Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Security Infrastructure

Check Point Fails to Renew Domain Name CheckPoint.Com

Network security firm Check Point made a big mistake this week, forgetting to renew the company’s primary domain name, CheckPoint.Com. When attempting to visit the company’s Web site at 6:55AM ET on Tuesday, my Web browser directed to a splash page for domain registrar Network Solutions. (see screenshot)

Network security firm Check Point made a big mistake this week, forgetting to renew the company’s primary domain name, CheckPoint.Com. When attempting to visit the company’s Web site at 6:55AM ET on Tuesday, my Web browser directed to a splash page for domain registrar Network Solutions. (see screenshot)

Mistakes like this happen frequently, but not often to companies of this size. For a vendor of Check Point’s stature, a leading security firm with a market cap topping $13 Billion, this is simply unacceptable.

CheckPoint.ComWhen a domain name expires, all domain services essentially become null and void, and requests won’t be directed to where they are supposed to, resulting in email failing to be delivered, web sites becoming in accessible, and in the case of software or hardware updates, failure to retrieve those updates from update servers if they were set to update on a domain ending in .checkpoint.com.

As SecurityWeek columnist Ram Mohan wrote back in December 2011, “Domain names are used a trillion times every day. They’re part of the plumbing of the Internet and, like regular plumbing, you don’t need to worry too much about how it works…it just does. Until it doesn’t.”

“Every webmaster’s worst nightmare is to discover a website has gone offline because of his own dumb mistake. Forgetting to renew a domain name can be embarrassing (and costly), but it’s not the end of the world,” Mohan added.

When a domain expires, they are typically not deleted for 80 days, but in the meantime you lose any services that rely on the domain name.

While the company did say it responded to the issue quickly, depending on where people are located and the DNS servers they are using to resolve domain names, the “outage” could last for hours. Another factor would be what limit Check Point has set as a TTL (Time to Live) for the domain, a setting which tells other DNS servers how often they should check back to get any updated DNS records. A longer TTL, for example, would cause any updates to take longer to propagate across the Internet.

The company appears to have registered the domain now through March 30, 2015. Friendly reminder to domain admins at CheckPoint– Set an outlook reminder to “Renew Domain Name” on or before March 29, 2015.

According to a statement from the company, action was taken within 23 minutes, but again, depending on TTL settings and where users are located, the refresh time could be, and appears to be taking much longer. The company said it renewed the domain around 1:30PM UK time, but the following morning, the domain still redirects to the Network Solutions home page for me.

Advertisement. Scroll to continue reading.

According to John Leyden at The Register, the company blamed the issue on Network Solutions sending the renewal notices to the wrong email address.

While Network Solutions may have sent the notice to a different address than CheckPoint wanted them to, it sent notices to what the company had listed in its domain registration. Due to the high volume of spam that comes with being listed as a domain contact, many companies use email addresses that are not often checked as a domain name contact.

At the time of this writing, the DNS resolution for www.checkpoint.com is still directing to Network Solutions, and I’m not alone, a quick search on twitter shows that many users are still experiencing the same issue.

Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Management & Strategy

Hundreds of companies are showcasing their products and services this week at the 2023 edition of the RSA Conference in San Francisco.

Security Infrastructure

Security vendor consolidation is picking up steam with good reason. Everyone wants to improve security efficiency and effectiveness while paying for less.

Cloud Security

The term ‘zero trust’ is now used so much and so widely that it has almost lost its meaning.

Security Infrastructure

Instead of deploying new point products, CISOs should consider sourcing technologies from vendors that develop products designed to work together as part of a...

Funding/M&A

Responding to Cyber Threats Against Critical Infrastructures: Wired Business Media Acquires Long Running ICS Cybersecurity Conference Series

Security Infrastructure

Comcast jumps into the enterprise cybersecurity business, betting that its internal security tools and inventions can find traction in an expanding marketplace.

Audits

The PCI Security Standards Council (SSC), the organization that oversees the Payment Card Industry Data Security Standard (PCI DSS), this week announced the release...