http://security.stackexchange.com/questions/49612/how-does-d...
Taking Over DigitalOcean Domains via a Lax Domain Import System
131–140 of 186 posts
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#132This doesn't help my impression of Digital Ocean at all (even if I am a paying customer currently). A few years ago you could impersonate Digital Ocean staff on their support pages with no effort. They grabbed the username from your email, so whatever you put in front of the @ becamse your username on the forums, visible to everyone. And the avatar came from one of those email->avatar services where you can sign up a…
And the ban reminds me of the recent case, where DO invalidated the credits of many people within of 2 weeks with a simple TOS change. I had to pay 5€ to even be able to add the 100$ credit from the GitHub students pack to my account (for "verification purposes"), and then they – illegally – delete it just like that? (I never got to use any of it) DO is one of the shadiest hosters I know.
For what it's worth, we posted on our blog about just this. https://www.digitalocean.com/company/blog/details-on-expirin...
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#133This same thing happens with CloudFlare & is being actively exploited. We reported it to them within the last two weeks and we were told that it's expected behaviour and that they weren't going to do anything about it. I asked them to, at the absolute least, send an email notification to the prior-CloudFlare owner letting them know that the domain "your CF account used to control is now being controlled by a new CF a…
Definitely not the case.
I work at CloudFlare, not in DNS or on this code, and have mentioned this incident in the all-company chat. There is a healthy conversation happening there and it turns out a fix was already in the works for the underlying issue.
adanto6840 has supplied the support ticket number (thank you), and this specific incident is also being reviewed.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#134Earlier quoted context omitted.
EDIT: Just tested it and looks like I'm wrong. Proxying with CloudFlare doesn't help either... Looks like I may have done this with CloudFront instead? That's not correct. The S3 bucket name is always prefixed. The format is: bucketname.region.amazonaws.com. https://docs.aws.amazon.com/AmazonS3/latest/dev/WebsiteHosti... To clarify, you're going to have to add a DNS record either way. Doesn't matter what you call you…
You can't point DNS to any bucket, the bucket name must match the domain name.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#135I will never stop being infuriated by responses like this from companies - how many more megaleaks have to happen before they realize that they need to embrace white hats, not ban their accounts, not sue them, not swat them / have them arrested, not silence them. Great find / writeup.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#136Earlier quoted context omitted.
Typically when registering a new domain you add it on your panel first and then change the NS as instructed. If you didn't follow that order, well, that's on you. It's the same design just about everyone providing DNS uses (CloudFlare, XName, FreeDNS, probably others).
But DO instructs you to do it in the reverse order: https://www.digitalocean.com/community/tutorials/how-to-set-...
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#137Bye bye digitalocean - account deletion request submitted 1178917. When you have reckless people like Cashan Stine (trust & safety specialist - WTF is that title? sounds like a road safety officer?) that close accounts due to a security report then it won't win any business from me or my clients.
I've reported multiple vulnerabilities to DigitalOcean before and they've fixed them rapidly, credited me for the effort, and gave me free time on their services. The difference is I didn't exploit 20 thousand domains to make flashy headlines and prove a point about something that isn't even a serious bug.
I'm less inclined to believe the latter. I'm looking forward to transferring my domains on DO to elsewhere tonight.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#138Earlier quoted context omitted.
Typically when registering a new domain you add it on your panel first and then change the NS as instructed. If you didn't follow that order, well, that's on you. It's the same design just about everyone providing DNS uses (CloudFlare, XName, FreeDNS, probably others).
But DO instructs you to do it in the reverse order: https://www.digitalocean.com/community/tutorials/how-to-set-...
However it's the way I've always done it, because otherwise somebody else could add the domain first... it just made sense to me I guess.
Re: Taking Over DigitalOcean Domains via a Lax Domain Import System
#139I will never stop being infuriated by responses like this from companies - how many more megaleaks have to happen before they realize that they need to embrace white hats, not ban their accounts, not sue them, not swat them / have them arrested, not silence them. Great find / writeup.