Live data from Hacker News

Someone used my IPFS gateway for phishing

incoherency.co.uk

21–30 of 44 posts

Re: Someone used my IPFS gateway for phishing

#22
It's very shitty of DigitalOcean to not at least give you a small window of opportunity to investigate and remove offending content, especially if first complaint. Given that their investigation would of been limited too (unlike yours) it makes it somewhat easy to knock off someone on DigitalOcean with a flimsy complaint.

Re: Someone used my IPFS gateway for phishing

#23

> (although their hosting provider doesn't appear to have switched their networking off). I doubt that Microsoft Azure is going to switch off the networking for all of Microsoft OneDrive over this.

I wouldn't guarantee that. Depends on whether it's automated or manual.

Re: Someone used my IPFS gateway for phishing

#24

It's very shitty of DigitalOcean to not at least give you a small window of opportunity to investigate and remove offending content, especially if first complaint. Given that their investigation would of been limited too (unlike yours) it makes it somewhat easy to knock off someone on DigitalOcean with a flimsy complaint.

[deleted]

Re: Someone used my IPFS gateway for phishing

#25
post #6
post #3

Earlier quoted context omitted.

Note that the link to the OneDrive URL does not come from IPFS. It comes from the URL fragment, which makes it even more murky as to whether the IPFS hash should even be blocked! Perfectly legitimate sites could be using exactly the same content with no knowledge of the phishing attack. It is just copy and pasted from https://itty.bitty.site/ I didn't look into how GMA.html works, but a quick look just now shows that…

Looks like they are using 'Vesta', here's their control panel https://searchurl.bid:8083/login/ https://forum.vestacp.com/viewtopic.php?p=68594#p68594 https://www.digitalocean.com/community/questions/how-do-i-de... Appears there was a vulnerability in this panel, seems plausible that 'owner' of this page is an additional victim of the attacker.

Wow, there's a lot of open ports on that box.

Re: Someone used my IPFS gateway for phishing

#26

> (although their hosting provider doesn't appear to have switched their networking off). I doubt that Microsoft Azure is going to switch off the networking for all of Microsoft OneDrive over this.

That's not a OneDrive URL ("https://onedrivepreinhabitat.**blob.core.windows.net**") - it's Azure Blob Storage (equiv to Amazon S3). Microsoft could absolutely disable that account.

Re: Someone used my IPFS gateway for phishing

#27

It's very shitty of DigitalOcean to not at least give you a small window of opportunity to investigate and remove offending content, especially if first complaint. Given that their investigation would of been limited too (unlike yours) it makes it somewhat easy to knock off someone on DigitalOcean with a flimsy complaint.

> especially if first complaint

Well:

> It was sent by PhishLabs to DigitalOcean, and DigitalOcean forwarded it to me.

I don't think this is the first complaint from PhishLabs to DigitalOcean. I do think DO would have "investigated" up to the level where they'd click the link and see "yep, that's a google sign in form". It's not up to DO to dispute claims made by people who send them abuse e-mails. As for the dispute itself, we all seem to think the IPFS was not hosting the content. But I'm not sure if that holds up in a legal case (the PirateBay is also not hosting any illegal content).

Re: Someone used my IPFS gateway for phishing

#28
post #4

Earlier quoted context omitted.

Ah, I didn't catch that the Base64 string was part of the query param, not stored in IFPS. Yeah, seems like IFPS data isn't offending whatsoever in this case. Interesting that it is 'facilitating' phishing (as in dependency in attack chain), but only to the extent that would apply to a number of general-purpose open source libraries, or the browser, or any OS or ISP. Seems like DigitalOcean made the wrong choice, but…

I agree that it's too complex to expect front-line abuse support to work out what's going on, but yes I did expect them to turn my networking back on after I blacklisted the hash.

Digitalocean disabled network access to one of my droplets too. They won't respond to your emails, but poke them on twitter and hopefully you will get a response back. mine to 10 days to get a reply.

I switched to scaleway afterwards.

Re: Someone used my IPFS gateway for phishing

#30

It's very shitty of DigitalOcean to not at least give you a small window of opportunity to investigate and remove offending content, especially if first complaint. Given that their investigation would of been limited too (unlike yours) it makes it somewhat easy to knock off someone on DigitalOcean with a flimsy complaint.

If you don't want to be nullrouted at the first abuse or DMCA complaint, I recommend more professional hosters like Hetzner or OVH. They will forward abuse mail to you first and only react themselves if you ignore the mails entirely and repeatedly do nothing about it.
Post reply on HN