Live data from Hacker News

Sinkholed

susam.in

11–20 of 135 posts

Re: Sinkholed

#11
post #7
post #2

It is really unbelievable that a legitimate domain can be transferred so easily without any verification or due process. Isn't there an EPP-code-based domain transfer process to prevent exactly things like this?

As mentioned in this blog post, the domain transfer was done as part of an international operation against the Avalanche botnet. As such, it was a legal action as opposed to an administrative action. Further, the action was taken at registry level as opposed to registrar level (which is one level lower than the registry). Therefore, no EPP code was necessary and the "clientTransferProhibited" domain transfer record w…

It seems like there should be a notification after the fact so legitimate domain owners have a chance to reach someone who is in the know.

Re: Sinkholed

#13
post #8
post #5

Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…

This is great news! Have you consulted a lawyer? It seems that the Shadowsecurity Foundation did act recklessly. But you'd need to prove monetary damages. But perhaps they'd settle to avoid the hassle. Edit: This is an admission of guilt: > He explained in his email that my domain name was sinkholed accidentally as part of their Avalanche operation.

Yes, sue them, and incentivize a worse, slower (because lawyers involved) and less transparent resolution of errors.

Re: Sinkholed

#14
post #8
post #5

Hi, I am the author of this post. I had posted another link about this story a few days ago when this story was still unfolding.[1][2] This blog post summarizes the timeline and the events that occurred to resolve the domain transfer issue. Like I have mentioned in this blog post, multiple parties such as Namecheap Support, the Shadowsecurity Foundation, and NIXI helped me in resolving this issue. Thanks to all of th…

This is great news! Have you consulted a lawyer? It seems that the Shadowsecurity Foundation did act recklessly. But you'd need to prove monetary damages. But perhaps they'd settle to avoid the hassle. Edit: This is an admission of guilt: > He explained in his email that my domain name was sinkholed accidentally as part of their Avalanche operation.

Thank you for this comment. I have not consulted a lawyer. I have not suffered any monetary loss due to this yet. I use this domain name only to run a small personal blog (the one linked to in this post) and an Exim4 MTA. The fact that the MTA became unreachable via the domain name did mean that some emails sent to it must have bounced back. The primary loss I suffered was in terms of time.

In fact, I appreciate the efforts of the Shadowserver Foundation in depriving Avalanche malware families of their command and control infrastructure by sinkholing the domain names generated by the malware domain generation algorithms. I understand false-positives like this can happen. It comes with the territory. It just sucks that the domain name I was using happened to be a false positive. In this case, it ended well because the Shadowserver Foundation (along with Namecheap) acted quickly on my issue and asked NIXI to have the domain transfer undone.

Having said that, I do believe that you make a very good point. Actions like this should be taken with a lot more care. What if it were not a personal blog but a small business? Depending on the nature of the business, an inadvertent domain transfer like this could have affected the business seriously. The Shadowsecurity Foundation did say that they are improving their processes.

I am not very concerned about this particular foundation when I talk about this. But I am concerned about the systemic issue in the domain name management system that allowed a mistake like this to occur. There could be some type of peer review before a domain transfer like this is executed. I don't think there is a general and popular solution for this problem in the near future. I am hoping that the recent work that is going on in consensus protocols based on cryptography might pave the way to a more decentralized network and more decentralized name management that also become popular and mainstream.

Re: Sinkholed

#15
Automated legal actions and takedowns like this introduce a lot of risk of collateral damage, but I wonder what the alternatives are?

The investigators would likely argue that notifying domain holders would reduce the chance that they can take down a botnet's infrastructure successfully, which seems likely.

Could there be some maximum time after which the 'rule set' for the auto-takedown code needs to be made open source / public? It must presumably be implemented as software and/or configuration files.

That would at least allow for inspection, confirmation and disputes about how it's implemented, and if this was 30 days or so, it shouldn't risk the takedown effort.

While top-tier network engineers are developing takedowns like this, presumably they'll do a good job of minimizing false positives - but as this case shows, it's not always going to be perfect - and I worry that if it becomes more common, we'll see sloppier implementations.

That could lead to connectivity and access issues for more users (again in an international context). It's great that the situation was resolved in this case but I imagine not all users would be able to raise a complaint at a similar level of technical detail and respectful tone and for it to receive the same amount of attention.

Maybe that's untrue - maybe injustices really do get amplified by social media and relying on companies to notice this 'works'. It doesn't sit particularly well with me as a remediation process though, and I'm not sure it scales.

Re: Sinkholed

#17
post #9
post #2

It is really unbelievable that a legitimate domain can be transferred so easily without any verification or due process. Isn't there an EPP-code-based domain transfer process to prevent exactly things like this?

The FBI and analogous TLAs do this all the time. And generally, there's no recourse. In many cases, sites have resorted to distributing their IP addresses.

Personally I’d rather deal with the FBI accidentally seizing a domain than some foreign entity.

Re: Sinkholed

#18
Looking forward to hear from Shadowserver on a few points...

• What led to the false positive.

• What actions were taken to notify the domain owner about the actions being taken against them.

• Why there was not a comment put into the Whois entry — or in some other obvious place — saying what had been done to the domain.

Re: Sinkholed

#19
As someone that deals with sinkholed malware domains everyday, I have to day I slightly disagree with the logic and approach behind it.

The basic premise is that unwitting hosts are compromised by malware,this malware is talking to a domain and in order to protect the infected users and curtail the further spreading of the malware the domain is sinkholed.

First, a random authority, regardless of legal relevance has no standing to "protect" infected hosts without explicit consent of the owners. If the infected host is causing harm to other internet hosts then it needs to be taken offline by it's network owner (e.g.: isp or datacenter operator that owns the IP AS number).

Second, in case of malware spreading (e.g.: wannacry) and DGA domains: if the domain is not registered, instead of a sinkhole, an administrative restriction on registering that domain should be placed. If the domain is registered, you want the IP infrasructure to be taken down. IP blocks an reputation damage can be very harmful. IP subnet owners are much more responsive and where that is not the case, a null route can be blaced to "sinkhole" the IP -- null routes are advertised using predefined BGP communities, this means it will be unreachable only by networks that accept that community (e.g.: FBI sinkholes an IP, american networks accept the community and block the IP while other countries might not). You have to understand why there are so many malware domains for C2 and why DGAs exist, it is more costly to become in control of an IP address than it is a domain. If you block the IP as soon as C2 is detected on it,the attacker will just change the A record to point to another IP, but they have a much more limited set of IPs and costly IP infrastructure so they'll be running out of them fast. You can use DGA and dynamic domains such as noip.org (MS famously sinkholed them taking down millions of legit hosts!) But you can't as readily come up with IP addresses. I like this approach because the IP owner is always in a position to force remediation of the C2 server or infected host, they can ban the user or work with them to remediate the infection after confirming, they can request removal from the sinkhole. Most malware operators have no more than a handful active C2 IP addresses but from experience, I see them use dozens of domains,sometimes from different malware campaigns pointing to the few few IP addresses in their control.

I am sure this has challenges but it is a cleaner way of doing it and focuses remediation on the C2. If this approach was taken, OP's IP would have been accidentally sinkholed, her webhost would contact her about it, she would show proof that the server has not hosted malicious content and work with them to lift the sinkhole. Meanwhile,the site can be moved to a different host (if it takes too long) and IP address, since the domain is not being sinkholed it would just work. Malware researchers and law enforcement can see if infected hosts continue to communicate with the new IP or if the new IP responds to C2 initial traffic to decide if it should continue to be sinkholed (costing OP hosting money if it was an attacker, it might cost them money and access to compromised hosts).

Re: Sinkholed

#20
post #9

Earlier quoted context omitted.

The FBI and analogous TLAs do this all the time. And generally, there's no recourse. In many cases, sites have resorted to distributing their IP addresses.

Personally I’d rather deal with the FBI accidentally seizing a domain than some foreign entity.

[deleted]
Post reply on HN