Taking Over DigitalOcean Domains via a Lax Domain Import System
thehackerblog.com
Taking Over DigitalOcean Domains via a Lax Domain Import System
1–10 of 186 posts
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#2Great find / writeup.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#3Let's remember Linode offers 2x the RAM.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#4Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept?
Why not stop at 10 or 20, and then alert DO to the findings?
20 thousand was unnecessary.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#5This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#6I tried reporting it but got pretty much the same answer as this guy (though I did not get banned). Luckily they fixed it like a year later.
Great write-up, and interesting problem! I wonder if more hosting providers are vulnerable to the same problem.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#7Great article! I'm saddened by DO's response and further wronging a white hat by banning you. Let's remember Linode offers 2x the RAM.
I'm a long-time Linode customer and use them for all servers that run important services. I use DO for the less important stuff. But Linode has had a not-so-stellar record of data breaches.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#8Sort of hard to call it a vulnerability on DO's part though - more of an issue with the admins. I think most DNS services operate in this way, really, route53 may be the exception, not the rule.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#9I will never stop being infuriated by responses like this from companies - how many more megaleaks have to happen before they realize that they need to embrace white hats, not ban their accounts, not sue them, not swat them / have them arrested, not silence them. Great find / writeup.
They took almost twenty thousand, sent all the requests to their own server and logged them.
That's surely not your first step.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#10this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.
It was my plan to delete the domains (or at least null route them so others couldn't take them over with more malicious intent). However my account was banned before I could do so.