Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

121–130 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#121

Bye bye digitalocean - account deletion request submitted 1178917. When you have reckless people like Cashan Stine (trust & safety specialist - WTF is that title? sounds like a road safety officer?) that close accounts due to a security report then it won't win any business from me or my clients.

I've reported multiple vulnerabilities to DigitalOcean before and they've fixed them rapidly, credited me for the effort, and gave me free time on their services. The difference is I didn't exploit 20 thousand domains to make flashy headlines and prove a point about something that isn't even a serious bug.

More throwaway astroturfing? You say "20 thousand" the same way as your other likely throwaway account, V8OaSsoA (that is to say: somewhat identifiably) and complained about someone ripping off DigitalOcean's Web design on this account.

I'm doing math on the throwaways that are oddly attracted to this thread. You are making it very obvious that you are almost certainly a DigitalOcean employee across the two throwaways you've created so far, and that's giving me a whole lot of pause on DigitalOcean that I didn't have from reading the incident itself. If you're an employee or, less likely, a superfan, are you sure this is the type of sustained attack you want to levy? It's not making anybody look good.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#122

Amazon S3 has similar problems. To host static website you need use your domain name as the S3 bucket name. Amazon does not verify ownership of your domain, and bucket names use global namespace. Someone can easily block you from using S3 static website hosting by adding a bucket with your domain name before you do. Also if you delete a bucket and do not change your DNS, someone can recreate the bucket and will be se…

EDIT: Just tested it and looks like I'm wrong. Proxying with CloudFlare doesn't help either... Looks like I may have done this with CloudFront instead? That's not correct. The S3 bucket name is always prefixed. The format is: bucketname.region.amazonaws.com. https://docs.aws.amazon.com/AmazonS3/latest/dev/WebsiteHosti... To clarify, you're going to have to add a DNS record either way. Doesn't matter what you call you…

You can't point DNS to any bucket, the bucket name must match the domain name.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#123
post #55

Earlier quoted context omitted.

> this isn't even a vulnerability, this is expected behavior given the design Those aren't mutually exclusive. It's certainly possible to be broken by design. > This would only happen if it's something you're not using anymore From the writeup it seems like it would also happen if you registered a new domain and assigned the DO name-servers but didn't immediately point it to something.

Typically when registering a new domain you add it on your panel first and then change the NS as instructed. If you didn't follow that order, well, that's on you. It's the same design just about everyone providing DNS uses (CloudFlare, XName, FreeDNS, probably others).

But DO instructs you to do it in the reverse order: https://www.digitalocean.com/community/tutorials/how-to-set-...

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#124
Hey Matthew,

I just wanted to let you know that I really appreciate your feedback, as well as the feedback from the other commenters here.

I understand that many here are concerned that banning the account seems, from this perspective, to have been an unjustified action. I do believe that there is a bit of a misunderstanding on the timeline of events here, as well as the source of the decision. To be clear, Cash supported the decision that I had made to ban the account in question, and there had been no communication between us and Matthew at this point. We began receiving a significant number of support requests to remove domains from this account, and I authorized the shutting down of this account as it was clear to me what was happening. I have been working with our engineers to see to the removal of the domains from the account as well.

I apologize if our actions seemed at any point rude or inappropriate, it was definitely not my intention. I want nothing more than to look out for the safety and wellbeing of our customers, and I chose what I believed to be the best action. I do want you to know that if I was aware that a security researcher had been working on testing a theory, I might have acted differently. That can, however, impact the reason behind a white hat test. You generally want the company to see you as normal user, so that you can see how they act in return. We do shut down users who are intentionally causing problems for other users, and I do think that was made evident here.

I do understand that opening a line of communication with Matthew may have been appropriate, and I consider that valuable feedback moving forward.

<3 Jarland

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#125
Thank you all for the conversation around this!

The security team at DigitalOcean has been working to ensure that DO is a safe place for security researchers to identify issues on the Internet as well as at DigitalOcean - security is in everyone's interest. We encourage researchers to contact us when they want to use our platform for this type of work specifically so that we can avoid the types of pain that Matthew encountered while doing his experimentation.

Feel free to reach out to security@digitalocean.com and we will be happy to help.

Nick, DigitalOcean Security Director

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#126
post #30

Earlier quoted context omitted.

I believe Vultr offers FreeBSD (and custom ISO) hosting at about the same price and offers storage servers too. Their documentation and remote console tools leave a lot to be desired though (I wanted to install openSUSE and ended up resorting to manually entering the iPXE commands at a console to get the damn thing installed).

Looking at their DNS setup workflow[1] and API functions[2] I don't see any step where you would have to verify domain ownership - which is this whole thing is about, isn't it? [1] https://serverpilot.io/community/articles/how-to-configure-d... [2] https://www.vultr.com/api/#dns

I was providing an example of a host that provides FreeBSD support. To be clear, I don't think Vultr is a good host so I'm not really sure why I mentioned them to be honest...

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#127

Bye bye digitalocean - account deletion request submitted 1178917. When you have reckless people like Cashan Stine (trust & safety specialist - WTF is that title? sounds like a road safety officer?) that close accounts due to a security report then it won't win any business from me or my clients.

You don't need to make a deletion request, you can deactivate your account from your account settings, and it offers to delete everything for you. That's what I did when I wanted to close my account recently (I wasn't using the droplets I had, and liked my other VPS better anyway.)

>and liked my other VPS better anyway

Which ones?

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#128

Great article! I'm saddened by DO's response and further wronging a white hat by banning you. Let's remember Linode offers 2x the RAM.

Linode has an awful track record for security.

So does DigitalOcean.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#129
post #78

"I was walking down the street and I noticed your house wasn't locked very well. So I stole all your stuff and put it in my own house. Now I'm in prison because of this so it's really hard for me to put it back." The article writer is an idiot. He deliberately stole accounts because he could. Just because he then decided to blame the provider because he was able to do this does't make it any more defensible. If I mug…

He didn't steal anything at all.

All of those domain owners are free to change their nameservers at any time.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#130
post #97
post #6

This doesn't help my impression of Digital Ocean at all (even if I am a paying customer currently). A few years ago you could impersonate Digital Ocean staff on their support pages with no effort. They grabbed the username from your email, so whatever you put in front of the @ becamse your username on the forums, visible to everyone. And the avatar came from one of those email->avatar services where you can sign up a…

And the ban reminds me of the recent case, where DO invalidated the credits of many people within of 2 weeks with a simple TOS change. I had to pay 5€ to even be able to add the 100$ credit from the GitHub students pack to my account (for "verification purposes"), and then they – illegally – delete it just like that? (I never got to use any of it) DO is one of the shadiest hosters I know.

They changed their ToS a year before, you got a notice to review them. What's illegal about revoking promotional credit?

https://www.digitalocean.com/company/blog/details-on-expirin...

Post reply on HN