This doesn't help my impression of Digital Ocean at all (even if I am a paying customer currently). A few years ago you could impersonate Digital Ocean staff on their support pages with no effort. They grabbed the username from your email, so whatever you put in front of the @ becamse your username on the forums, visible to everyone. And the avatar came from one of those email->avatar services where you can sign up a…
I can think of at least Cloudflare (somewhat), Linode, and Hurricane Electric off the top of my head. Anybody who operates a well-known ns1 type of resolver. It's more a problem with zone hygiene than hosts, honestly.
Taking Over DigitalOcean Domains via a Lax Domain Import System
51–60 of 186 posts
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#52this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#53TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#54TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
Do you know of an alternative that can host an instance of FreeBSD?
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#55Earlier quoted context omitted.
Except a (theoretical?) attacker isn't going to stick with the things they're "meant" to do. I'd much rather know about this vulnerability via a researcher than when a high profile company loses control of their accounts / domains.
Except this isn't even a vulnerability, this is expected behavior given the design I think, to encounter an issue with it, you'd need to leave your domain with DO's nameservers, but delete it from your account. This would only happen if it's something you're not using anymore, or if you're a severely terrible admin.
Those aren't mutually exclusive. It's certainly possible to be broken by design.
> This would only happen if it's something you're not using anymore
From the writeup it seems like it would also happen if you registered a new domain and assigned the DO name-servers but didn't immediately point it to something.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#56Amazon S3 has similar problems. To host static website you need use your domain name as the S3 bucket name. Amazon does not verify ownership of your domain, and bucket names use global namespace. Someone can easily block you from using S3 static website hosting by adding a bucket with your domain name before you do. Also if you delete a bucket and do not change your DNS, someone can recreate the bucket and will be se…
This way you are not limited by bucket names and you also avoid any SSL validation errors.
Note: you can set Cloudfront's TTL to 0 if you don't need any caching.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#57TO: ANY DIGITAL-OCEAN USER, This is an absolutely terrible response from DO. If I had anything hosted here, I'd move away ASAP. Seriously, do it.
Where are you going to run off to? How is their security better over there? How many hours of work does that involve?
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#58this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.
How does making a domain that does not resolve suddenly resolve negatively impact a user, again? The domain could not have possibly been operational before the circumstances that brought about this scenario, and there is no legitimate traffic they could possibly be receiving. DigitalOcean could certainly improve authentication here but there are dozens of authoritative services that do not, and this is not a new prob…
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#59Earlier quoted context omitted.
Meh the owners of the domains gave up control by pointing to someone else's nameservers.
You've just condemned 99% of domains. You really think that's reasonable?
If the domain is added to the account there is no PoC, it's only for domains that have been removed from accounts but still have the nameserver values(meaning the domain is not being used at this point, there's no zone file if it isn't added to an account).
So this is mostly only going to affect currently derelict domains. I'm not saying it isn't something to worry about, but I do think it's a reasonable solution.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#60this post raises questions: Was there a realization into how legitimate users may be affected by this action? Was there a plan to remove those domains from their account after making and disclosing their proof of concept? Why not stop at 10 or 20, and then alert DO to the findings? 20 thousand was unnecessary.
Fair point, my relucatance to stop was mainly due to companies usually disreguarding reports unless I have strong proof. Stopping short of the full scope would've left it up to speculation as to the full amount of vulnerable domains. It was my plan to delete the domains (or at least null route them so others couldn't take them over with more malicious intent). However my account was banned before I could do so.
Remember, it's just another nerd out there somewhere who receives your report. Sometimes they are super stoked to have it and will be very responsive. This can be more satisfying than a public disclosure without first contacting the company.