Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

41–50 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#41

Great article! I'm saddened by DO's response and further wronging a white hat by banning you. Let's remember Linode offers 2x the RAM.

Linode has had _far_ larger issues than DO ever has. That's why I switched to DO in the first place.

Same here. Please stay away from Linode. They used to be good. Now they are unprofessional and unethical.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#42
post #17

Earlier quoted context omitted.

Not that I don't believe you, but you already lost white hat status in this case the moment you log traffic on 20k domains. Just do an attack on another domain you own is white hat, 20k domains is not.

You're probably right about the logging being a bit too far, it was mainly my curiosity getting the best of me. One of my big assumptions was that all of these domains were just owned by one domain broker and this wasn't actually a systemic problem with the implemented importation methodology. I also thought it would be mild because if they had been deleted from an account they were likely no longer used (or so I had…

I certainly don't attribute malice on your part, and I'm sorry if my comment came across this way. My point was (at least intended to be) that I'm not really surprised at DO banning you.

I would be careful about doing something like this on a large scale, I would actually be surprised if this doesn't technically violate some laws. Please be careful, you don't want to end up trying to explain nameservers to a judge. [edit - and the rest of us don't want that either, even just selfishly I would like as many security researchers practicing their craft as possible, but also I don't want people being punished for trying to do the right thing]

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#43
post #30
post #19

Earlier quoted context omitted.

Do you know of an alternative that can host an instance of FreeBSD?

I believe Vultr offers FreeBSD (and custom ISO) hosting at about the same price and offers storage servers too. Their documentation and remote console tools leave a lot to be desired though (I wanted to install openSUSE and ended up resorting to manually entering the iPXE commands at a console to get the damn thing installed).

Are Vuktr and DigitalOcean related in any way? their websites look really similar down to the animation that shows you how to create a new droplet/server.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#44
post #19

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

Do you know of an alternative that can host an instance of FreeBSD?

Sure, Bytemark Cloud https://www.bytemark.co.uk/cloud will let you install from a CD image if you need to, and we FreeBSD works fine.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#45
post #6

This doesn't help my impression of Digital Ocean at all (even if I am a paying customer currently). A few years ago you could impersonate Digital Ocean staff on their support pages with no effort. They grabbed the username from your email, so whatever you put in front of the @ becamse your username on the forums, visible to everyone. And the avatar came from one of those email->avatar services where you can sign up a…

I can think of at least Cloudflare (somewhat), Linode, and Hurricane Electric off the top of my head. Anybody who operates a well-known ns1 type of resolver. It's more a problem with zone hygiene than hosts, honestly.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#46
post #9

Earlier quoted context omitted.

Why, when the author realised this was likely to be possible, didn't they get in touch with DO? Or try with a domain they knew was OK to use? Or at least just try with one domain. They took almost twenty thousand, sent all the requests to their own server and logged them. That's surely not your first step.

Domains can only be added if they are not in another account, so he added only domains which were previously deleted but still pointed to DO nameservers (hence almost certainly not being used). And if DO was really concerned about the damage then they would have removed the added A records, but they didn't, they banned the author and continued to let all traffic go to his server.

> (hence almost certainly not being used)

Well they were still being accessed by real people.

> And if DO was really concerned about the damage then they would have removed the added A records, but they didn't, they banned the author and continued to let all traffic go to his server.

Both seem reasonable. And it does sound like the security team are actually doing something about it.

> I reached out to DigitalOcean’s team to see if they can assist in deleting the domains from my account (sadly leaving them vulnerable again) or sinkholing the DNS to 127.0.0.1. I received a very helpful response from someone on the security team and it appears they will look into it.

I assume these things happened from different departments. Banning an account because you saw it make 20k requests to your API adding domains seems pretty reasonable, and it was a few hours before they reached out. If you saw that activity, would you ban the account or leave it open hoping that they'd be doing something nice and reach out?

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#47
post #15

Earlier quoted context omitted.

> Response wasn't perfect but it was reasonable I'm sorry, "We aware that we make it easy for about 20k domains to be directed to a malicious host, but we're not going to do anything about it" is reasonable ? But of course, it's because Matt "was messing around with things he shouldn't be". It's all solved - we just need everyone to stop doing things that DO "don't want people to do".

Meh the owners of the domains gave up control by pointing to someone else's nameservers.

You've just condemned 99% of domains. You really think that's reasonable?

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#48
post #43
post #30

Earlier quoted context omitted.

I believe Vultr offers FreeBSD (and custom ISO) hosting at about the same price and offers storage servers too. Their documentation and remote console tools leave a lot to be desired though (I wanted to install openSUSE and ended up resorting to manually entering the iPXE commands at a console to get the damn thing installed).

Are Vuktr and DigitalOcean related in any way? their websites look really similar down to the animation that shows you how to create a new droplet/server.

No, Vultr is a spin off of choopa. DO and them have nothing to do with each other.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#49
Amazon S3 has similar problems. To host static website you need use your domain name as the S3 bucket name. Amazon does not verify ownership of your domain, and bucket names use global namespace.

Someone can easily block you from using S3 static website hosting by adding a bucket with your domain name before you do. Also if you delete a bucket and do not change your DNS, someone can recreate the bucket and will be serving files from your domain.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#50

Very interesting read, thanks. I'm surprised at the response from Digital Ocean, did you adequately explain what you had done? The first person that replied looks like he just skim read your email or didn't understand the fact you had sinkholed a lot of traffic.

I believe I was clear about it. However sometimes my writing can be unclear so perhaps it wasn't properly understood (I assume you're talking about their security team's response and not Trust & Safety?). Kind of sad about the massive amount of hate for DigitalOcean in this thread as their security team really seemed quite nice. Their support was just acting on an anomaly they had seen so shrugs .

It was the guy who said "Thank you for sending this in. This is a known workflow within our platform. We are committed to always improving our customer’s experience and have been examining ways of minimizing the type of behavior you are describing."

It sounds to me like he read your email about the vulnerability, dismissed it as "on the backlog" and skipped the bit about the fact you had sinkholed lots of traffic.

We only have one side of the story though, so who knows. Lessons can be learnt.

Post reply on HN