Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

51–60 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#51
post #6

This doesn't help my impression of Digital Ocean at all (even if I am a paying customer currently). A few years ago you could impersonate Digital Ocean staff on their support pages with no effort. They grabbed the username from your email, so whatever you put in front of the @ becamse your username on the forums, visible to everyone. And the avatar came from one of those email->avatar services where you can sign up a…

I can think of at least Cloudflare (somewhat), Linode, and Hurricane Electric off the top of my head. Anybody who operates a well-known ns1 type of resolver. It's more a problem with zone hygiene than hosts, honestly.

[deleted]

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#52
post #4

this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.

Why run a loop 20 times when you can run it 20000 times. I guess the thoughts of the developer were 'check domain, redirect if not used, repeat till end', not 'stop after 20'.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#53

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

Meh, it was just mild incompetence. I expect the only providers (hell, large companies in general) who never responded this way are the ones who haven't been around long enough.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#54
post #19

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

Do you know of an alternative that can host an instance of FreeBSD?

TransIP is similar to DO (except they've had large storage for years) and they support FreeBSD. I've been a happy customer for a couple of years now, never had any problems.

https://www.transip.eu/

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#55

Earlier quoted context omitted.

Except a (theoretical?) attacker isn't going to stick with the things they're "meant" to do. I'd much rather know about this vulnerability via a researcher than when a high profile company loses control of their accounts / domains.

Except this isn't even a vulnerability, this is expected behavior given the design I think, to encounter an issue with it, you'd need to leave your domain with DO's nameservers, but delete it from your account. This would only happen if it's something you're not using anymore, or if you're a severely terrible admin.

> this isn't even a vulnerability, this is expected behavior given the design

Those aren't mutually exclusive. It's certainly possible to be broken by design.

> This would only happen if it's something you're not using anymore

From the writeup it seems like it would also happen if you registered a new domain and assigned the DO name-servers but didn't immediately point it to something.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#56

Amazon S3 has similar problems. To host static website you need use your domain name as the S3 bucket name. Amazon does not verify ownership of your domain, and bucket names use global namespace. Someone can easily block you from using S3 static website hosting by adding a bucket with your domain name before you do. Also if you delete a bucket and do not change your DNS, someone can recreate the bucket and will be se…

As a best practice, use a 'normal' name for your S3 bucket and then put Cloudfront in front of your S3 website.

This way you are not limited by bucket names and you also avoid any SSL validation errors.

Note: you can set Cloudfront's TTL to 0 if you don't need any caching.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#57

TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.

I have an account with DigitalOcean (and several competitors) and I'm not going anywhere or moving any sites around because of this. Sure, they could have handled things better and the security researcher could have too. I don't see any malice or incompetence here, nor do I see a reason to make the effort to switch to another provider.

Where are you going to run off to? How is their security better over there? How many hours of work does that involve?

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#58
post #4

this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.

How does making a domain that does not resolve suddenly resolve negatively impact a user, again? The domain could not have possibly been operational before the circumstances that brought about this scenario, and there is no legitimate traffic they could possibly be receiving. DigitalOcean could certainly improve authentication here but there are dozens of authoritative services that do not, and this is not a new prob…

What was his/her flagged follow up if you don't mind me asking?

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#59

Earlier quoted context omitted.

Meh the owners of the domains gave up control by pointing to someone else's nameservers.

You've just condemned 99% of domains. You really think that's reasonable?

I do think it's reasonable.

If the domain is added to the account there is no PoC, it's only for domains that have been removed from accounts but still have the nameserver values(meaning the domain is not being used at this point, there's no zone file if it isn't added to an account).

So this is mostly only going to affect currently derelict domains. I'm not saying it isn't something to worry about, but I do think it's a reasonable solution.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#60
post #4

this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.

Fair point, my relucatance to stop was mainly due to companies usually disreguarding reports unless I have strong proof. Stopping short of the full scope would've left it up to speculation as to the full amount of vulnerable domains. It was my plan to delete the domains (or at least null route them so others couldn't take them over with more malicious intent). However my account was banned before I could do so.

Have you had any contact with DO's support or security team prior to this? You are correct that companies frequently ignore or downplay reports but it's nice to at least make that first attempt for each new find (per company). This is only ever done as a courtesy, I'm not saying you must or even that you should have here.

Remember, it's just another nerd out there somewhere who receives your report. Sometimes they are super stoked to have it and will be very responsive. This can be more satisfying than a public disclosure without first contacting the company.

Post reply on HN