Taking Over DigitalOcean Domains via a Lax Domain Import System
21–30 of 186 posts
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#22Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#23TL;DR - If you own example.com and use DO as your nameserver, then anyone with a DO account can add DNS records for example.com.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#24TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#25this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.
Put another way, the domains were entirely unresolved and offline. Then they weren't. If anything, this is a nice lesson about keeping your zone and delegations clean, and I'm glad I read it. Nobody got hacked, nobody lost traffic, nobody was impacted. If there was sensitive traffic going to a non-resolving domain, I have more questions than answers. I agree adding the full set was probably a bit much, but you can make that point without misplaced concern for alleged harm.
I'm not impressed with signing up for HN to hit someone like this and your far worse and flagged followup, particularly since it really looks like astroturfing. I guess take solace that the OP pretty much guaranteed he won't get the zones again, since they're for research.
(Nice ninja edit and deletion.)
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#26Earlier quoted context omitted.
I should leave the most reliable host I had to date because someone was messing around with things he shouldn't be? DO knows people can do this, but they don't want people to do it. Remembering 2 recurring DNS servers is easier for bulk management than a bunch of different ones. You don't test services like that, it can negatively affect other users. Response wasn't perfect but it was reasonable.
Except a (theoretical?) attacker isn't going to stick with the things they're "meant" to do. I'd much rather know about this vulnerability via a researcher than when a high profile company loses control of their accounts / domains.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#27EG if foo.com is a working site on your DNS provider, try creating a zonefile for bar.foo.com and see if you can create an A record to point to your own server.
This used to be something shared web hosting services running CPanel/WHM were particularly susceptible to. Clearly, the risks here are both phishing/identity and cookie credential stealing.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#28The first person that replied looks like he just skim read your email or didn't understand the fact you had sinkholed a lot of traffic.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#29The first person that replied looks like he just skim read your email or didn't understand the fact you had sinkholed a lot of traffic.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#30TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
Do you know of an alternative that can host an instance of FreeBSD?