briankrebs ,
@briankrebs@infosec.exchange avatar

At least a dozen organizations with domain names at domain registrar Squarespace saw their websites hijacked last week. Squarespace bought all assets of Google Domains a year ago, but many customers still haven’t set up their new accounts. Experts say malicious hackers learned they could commandeer any migrated Squarespace accounts that hadn’t yet been registered, merely by supplying an email address tied to an existing domain.

From the story:

"...an analysis released by security experts at Metamask and Paradigm finds the most likely explanation for what happened is that Squarespace assumed all users migrating from Google Domains would select the social login options — such “Continue with Google” or “Continue with Apple” — as opposed to the “Continue with email” choice.

Taylor Monahan, lead product manager at Metamask, said Squarespace never accounted for the possibility that a threat actor might sign up for an account using an email associated with a recently-migrated domain before the legitimate email holder created the account themselves.

“Thus nothing actually stops them from trying to login with an email,” Monahan told KrebsOnSecurity. “And since there’s no password on the account, it just shoots them to the ‘create password for your new account’ flow. And since the account is half-initialized on the backend, they now have access to the domain in question.”

https://krebsonsecurity.com/2024/07/researchers-weak-security-defaults-enabled-squarespace-domains-hijacks/

ALT
  • Reply
  • Loading...
  • briankrebs OP ,
    @briankrebs@infosec.exchange avatar

    Also from the story, a serious warning to people who previously purchased Google Workspace accounts via Google Domains (which are now Squarespace):

    "If you bought Google Workspace via Google Domains, Squarespace is now your authorized reseller," the help document explains. "This means that anyone with access to your Squarespace account also has a backdoor into your Google Workspace unless you explicitly disable it by following the instructions here, which you should do. It’s easier to secure one account than two."

    neurovagrant ,
    @neurovagrant@masto.deoan.org avatar

    @briankrebs ...did not expect that to be the mechanism. Wow.

    In case folks are interested, we ( @DomainTools ) uploaded all DNS records observed for about a hundred sites listed by the cryptocurrency community as vulnerable, going back to 2024-07-01. Hopefully it helps some investigators and blue teamers.

    (Inclusion does not necessarily indicate compromise.)

    https://cti-grapevine.com/web3-related-domain-takeovers/

    https://github.com/DomainTools/SecuritySnacks/tree/main/2024/DeFiDNS

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • test
  • worldmews
  • mews
  • All magazines