indianajson/can-i-take-over-dns

UltraDNS

indianajson opened this issue · 7 comments

Service UltraDNS

Status Not Vulnerable

Nameserver

pdns***.ultradns.com
udns***.ultradns.com
sdns***.ultradns.com

All DNS nameservers under ultradns.com run off the same list of zones, thus a zone with NS udns34.ultradns.com will still get resolved by pdns148.ultradns.com.

Explanation

While accounts start at $30 per month and can be created by adding a service to your cart via this page UltraDNS has built internal detection to limit/stop DNS takeovers using their service.

Credit

Special thanks to @m0chan for investigating this and getting us an answer!

This is no longer possible, UltraDNS patched the issue & built internal detection.

Thanks for sharing, @m0chan! I'll update this right away.

@m0chan Do we know what kind of built-in protection is being used?

edns83.ultradns.net.
edns83.ultradns.com.
edns83.ultradns.org.
edns83.ultradns.biz.
what about this fingerprint?

edns83.ultradns.net.

edns83.ultradns.com.

edns83.ultradns.org.

edns83.ultradns.biz.

what about this fingerprint?

Good question. I haven't been able to get an account to test double check this as of yet.

So we can't takeover ultradns nameservers?

@aravindb26 As far as I am aware, no, however, feel free to open a paid account and test it yourself. If you find you are able to perform a takeover I'll definitely update this thread.