You can Watch Angel Has Fallen Onlinepretend to be anyone on the internet. Even the mayor of a small town.
A security researcher did just that and acquired an official .gov domain name, which could have been used to spread fake emergency alerts or ask Facebook for private user information.
The researcher successfully registered the domain name exeterri.gov after posing as the mayor of the Exeter, Rhode Island — a small town with a population of less than 6,500 people.
According to the individual, who reached out to cybersecurity reporter Brian Krebs of Krebs on Security, all they had to do was set up a fake Google Voice number and Gmail address, both completely unaffiliated with the town. After that, they filled out an official authorization form, which basically asks for the same contact information a registrar like GoDaddy or Namecheap would require.
The documents needed to be printed on the town government’s official letterhead, which the researcher obtained by searching for other official Exeter documents online.
According to a town clerk from Exeter, the only inquiry the city received from the GSA came 10 days after the researcher’s fake registration was approved. And the GSA only called Exeter after Krebs on Security asked about the domain.
While the exeterri.gov domain has since been revoked, this case exposes serious flaws in the system that could be used for nefarious purposes.
For example, the researcher was able to sign up for Facebook’s law enforcement subpoena request system, which provides law enforcement and government entities with personal user records.
“GSA is working with the appropriate authorities and has already implemented additional fraud prevention controls,” said the agency in a statement to Krebs on Security.
Before it was taken down, the researcher's .gov domain displayed the same content as the official Exeter website. It’s not hard to imagine someone using the fake site to spread fear through terror alerts, or ruin reputations with false arrest records, or post inaccurate voting information to sway an election.
Sure, that be considered wire fraud or criminal impersonation. But some people — say, foreign entities — might be willing to risk prosecution.
Initially, .gov domain names were only open to federal U.S. institutions. Now they're open to state and local governments. Last month, a bill was introducedin Congress to improve oversight over government domains by the Cybersecurity and Infrastructure Security Agency.
Topics Cybersecurity Government Politics
The 'Sad Kermit' meme will crush your hopes and dreams foreverSnowden tells Twitter CEO hate speech can be countered with 'more speech'People are using Kanye West lyrics to diss Kanye West in the wake of his Trump Tower visitGenius woman hacks fridge to dispense wine instead of waterElon Musk says Tesla pickup will look like it 'came out of a sciHow a pair of leather trousers reduced the government into a bunch of 'Mean Girls''Dark Phoenix' has the worst opening of the XThe biggest trailers and news from Ubisoft's E3 2019 press conferenceElon Musk says Tesla pickup will look like it 'came out of a sciU.S. embassies defy State Department and continue to rock Pride flagHayley Kiyoko on connecting artistry and identityLyft's bikeSinging cartoon whale is the cutest send off ever for New Zealand PM, ehBam Bam the dog steals the show at Ubisoft's E3 press conferenceAirbnb says it's down to play by the rules in Australia, as regulation loomsMan sparks possibly the world's greatest Wiki photo caption battle'Russian Doll' renewed for second season at NetflixAirbnb says it's down to play by the rules in Australia, as regulation loomsThere's a deepfake of Zuckerberg on Instagram. Your move, Facebook.Meet the woman who quit her NYC job to run a baby goat sanctuary Elon Musk visits Shanghai to announce first Tesla factory outside U.S. Activists create hidden Pride flag in Russia to protest anti 'Top Gear' season opener fails to fire on all cylinders Prankster students streamed porn on their high school cafeteria's TV Justin Trudeau raises Pride flag at Canadian parliament for the first time Dan Rather on Trump's media bashing: 'I felt a shudder down my spine' England fan gets soccer player's face tattooed on his chest after making Twitter promise Snapchat is making it easier to find lenses created by other users Things got real weird at the Libertarian National Convention Hackers steal $23.5 million from cryptocurrency exchange Bancor The KLM Care A photo of Thai Navy SEALs has gone viral after rescue Man in massive penis costume sneaks onto live CNN broadcast Brits plan cheeky 'American Idiot' protest for Trump visit Lando is back in Star Wars Episode IX, report says 5 ways to fight Trump's Supreme Court pick, Brett Kavanaugh Hacked construction signs alert motorists to breaking news: Trump is a 'lizard' Elon Musk's mini submarine may be too late to help rescue Thai boys Timehop hacked: Names, emails, phone numbers stolen Everything we know about the low
1.6089s , 8199.9921875 kb
Copyright © 2025 Powered by 【Watch Angel Has Fallen Online】,Inspiration Information Network