Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

101–110 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#101
post #43
post #30

Earlier quoted context omitted.

I believe Vultr offers FreeBSD (and custom ISO) hosting at about the same price and offers storage servers too. Their documentation and remote console tools leave a lot to be desired though (I wanted to install openSUSE and ended up resorting to manually entering the iPXE commands at a console to get the damn thing installed).

Are Vuktr and DigitalOcean related in any way? their websites look really similar down to the animation that shows you how to create a new droplet/server.

No, but they've always ripped off the site like that, either on purpose or not. It was worse when the company just came out.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#102
post #46

Earlier quoted context omitted.

> (hence almost certainly not being used) Well they were still being accessed by real people. > And if DO was really concerned about the damage then they would have removed the added A records, but they didn't, they banned the author and continued to let all traffic go to his server. Both seem reasonable. And it does sound like the security team are actually doing something about it. > I reached out to DigitalOcean’s…

> Banning an account because you saw it make 20k requests to your API adding domains seems pretty reasonable, and it was a few hours before they reached out. If you saw that activity, would you ban the account or leave it open hoping that they'd be doing something nice and reach out? If I was a domain reseller, adding my 20k domains to digital ocean just to get banned without warning, explaination or option for recon…

Or 6, they spoke to the security team in the interim period of several hours between the addition of all the domains and when the author reported the issue to the security team.

Neither of us really know what's happened here, but the author at least thinks DOs actions were justified so I'm reasonably happy to leave it at that.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#103
This same thing happens with CloudFlare & is being actively exploited. We reported it to them within the last two weeks and we were told that it's expected behaviour and that they weren't going to do anything about it.

I asked them to, at the absolute least, send an email notification to the prior-CloudFlare owner letting them know that the domain "your CF account used to control is now being controlled by a new CF account". Better yet, implement a domain ownership validation scheme.

They told us that they wouldn't be making any changes.

FWIW, on CloudFlare what happened to us was: we were moving registrars for ~100 domains, from GoDaddy to Route53. During this transition, the NS for the domains temporarily became blank; at this point CF automatically removed the domains from our CF account. The NS were then re-added to the domains on the Route53 side (Apparently there are people out there that are looking for domains that are pointed to CF and then attempting to add them to their own CF account (automated I'm sure) -- which CF lets them do without any verification once they've been auto-removed from your [the original CF account] account.

Interestingly, the original account must be still stored in their system with the domain because we were able to re-add the domain to our original CF account without any verification; effectively "stealing the domains back" to our CF account, away from the thieve's CF account.

In this case, the "attackers" (perhaps more appropriate, I call them 'malicious actors') were able to commandeer ~100 of our domains for ~2 months, for free; they redirected them to Russian websites, torrent sites, affiliate sites, etc.

Again, this is being actively exploited on CloudFlare, at the direct expense of CF customers -- but, according to CF, it's not an issue...?!

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#104
post #100
post #94

Earlier quoted context omitted.

That's not why his account was closed. His account was closed not for discovering a vulnerability, but for exploiting it . While his intentions might have been good (and I expect that they were!), that kind of behavior isn't.

He did not exploit it, he just provided proof. He did not make any money from the traffic and visitors just saw a white page.

That is exploiting the bug. That is literally exploiting the bug. In the same paragraph where you say he did not exploit the bug, you describe the peripherals of his exploit of the bug.

If he was operating responsibly, he would have applied it to a domain he controlled and provided that as a proof of concept. Instead, he ganked twenty thousand domains. That is at best irresponsible and at worst malicious and DigitalOcean (who I am no fan of, for what it's worth) has no obligation to figure out, or even care, which is which before showing him the door.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#107
post #78

"I was walking down the street and I noticed your house wasn't locked very well. So I stole all your stuff and put it in my own house. Now I'm in prison because of this so it's really hard for me to put it back." The article writer is an idiot. He deliberately stole accounts because he could. Just because he then decided to blame the provider because he was able to do this does't make it any more defensible. If I mug…

This is a really bad comparison. He didn't deny anyone access to anything or take anything at all. The real-world equivalent would be if he found a bunch of empty community/neighborhood whiteboards and drew a (trivially erased) line on them. The signs weren't there for him to use but they were empty (he didn't erase them) and the change he made was absolutely minimal.

He just configured a bunch of deleted/unconfigured domains to point them to a blank web page running on his own server. The point is that he could have done all sorts of nefarious things with that redirection but he didn't. He made a harmless change to demonstrate the vulnerability. That's what white hats do. It's what they're supposed to do. We should thank him for his efforts not lambaste him for actually doing something about the problem.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#110

This same thing happens with CloudFlare & is being actively exploited. We reported it to them within the last two weeks and we were told that it's expected behaviour and that they weren't going to do anything about it. I asked them to, at the absolute least, send an email notification to the prior-CloudFlare owner letting them know that the domain "your CF account used to control is now being controlled by a new CF a…

> according to CF, it's not an issue...?!

According to CloudFlare, they are are a reverse proxy, and they are not responsible for anything. This has been their response to every issue that I've tried to bring up with them over any channel, including here on HN.

CloudFlare just doesn't care.

Post reply on HN