Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

131–140 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#132
post #97
post #6

This doesn't help my impression of Digital Ocean at all (even if I am a paying customer currently). A few years ago you could impersonate Digital Ocean staff on their support pages with no effort. They grabbed the username from your email, so whatever you put in front of the @ becamse your username on the forums, visible to everyone. And the avatar came from one of those email->avatar services where you can sign up a…

And the ban reminds me of the recent case, where DO invalidated the credits of many people within of 2 weeks with a simple TOS change. I had to pay 5€ to even be able to add the 100$ credit from the GitHub students pack to my account (for "verification purposes"), and then they – illegally – delete it just like that? (I never got to use any of it) DO is one of the shadiest hosters I know.

On one hand, the policy change was made a year prior. On the other hand, we didn't communicate it as well as we should have. I apologize for that. I consider myself as much responsible as anyone else on that. If you ever want that account credit back, please let me know. I'm an easy find on Google, or you can open a support ticket anytime.

For what it's worth, we posted on our blog about just this. https://www.digitalocean.com/company/blog/details-on-expirin...

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#133

This same thing happens with CloudFlare & is being actively exploited. We reported it to them within the last two weeks and we were told that it's expected behaviour and that they weren't going to do anything about it. I asked them to, at the absolute least, send an email notification to the prior-CloudFlare owner letting them know that the domain "your CF account used to control is now being controlled by a new CF a…

> according to CF, it's not an issue...?!

Definitely not the case.

I work at CloudFlare, not in DNS or on this code, and have mentioned this incident in the all-company chat. There is a healthy conversation happening there and it turns out a fix was already in the works for the underlying issue.

adanto6840 has supplied the support ticket number (thank you), and this specific incident is also being reviewed.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#134

Earlier quoted context omitted.

EDIT: Just tested it and looks like I'm wrong. Proxying with CloudFlare doesn't help either... Looks like I may have done this with CloudFront instead? That's not correct. The S3 bucket name is always prefixed. The format is: bucketname.region.amazonaws.com. https://docs.aws.amazon.com/AmazonS3/latest/dev/WebsiteHosti... To clarify, you're going to have to add a DNS record either way. Doesn't matter what you call you…

You can't point DNS to any bucket, the bucket name must match the domain name.

Oh wow you're right! Just tested it.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#135
post #2

I will never stop being infuriated by responses like this from companies - how many more megaleaks have to happen before they realize that they need to embrace white hats, not ban their accounts, not sue them, not swat them / have them arrested, not silence them. Great find / writeup.

Because it can still cause real damage, even if the intentions were good.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#136
post #123

Earlier quoted context omitted.

Typically when registering a new domain you add it on your panel first and then change the NS as instructed. If you didn't follow that order, well, that's on you. It's the same design just about everyone providing DNS uses (CloudFlare, XName, FreeDNS, probably others).

But DO instructs you to do it in the reverse order: https://www.digitalocean.com/community/tutorials/how-to-set-...

[deleted]

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#137

Bye bye digitalocean - account deletion request submitted 1178917. When you have reckless people like Cashan Stine (trust & safety specialist - WTF is that title? sounds like a road safety officer?) that close accounts due to a security report then it won't win any business from me or my clients.

I've reported multiple vulnerabilities to DigitalOcean before and they've fixed them rapidly, credited me for the effort, and gave me free time on their services. The difference is I didn't exploit 20 thousand domains to make flashy headlines and prove a point about something that isn't even a serious bug.

You're coming across as a shill either to make DO seem like an infalliable company or to blatantly astroturf enough to get people to hate DO (See jsmthrowaway's sibling comment).

I'm less inclined to believe the latter. I'm looking forward to transferring my domains on DO to elsewhere tonight.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#138
post #123

Earlier quoted context omitted.

Typically when registering a new domain you add it on your panel first and then change the NS as instructed. If you didn't follow that order, well, that's on you. It's the same design just about everyone providing DNS uses (CloudFlare, XName, FreeDNS, probably others).

But DO instructs you to do it in the reverse order: https://www.digitalocean.com/community/tutorials/how-to-set-...

That's a community tutorial, however it does appear their panel is very sparse in instructions, when you add the domain you see a nameservers list. They don't even tell you that it's not pointed at them and that you should now configure your nameservers as other providers (like CloudFlare) do. I think you're right, some improved documentation would definitely be good here.

However it's the way I've always done it, because otherwise somebody else could add the domain first... it just made sense to me I guess.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#139
post #2

I will never stop being infuriated by responses like this from companies - how many more megaleaks have to happen before they realize that they need to embrace white hats, not ban their accounts, not sue them, not swat them / have them arrested, not silence them. Great find / writeup.

I wouldn't call redirecting 10s of thousands of accounts 'white-hat' hacking. He could have just done like, I dunno, 3, to prove his point.
Post reply on HN