Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

21–30 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#22
post #19

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

Do you know of an alternative that can host an instance of FreeBSD?

I'm familiar only with AWS, and it supports FreeBSD.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#23

TL;DR - If you own example.com and use DO as your nameserver, then anyone with a DO account can add DNS records for example.com.

Not quite, only one person can, so if you add first, it's yours. Typically they have you add the domain and then you switch the DNS and in that configuration you wouldn't be vulnerable at all.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#24

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

It's pretty understandable actually. Most DNS providers do similar, it's really just the admins fault for not switching their DNS, likely because they were abandoned and unused.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#25
post #4

this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.

How does making a domain that does not resolve suddenly resolve negatively impact a user, again? The domain could not have possibly been operational before the circumstances that brought about this scenario, and there is no legitimate traffic they could possibly be receiving. DigitalOcean could certainly improve authentication here but there are dozens of authoritative services that do not, and this is not a new problem (but is a valuable reminder). I can think of four free providers off the top of my head that this trick would work against.

Put another way, the domains were entirely unresolved and offline. Then they weren't. If anything, this is a nice lesson about keeping your zone and delegations clean, and I'm glad I read it. Nobody got hacked, nobody lost traffic, nobody was impacted. If there was sensitive traffic going to a non-resolving domain, I have more questions than answers. I agree adding the full set was probably a bit much, but you can make that point without misplaced concern for alleged harm.

I'm not impressed with signing up for HN to hit someone like this and your far worse and flagged followup, particularly since it really looks like astroturfing. I guess take solace that the OP pretty much guaranteed he won't get the zones again, since they're for research.

(Nice ninja edit and deletion.)

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#26

Earlier quoted context omitted.

I should leave the most reliable host I had to date because someone was messing around with things he shouldn't be? DO knows people can do this, but they don't want people to do it. Remembering 2 recurring DNS servers is easier for bulk management than a bunch of different ones. You don't test services like that, it can negatively affect other users. Response wasn't perfect but it was reasonable.

Except a (theoretical?) attacker isn't going to stick with the things they're "meant" to do. I'd much rather know about this vulnerability via a researcher than when a high profile company loses control of their accounts / domains.

Except this isn't even a vulnerability, this is expected behavior given the design I think, to encounter an issue with it, you'd need to leave your domain with DO's nameservers, but delete it from your account. This would only happen if it's something you're not using anymore, or if you're a severely terrible admin.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#27
An additional vector for this kind of attack is to create a zonefile for a subdomain off of a working, live domain administered by the same DNS server.

EG if foo.com is a working site on your DNS provider, try creating a zonefile for bar.foo.com and see if you can create an A record to point to your own server.

This used to be something shared web hosting services running CPanel/WHM were particularly susceptible to. Clearly, the risks here are both phishing/identity and cookie credential stealing.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#28
Very interesting read, thanks. I'm surprised at the response from Digital Ocean, did you adequately explain what you had done?

The first person that replied looks like he just skim read your email or didn't understand the fact you had sinkholed a lot of traffic.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#29
Very interesting read, thanks. I'm surprised at the response from Digital Ocean, did you adequately explain what you had done?

The first person that replied looks like he just skim read your email or didn't understand the fact you had sinkholed a lot of traffic.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#30
post #19

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

Do you know of an alternative that can host an instance of FreeBSD?

I believe Vultr offers FreeBSD (and custom ISO) hosting at about the same price and offers storage servers too. Their documentation and remote console tools leave a lot to be desired though (I wanted to install openSUSE and ended up resorting to manually entering the iPXE commands at a console to get the damn thing installed).
Post reply on HN