A €5 expired domain handed a researcher DNS control over three territories' phone routing
Original source
I accidentally logged hundreds of thousands of phone calls to military bases
Hacker News →ENUM (e164.arpa) is a largely abandoned early-2000s scheme that maps phone numbers to DNS records so carriers can route calls over VoIP instead of the legacy phone network. Scanning these neglected zones, a researcher found three country-code delegations — +290 (Saint Helena), +246 (Diego Garcia / British Indian Ocean Territory), and +247 (Ascension Island) — all pointing at two nameservers. One subdomain no longer resolved, and the fallback nameserver’s domain had lapsed. Registering that expired domain for €5 gave the researcher authoritative DNS control over all three zones, meaning they could answer any ENUM routing query however they liked — including pointing calls at their own SIP server to sit invisibly in the middle of live conversations with a spoofed caller ID.
Initial logging on the Saint Helena zone showed zero traffic, and repeated reports to the British government and RIPE went nowhere — RIPE declined because e164.arpa delegations sit under an ITU-T committee at the UN, a jurisdictional dead end nobody wanted to touch. Assuming the system was truly dead, the researcher kept the domains and hosted personal services on them. Six months later, logs on the other two zones told a different story: hundreds of thousands of ENUM queries, almost all for Diego Garcia and Ascension Island, from mostly American resolvers. Because each query name is just a reversed phone number, the logs exposed full numbers, timestamps, and resolver IPs for calls to sensitive military installations.
The practical exposure was metadata rather than intercepted audio — the server returned NXDOMAIN, so calls fell back to the normal phone network — but a hostile actor in the same position could have quietly MITM’d every routed call for months. The researcher deleted the logs and shut the server down. Only after a second disclosure to the UK’s NCSC that explicitly named the military bases did anyone act, and even then the abandoned delegation was hard to fix because no one could identify who originally created it, running straight back into the same ITU governance bottleneck. The episode is a sharp reminder that dead infrastructure protocols never fully die — they rot into single points of failure that a lapsed domain registration can hand to anyone.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.