DEV Community

Jason Miller
Jason Miller

Posted on Originally published at axeploit.com

Someone Claimed a Dead DNS Record and Got Military Base Call Logs by Morning

No malware. No stolen credentials. Someone registered an orphaned phone-routing DNS record, and by the next day their system held records of hundreds of thousands of calls to US military bases. If your threat model only accounts for attackers, this one should bother you.

Security practitioner Wiktor Stefański summarized the mechanism: "No hack. No breach. Just a bit of DNS that nobody owned, so they registered it." Public detail beyond his summary is thin, so treat the specifics as reported rather than confirmed. But the failure shape is real, and telecom people have warned about this exact class of accident for years.

How a DNS record ends up holding your call logs

Modern telephony is name lookups all the way down. SIP proxies resolve NAPTR, SRV, and A records to find the next hop. ENUM maps phone numbers themselves into DNS under e164.arpa. Separately, every SBC and softswitch exports call detail records to a hostname someone typed into a config file, possibly years ago, possibly by an engineer who has since left.

Records lose owners quietly. A carrier migrates platforms and the old domain lapses. A vendor contract ends, the hosted SBC is decommissioned, but a CNAME still points at it. The organizational seam makes it worse: telecom config belongs to one team, DNS to another, the vendor contract to procurement. Nobody owns the record in the middle, so nobody renews it.

One routing record can front an entire number block. That is how a single registration produces hundreds of thousands of records overnight instead of a trickle. Nothing pages when a log destination changes hands. Calls kept completing. The only symptom was data arriving somewhere new.

"No content" is a weak comfort

Metadata analyzes better than content. It is structured data that scales and never needs translation. A month of CDRs yields a cleaner network graph than a year of intercepted audio.

What does an analyst read in base call records? Volume rhythms that track operational tempo, with off-hours upticks often preceding exercises or deployments. Recurring calls to logistics firms, fuel suppliers, or medical providers that sketch support relationships never made public. Calling trees between command numbers that reveal escalation flow. You can reconstruct a working org chart without hearing a single word.

"We are not a military base" does not save you. Your calls cross the same plumbing. Merger talks, layoff planning, and your real customer list are all visible in call patterns to whoever holds your CDRs. And once a stranger holds months of your traffic, takedown requests do not rewind analysis already done.

Audit your call path this week

Pull every hostname your phone system trusts: SBC and PBX configs, provider portal settings, voicemail relays, RADIUS accounting targets, every CDR export destination. Then verify what each resolves to today, not what the config author intended:

dig SRV _sip._udp.yourdomain.com
dig NAPTR 1.2.3.4.5.5.5.1.2.0.2.e164.arpa

# Flag anything in your inventory that no longer resolves
while read -r name; do
  ips=$(dig +short "$name" A)
  [ -z "$ips" ] && echo "UNRESOLVED: $name" || echo "$name -> $ips"
done < telephony-dns.txt
Enter fullscreen mode Exit fullscreen mode

Any hostname landing outside your or your carrier's known netblocks is an incident, not a curiosity. Check expiry on every domain in the path via RDAP, and put auto-renew plus registrar lock on anything routing-critical.

One more detection worth building: alert on a sharp drop in daily CDR volume at your collector. A silent falloff can mean the stream found a new home.

Do this week:

  • Resolve every hostname in your call path and flag anything outside known netblocks.
  • Registrar-lock and auto-renew domains fronting number blocks, with expiry alerts at 90, 60, and 30 days.
  • Ask your provider who owns your phone-routing DNS, where CDR exports go, and how long they keep logs. Get it in the contract.
  • If you find a dangling record: contain first, scope second, notify third.

Question for the comments: who at your org actually owns the DNS records your phone system depends on, and when did anyone last check?

Longer writeup with the full argument: https://axeploit.com/blog/a-forgotten-dns-record-just-handed-a-stranger-hundreds-of-thousands-of

Top comments (0)