A researcher successfully hijacked e164.arpa domains, which are part of the infrastructure for phone networks. This allowed them to intercept and log data related to phone calls, including those directed to military bases. The researcher previously reported similar takeovers of .gov and .edu domains.
e164.arpa, also known as ENUM, was conceived in the early 2000s as a method to route phone calls over the internet using DNS. It translates phone numbers into domain names (e.g., +49 30 123456 becomes 6.5.4.3.2.1.0.3.9.4.e164.arpa). The intention was for carriers to use these domains to find SIP/VoIP addresses, bypassing traditional, more expensive phone networks.
The ENUM system never gained widespread adoption and has largely deteriorated over the years, with minimal current use. Despite its obsolescence, some countries, like Germany, still technically allow the registration of e164.arpa domains. The researcher noted that while RFCs specify only NAPTR records for call routing, nothing prevents hosting websites or other services on these domains, creating a potential for misuse.
The successful hijacking and logging of calls, including those to military bases, demonstrates a vulnerability in this neglected part of the internet's infrastructure. Although the system is largely defunct, its continued existence and the ability to register and control these domains present a security risk, as they can be exploited for data interception or other malicious activities.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A researcher demonstrated how DNS hijacking of e164.arpa domains, intended for phone network infrastructure, allowed them to log hundreds of thousands of phone calls to military bases. This highlights a vulnerability in an outdated but still active part of the internet's phone routing system.