Specifically, watchTowr researchers were able to receive a verification link for any domain ending in .mobi, including ones they didn’t own. The researchers did this by deploying a fake WHOIS server and populating it with fake records. Creation of the fake server was possible because dotmobiregistry.net—the previous domain hosting the WHOIS server for .mobi domains—was allowed to expire after the server was relocated to a new domain. watchTowr researchers registered the domain, set up the imposter WHOIS server, and found that CAs continued to rely on it to verify ownership of .mobi domains.
So, it was a takeover attack for a TLD registry that wasn’t properly retired…
For comparison, Voyager 1 is almost 24.8 billion km away from Earth right now and has been traveling since 1977 (near on 50 years).
Haven’t read the article yet, but if the headline is anything to go by, very cool if it can be done.
Edit:
Just read the article. Disappointingly but unsurprisingly: