Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

161–170 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#161
post #71

As an aside, you can set up a security group in AWS that blocks inbound traffic on port 80 if you'd like to neuter the incoming requests.

Or, like, simply shut down the web server.

He'd still have to pay. By neutering it he means that nobody with bad intensions should be able to use the domains. It is neutered now, but if he was allowed to change DNS entry to point to localhost, he wouldn't have to pay Amazon.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#163
post #110

Earlier quoted context omitted.

> according to CF, it's not an issue...?! According to CloudFlare, they are are a reverse proxy, and they are not responsible for anything. This has been their response to every issue that I've tried to bring up with them over any channel, including here on HN. CloudFlare just doesn't care.

not at all accurate. If you find something abusive or malicious report it: cloudflare.com/abuse -- every report filed there is reviewed by a human.

For what it's worth, in the support ticket exchange I did indeed offer to submit details of the attack vector along with proof that it's currently being actively exploited, for financial gain & at the direct expense of your customers.

I was basically told "you will be wasting your time"...

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#165
post #100
post #94

Earlier quoted context omitted.

That's not why his account was closed. His account was closed not for discovering a vulnerability, but for exploiting it . While his intentions might have been good (and I expect that they were!), that kind of behavior isn't.

He did not exploit it, he just provided proof. He did not make any money from the traffic and visitors just saw a white page.

Doing it once, proof. Doing it 20,000 times... Exploit.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#166

Earlier quoted context omitted.

I've reported multiple vulnerabilities to DigitalOcean before and they've fixed them rapidly, credited me for the effort, and gave me free time on their services. The difference is I didn't exploit 20 thousand domains to make flashy headlines and prove a point about something that isn't even a serious bug.

More throwaway astroturfing? You say "20 thousand" the same way as your other likely throwaway account, V8OaSsoA (that is to say: somewhat identifiably) and complained about someone ripping off DigitalOcean's Web design on this account. I'm doing math on the throwaways that are oddly attracted to this thread. You are making it very obvious that you are almost certainly a DigitalOcean employee across the two throwaway…

Eh, I used '20 thousand' in one of my responses, does that mean I'm the real identity of the throwaways?

Probably not.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#167

Earlier quoted context omitted.

not at all accurate. If you find something abusive or malicious report it: cloudflare.com/abuse -- every report filed there is reviewed by a human.

For what it's worth, in the support ticket exchange I did indeed offer to submit details of the attack vector along with proof that it's currently being actively exploited, for financial gain & at the direct expense of your customers. I was basically told "you will be wasting your time"...

To be fair, he did say "is reviewed by a human", not "we care" or "we will act on it"

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#168

Earlier quoted context omitted.

Meh the owners of the domains gave up control by pointing to someone else's nameservers.

You've just condemned 99% of domains. You really think that's reasonable?

If I buy a domain from a registrar, I can point the registrar at Digital Ocean's nameservers (or AWS, CloudFlare, etc) for my domain (by adding NS records at the registrar). Then I need to go to Digital Ocean and add my domain and records to their nameservers (via their control panel or api).

If I remove my domain from Digital Ocean, it's my responsibility to then go to the registrar and point the registrar away from DigitalOcean's nameservers. (I own the domain, so I'm the only one the registrar allows to do this. Digital Ocean cannot do this.)

Now, your suggestion is that Digital Ocean goes and verifies that I'm the one who owns that domain. But how would they do this (legitimate question)? I imagine manual verification of ownership of every domain upon creation isn't feasible for their scale. Digital Ocean could query DNS, and see NS records pointing to Digital Ocean, but this only tells them someone configured the nameservers for that domain - it doesn't imply ownership. Digital Ocean can check Whois for the owner of the domain. Checking Whois might work for many cases, but at least some registrars have the option of obscuring Whois data.

It seems simpler to put the onus of security on the owner of the domain. I should cleanup my registrar's NS records before removing my domain from Digital Ocean to ensure nobody hijacks it. I would be satisfied as long as Digital Ocean maintained a simple eviction policy (I don't know if they do) as a way for legitimate owners to add their domains to Digital Ocean's nameservers.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#169
post #78

"I was walking down the street and I noticed your house wasn't locked very well. So I stole all your stuff and put it in my own house. Now I'm in prison because of this so it's really hard for me to put it back." The article writer is an idiot. He deliberately stole accounts because he could. Just because he then decided to blame the provider because he was able to do this does't make it any more defensible. If I mug…

It's not very re-assuring for users of DigitalOcean to know that issues like this can put our domains at risk to "idiots". I don't care whether the guy was malicious or a nice guy or what. I care that a system I may be trusting my domain name to is trivially exploitable like this.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#170
post #73

Banning his account was totally unjustified since he approached them first with the issue. A less ethical person could have tried to make money or sold this off on the back market. People like him should be rewarded not have their accounts banned. For all we know he just saved DO a lot of headache in sorting this issue had it gone wrong. I really wish the response from DO on this was different.

Adding 20k domains to your account is probably enough to flag as abuse even if you own the domains. Next time the author should probably try just the one or two. Bonus points if they're their own domains.

>Bonus points if they're their own domains.

If the service doesn't understand the issue at all, then when you explain that they're your domains, then they'll probably just tell you it's working as intended and that users should be able to add their own domains.

Post reply on HN