News Update – The Corp.com Conundrum
TL;DRMike O'Connor bought corp.com in 1994 and held it for 26 years because Windows PCs using default Microsoft Active Directory configs leaked corporate passwords and data to it. He sold it in 2020, with Microsoft as the likely buyer.
Jordan & Scott discuss the the very nerdy story of the website that lets you read secrets and the man who kept it safe.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: It's 1994, and Mike O'Connor has just scooped up some choice web domains. One of which comes with a very strange responsibility. Back in '94, buying domains and really the Internet in general was a chaotic place. ICANN, the Internet corporation for assigned names and numbers, the big organization that oversees domain registries, didn't even exist until 1998. So way before what O'Connor calls the domain name land rush, before cyber squatters, before websites and domains were worth something, Mike buys up a few. Mike buys them because they reminded him of radio station names. They seemed like they might be useful. Mike O'Connor buys up a bunch of one word domains in 1994, and he gets some good ones. And if you know anything about cyber squatting and domain investing, brace yourself. MikeBot, amongst others, television.com, place.com, bar.com, cafe.com, have.com, shelter.com, and company.com. For context, if we go over to Estebot, a service that creates quick estimates of how much domains are worth, we see that all by itself, television.com, this one little domain, is worth at least 1,083,000 US, and that is just one. So, good for Mike. But in all that time, there's been this one domain that Mike has refused to sell. He's held onto it for twenty six years because this domain is dangerous. Corp, corp,.com is a Pandora's box. And for reasons that we will explain, whoever owns that domain possesses a very uneasy power. Because of an issue affecting networked Windows PCs called Namespace Collision, whoever owns corp.com gains access to a never ending flood of passwords, emails, and proprietary data from hundreds of thousands of major companies around the world. All day, every day, for twenty six years. Whoever owns that domain owns a floodgate of secrets that if it were to fall into the hands of either cyber criminals or state actors, would expose a bottomless well of private information that you could never claw back. This year, Mike turned 70, and he decided it was time to sell. And this week, this story, twenty six years in the making, finally reached its conclusion. We don't know how much Mike sold corporate.com for, but we know his starting price was $1,700,000. This is a quick explanation of how corp.com worked on this Hacked Update. I think we're getting in the weeds in this episode. This sounds like it's gonna be pretty esoteric. I
Speaker 2: think we're living in the domain name service headspace for a while here. It seems like this is one of many updates that revolve around DNS configurations and how it makes us vulnerable.
Speaker 1: Before we get to corp.com I've been saying corp.com. Core? Corp. Corp. That's what I'm
Speaker 2: gonna say. Short for corporation.
Speaker 1: That's what I thought. Yeah. Before we get to that, remind people what DNS is.
Speaker 2: DNS is the system that allows us to type google.com into our web browser, and it knows the IP address of the server it's trying to reach. That's what DNS does.
Speaker 1: So it's like a big index.
Speaker 2: Yeah. It's like a big phone book.
Speaker 1: Cool. Now that we've got
Speaker 2: that People don't know what phone books are anymore.
Speaker 1: So that having been said, what is corp.com?
Speaker 2: Corp.com is just a DNS name like anything else. Same as Google. Same as hackpodcast.com. Name is patreon.com/hackpodcast.
Speaker 1: And what makes it special?
Speaker 2: A configuration vulnerability by default in early active directory servers from Microsoft. Is that a good answer?
Speaker 1: I feel like I should let people know that next week's episode, it's it's gonna be poppy. It's gonna be, like, sextortion scams. It's gonna be real provocative stuff. So if if the in the weeds stuff isn't for you, we totally get that. But while we're here, just can you can you explain this?
