Researcher will control all of the websites .io-domain name
By a beveiligingsblunder was for a researcher to be possible to gain control over all domain names that end in the extension .io.
The researcher, Matthew Bryant, found out that he is the so-called name servers .io domain could register reports The Register. Which name servers to be used to website visitors to the correct page.
For about 85 euro per piece of took Bryant four of the seven nameservers. So he had a lot of visitors .io-web sites to a private page can send, for example, malicious software to spread. Despite a direct mention of the problem was Bryant a day the control over the servers.
Because some name servers are still in the right hands, and because website visitors is not always required to use a name server, had Bryant not all visitors of .io-pages to redirect to. Still had the leak on a large scale can be used.
The .io-domain is used primarily by startups in the tech industry and contains over 270.000 active addresses.
The name servers appear available become then the administrator of the .io-domain certain activities handed over to another company. However, the administrator has the control over three of the seven name servers, but the other seven will be available for registration.