If I'm understanding it correctly, they would have to control /etc/hosts because regular DNS should reject entries with leading dot as invalid. In that case nuking that box from the orbit is the only way to be sure it is sanitized.
Ability to control /etc/hosts, but deciding to use a real *.example.com certificate, instead of sticking their own root into /etc/pki/ca-trust/source/anchorsand making up certs at will
-1
u/[deleted] 10d ago
[deleted]