Speaker 2: I'll I'll let me just explain this for you. Major corporations that run the Microsoft stack, stack being all the Microsoft major corp products, use something called active directory to control user login, sign ins, and a bunch of other things. It's kind of like the key chain for the corporation. So that active directory servers, when they used to came out, like, you know, Microsoft small business server and stuff like this dating way back to when this problem probably originated, used to kinda come with a default example setup for a corporation called Corp. But in the world of of Microsoft and in the world of these new active directory kind of controlled PCs that connected to this directory, corp would become corp.com, except for that the internal DNS would overwrite it to whatever it needed to be internal to the corporation. So then when you take these PCs out of the corporation, out of the network where they have direct access to their stuff, pre kind of massive rollouts of VPNs. Anytime that these computers tried to access a local resource, it would think it was looking for something somethingsomething.corp.com. So all of that traffic, logins, email server requests, all of this stuff was getting spilled out to this random DNS that this guy owned called corp.com. So in the weeds, it all revolves around Microsoft trying to set up a comprehensive enterprise solution, showing people how to set up their first installation of this active directory and a bunch of other, you know, assets inside of the the Microsoft stack and doing it under a pretense of a kind of an example corporation colloquially known as Corp. So all of those IT admins who just kind of adopted the example setup up inherited this problem. So, you know, again, these are probably and this is is, you know, a big assumption, but I'd say a lot of these were smaller to medium businesses where they didn't have huge IT infrastructures. Maybe there's one IT manager taking care of the whole 400 person, you know, company. And there's just some misconfiguration issues in setup that led to long term vulnerabilities.
Speaker 1: Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.
Speaker 2: This is
Speaker 1: kind of the equivalent of, something's default password being set to password, the person not changing it, and introducing a vulnerability. Yeah. A little.
Speaker 2: A little bit. Yeah. It's a lot more crazy complicated and will require a lot more stuff to manipulate and Right. Take advantage of it. But yeah.
Speaker 1: Instead of a password, it's this destination.
Speaker 2: It's like a teaching a bunch of, you know, teaching a bunch of computers that when they need to do things, look up DNS entries, send emails, you know, the list goes on, log in to the network, that they need to go to this place to do it Mhmm. And then changing that place.
Speaker 1: What if Mike had sold it? For thirty years, this guy's been holding on to the destination of all of this rogue traffic. What if he had decided, I'm just gonna sell this thing to the highest bidder?
Speaker 2: Oh, I think Microsoft would have had something to say about it. Yeah. I I can't imagine I don't know. That's a great question. I I can't imagine they would have let it go rogue. I actually am surprised it took them this long to close it down. And it's probably only because Mike was so innocent in this and so, like, altruistic that that they didn't have to deal with it earlier.
Speaker 1: When it said the story of its availability was, I think, quite public. It was pretty widely covered that this domain was kind of up in the air all of a sudden, that Micah decided to, you know, liquidate his estate and that this was gonna be purchasable, and that he wanted Microsoft to buy it.
Speaker 2: Yeah. Yeah. I think I think when you talk about the biggest bidders, I think Microsoft is the obvious one. I'm sure you could've convinced some Russian state organization to buy it, but, you know, at the end of the day, he might go to jail for that one. Yeah. I think it's I think it's good. I'm glad Microsoft bought it. They can, you know, button it up, lock it down, make sure nothing happens with it. And, good for Mike for being so altruistic all of those years or seeming to be so altruistic after all those years. So, yeah, I'm I'm glad it's resolved. There's gonna be, you know, millions of more instances of this. When you teach a computer how to look for, you know, DNS short handles, like, you know, immediately anytime somebody types something into the file explorer bar. When it does a network search, it attaches somethingsomething.com onto the end of it. You're creating a perpetual vulnerability.
Speaker 1: Thanks for listening, everybody. I think this is our record for the shortest news update yet. We're gonna be back next week. Got an interesting update lined up I think you're all gonna like. You can follow us on Twitter at hacked podcast or support the show at patreon.com/hackedpodcast. Thank you for listening, and thanks to Mike O'Connor for keeping it real.
Speaker 3: The biggest tournament in soccer is finally here, and I've already started planning my watch parties. My go to move before kickoff is stopping at Total Wine and More to grab drinks for the whole crew. Wine, beer, seltzers, maybe a few ready to drink options. Everything we need for a full day of matches. With this many games, it definitely helps knowing you're getting the lowest prices. Total Wine makes it so easy because I can grab everything I need in one stop. Get match day ready with Total Wine and More today so you're set from kickoff to the final whistle. Spirits are not sold in Virginia and North Carolina. Drink responsibly. Must be 21.