Skip to main content
Philippe Caturegli

Philippe Caturegli

Chief Hacking Officer

Seralys

About

Philippe started his hacking career in the 1990s with a multi-node hacking/phreaking BBS in his parents' basement. Over the past 30 years, he has worked across all sides of security: defending large enterprise networks, advising financial institutions, and ultimately following his passion for breaking things as a penetration tester and vulnerability researcher.

Sessions

I own your "internal" domain… Weaponizing name collisions at scale

What you will learn:

What happens when your internal domain name is actually registered and operated by someone else? You start leaking credentials, email gets misrouted, deployment pipelines pull code from untrusted places, and most of the time, you don’t even notice for years. With over 1,200 new TLDs introduced over the past decade, many organizations are unknowingly using internal domain names that now exist as valid, publicly registrable FQDNs that they don’t own and never thought to claim. Name collision itself is not new. It has been documented as a theoretical risk since 2013. But no one has studied it at scale, or answered simpler questions: how could threat actors identify a potential collision and what would be the impact if they claimed a colliding domain and operated it? We analyzed nearly 39 million SSL certificates and over 9.5 million services to surface internal names leaking onto the public internet, found more than 92,000 colliding domains that nobody had registered. We then decided to claim 200 of them. Over two years, those domains passively recorded more than 11 billion DNS requests. And when we started answering some of those queries, web requests, email, credentials, auth tokens, build artifacts and much more started flowing in. The affected organizations ranged from police departments and airports to Fortune 500 companies, enterprise software vendors, and critical infrastructure. We’ll walk through how these collisions were discovered, what happened after claiming the domains, why organizations kept leaking data for months/years, and what happened when we tried to report it. Between radio silence and legal threats, the disclosure process turned out to be almost as revealing as the technical findings themselves.