forgot it was still in the Eden Park's DNS.

    The Fujitsu team reached out to me earlier this month and today I finally initiated the domain transfer, so the case is now cliosed.