Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

1–10 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#2
I will never stop being infuriated by responses like this from companies - how many more megaleaks have to happen before they realize that they need to embrace white hats, not ban their accounts, not sue them, not swat them / have them arrested, not silence them.

Great find / writeup.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#4
this post raises questions:

Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept?

Why not stop at 10 or 20, and then alert DO to the findings?

20 thousand was unnecessary.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#6
This doesn't help my impression of Digital Ocean at all (even if I am a paying customer currently). A few years ago you could impersonate Digital Ocean staff on their support pages with no effort. They grabbed the username from your email, so whatever you put in front of the @ becamse your username on the forums, visible to everyone. And the avatar came from one of those email->avatar services where you can sign up and set it to anything. So when I signed up with a username like digitalocean@mydomain.com, I ended up being called "digitalocean" on the support forums, and if I had wanted I could just change the avatar to the Digital Ocean logo and impersonate DO or anyone else.

I tried reporting it but got pretty much the same answer as this guy (though I did not get banned). Luckily they fixed it like a year later.

Great write-up, and interesting problem! I wonder if more hosting providers are vulnerable to the same problem.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#7

Great article! I'm saddened by DO's response and further wronging a white hat by banning you. Let's remember Linode offers 2x the RAM.

Linode also does not verify domain ownership before you add a domain to their DNS. And they also use the same nameservers for all accounts. So I think they're in the same boat as DO as far as this "vulnerability" is concerned.

I'm a long-time Linode customer and use them for all servers that run important services. I use DO for the less important stuff. But Linode has had a not-so-stellar record of data breaches.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#8
Wonder what else might be vulnerable to this... CloudFlare seems like it may, they only have a handful of nameservers in any case.

Sort of hard to call it a vulnerability on DO's part though - more of an issue with the admins. I think most DNS services operate in this way, really, route53 may be the exception, not the rule.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#9
post #2

I will never stop being infuriated by responses like this from companies - how many more megaleaks have to happen before they realize that they need to embrace white hats, not ban their accounts, not sue them, not swat them / have them arrested, not silence them. Great find / writeup.

Why, when the author realised this was likely to be possible, didn't they get in touch with DO? Or try with a domain they knew was OK to use? Or at least just try with one domain.

They took almost twenty thousand, sent all the requests to their own server and logged them.

That's surely not your first step.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#10
post #4

this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.

Fair point, my relucatance to stop was mainly due to companies usually disreguarding reports unless I have strong proof. Stopping short of the full scope would've left it up to speculation as to the full amount of vulnerable domains.

It was my plan to delete the domains (or at least null route them so others couldn't take them over with more malicious intent). However my account was banned before I could do so.

Post reply on HN