Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

11–20 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#11
post #9
post #2

I will never stop being infuriated by responses like this from companies - how many more megaleaks have to happen before they realize that they need to embrace white hats, not ban their accounts, not sue them, not swat them / have them arrested, not silence them. Great find / writeup.

Why, when the author realised this was likely to be possible, didn't they get in touch with DO? Or try with a domain they knew was OK to use? Or at least just try with one domain. They took almost twenty thousand, sent all the requests to their own server and logged them. That's surely not your first step.

See my response below and the logs were secure removed shortly after (as stated in the blog post).

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#12

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

I should leave the most reliable host I had to date because someone was messing around with things he shouldn't be?

DO knows people can do this, but they don't want people to do it.

Remembering 2 recurring DNS servers is easier for bulk management than a bunch of different ones.

You don't test services like that, it can negatively affect other users.

Response wasn't perfect but it was reasonable.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#13
post #4

this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.

Fair point, my relucatance to stop was mainly due to companies usually disreguarding reports unless I have strong proof. Stopping short of the full scope would've left it up to speculation as to the full amount of vulnerable domains. It was my plan to delete the domains (or at least null route them so others couldn't take them over with more malicious intent). However my account was banned before I could do so.

[deleted]

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#14
post #9
post #2

I will never stop being infuriated by responses like this from companies - how many more megaleaks have to happen before they realize that they need to embrace white hats, not ban their accounts, not sue them, not swat them / have them arrested, not silence them. Great find / writeup.

Why, when the author realised this was likely to be possible, didn't they get in touch with DO? Or try with a domain they knew was OK to use? Or at least just try with one domain. They took almost twenty thousand, sent all the requests to their own server and logged them. That's surely not your first step.

Domains can only be added if they are not in another account, so he added only domains which were previously deleted but still pointed to DO nameservers (hence almost certainly not being used).

And if DO was really concerned about the damage then they would have removed the added A records, but they didn't, they banned the author and continued to let all traffic go to his server.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#15

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

I should leave the most reliable host I had to date because someone was messing around with things he shouldn't be? DO knows people can do this, but they don't want people to do it. Remembering 2 recurring DNS servers is easier for bulk management than a bunch of different ones. You don't test services like that, it can negatively affect other users. Response wasn't perfect but it was reasonable.

> Response wasn't perfect but it was reasonable

I'm sorry, "We aware that we make it easy for about 20k domains to be directed to a malicious host, but we're not going to do anything about it" is reasonable?

But of course, it's because Matt "was messing around with things he shouldn't be". It's all solved - we just need everyone to stop doing things that DO "don't want people to do".

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#16

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

I should leave the most reliable host I had to date because someone was messing around with things he shouldn't be? DO knows people can do this, but they don't want people to do it. Remembering 2 recurring DNS servers is easier for bulk management than a bunch of different ones. You don't test services like that, it can negatively affect other users. Response wasn't perfect but it was reasonable.

Except a (theoretical?) attacker isn't going to stick with the things they're "meant" to do.

I'd much rather know about this vulnerability via a researcher than when a high profile company loses control of their accounts / domains.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#17
post #9

Earlier quoted context omitted.

Why, when the author realised this was likely to be possible, didn't they get in touch with DO? Or try with a domain they knew was OK to use? Or at least just try with one domain. They took almost twenty thousand, sent all the requests to their own server and logged them. That's surely not your first step.

See my response below and the logs were secure removed shortly after (as stated in the blog post).

Not that I don't believe you, but you already lost white hat status in this case the moment you log traffic on 20k domains. Just do an attack on another domain you own is white hat, 20k domains is not.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#20
post #17

Earlier quoted context omitted.

See my response below and the logs were secure removed shortly after (as stated in the blog post).

Not that I don't believe you, but you already lost white hat status in this case the moment you log traffic on 20k domains. Just do an attack on another domain you own is white hat, 20k domains is not.

You're probably right about the logging being a bit too far, it was mainly my curiosity getting the best of me. One of my big assumptions was that all of these domains were just owned by one domain broker and this wasn't actually a systemic problem with the implemented importation methodology. I also thought it would be mild because if they had been deleted from an account they were likely no longer used (or so I had wrongfully assumed).
Post reply on HN