I will never stop being infuriated by responses like this from companies - how many more megaleaks have to happen before they realize that they need to embrace white hats, not ban their accounts, not sue them, not swat them / have them arrested, not silence them. Great find / writeup.
Why, when the author realised this was likely to be possible, didn't they get in touch with DO? Or try with a domain they knew was OK to use? Or at least just try with one domain. They took almost twenty thousand, sent all the requests to their own server and logged them. That's surely not your first step.
Taking Over DigitalOcean Domains via a Lax Domain Import System
11–20 of 186 posts
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#12TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
DO knows people can do this, but they don't want people to do it.
Remembering 2 recurring DNS servers is easier for bulk management than a bunch of different ones.
You don't test services like that, it can negatively affect other users.
Response wasn't perfect but it was reasonable.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#13this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.
Fair point, my relucatance to stop was mainly due to companies usually disreguarding reports unless I have strong proof. Stopping short of the full scope would've left it up to speculation as to the full amount of vulnerable domains. It was my plan to delete the domains (or at least null route them so others couldn't take them over with more malicious intent). However my account was banned before I could do so.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#14I will never stop being infuriated by responses like this from companies - how many more megaleaks have to happen before they realize that they need to embrace white hats, not ban their accounts, not sue them, not swat them / have them arrested, not silence them. Great find / writeup.
Why, when the author realised this was likely to be possible, didn't they get in touch with DO? Or try with a domain they knew was OK to use? Or at least just try with one domain. They took almost twenty thousand, sent all the requests to their own server and logged them. That's surely not your first step.
And if DO was really concerned about the damage then they would have removed the added A records, but they didn't, they banned the author and continued to let all traffic go to his server.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#15TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
I should leave the most reliable host I had to date because someone was messing around with things he shouldn't be? DO knows people can do this, but they don't want people to do it. Remembering 2 recurring DNS servers is easier for bulk management than a bunch of different ones. You don't test services like that, it can negatively affect other users. Response wasn't perfect but it was reasonable.
I'm sorry, "We aware that we make it easy for about 20k domains to be directed to a malicious host, but we're not going to do anything about it" is reasonable?
But of course, it's because Matt "was messing around with things he shouldn't be". It's all solved - we just need everyone to stop doing things that DO "don't want people to do".
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#16TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
I should leave the most reliable host I had to date because someone was messing around with things he shouldn't be? DO knows people can do this, but they don't want people to do it. Remembering 2 recurring DNS servers is easier for bulk management than a bunch of different ones. You don't test services like that, it can negatively affect other users. Response wasn't perfect but it was reasonable.
I'd much rather know about this vulnerability via a researcher than when a high profile company loses control of their accounts / domains.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#17Earlier quoted context omitted.
Why, when the author realised this was likely to be possible, didn't they get in touch with DO? Or try with a domain they knew was OK to use? Or at least just try with one domain. They took almost twenty thousand, sent all the requests to their own server and logged them. That's surely not your first step.
See my response below and the logs were secure removed shortly after (as stated in the blog post).
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#18Great article! I'm saddened by DO's response and further wronging a white hat by banning you. Let's remember Linode offers 2x the RAM.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#19TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#20Earlier quoted context omitted.
See my response below and the logs were secure removed shortly after (as stated in the blog post).
Not that I don't believe you, but you already lost white hat status in this case the moment you log traffic on 20k domains. Just do an attack on another domain you own is white hat, 20k domains is not.