Live data from Hacker News

We spent $20 to achieve RCE and accidentally became the admins of .mobi

labs.watchtowr.com

291–300 of 391 posts

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#292
post #230

Earlier quoted context omitted.

I'm wondering, many SaaS offer companyname.mysaas.com. Is that totally secure?

If it's on the PSL it gets treated similarly to second level "TLDs" like co.uk.

PSL = Public Suffix List

https://publicsuffix.org/

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#293

Earlier quoted context omitted.

interesting, why is this?

I can think of two reasons: 1. it's immediately clear to users that they're seeing content that doesn't belong to your business but instead belongs to your business's users. maybe less relevant for github, but imagine if someone uploaded something phishing-y and it was visible on a page with a url like google.com/uploads/asdf. 2. if a user uploaded something like an html file, you wouldn't want it to be able to run j…

3. If someone uploads something bad, it could potentially get your entire base domain blocklisted by various services, firewalls, anti-malware software, etc.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#294

Obviously there are a lot of errors by a lot of people that led to this, but here's one that would've prevented this specific exploit: > As part of our research, we discovered that a few years ago the WHOIS server for the .MOBI TLD migrated from whois.dotmobiregistry.net to whois.nic.mobi – and the dotmobiregistry.net domain had been left to expire seemingly in December 2023. Never ever ever ever let a domain expire.…

I like the point you are making in this post. It makes me think about the Backblaze blog posts where they discuss the likelihood of enough drive failures to lose user data. Then, they decided the calculation result hardly matters, because people are more likely to forget to pay due to an expired credit card or email spam filtering (missed renewal reminders!).

How do mega corps remember to pay their domain bills? Do they pay an (overpriced) registrar for "infinity" years of renewals? This seems like a genuinely hard business operations problem.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#295

Obviously there are a lot of errors by a lot of people that led to this, but here's one that would've prevented this specific exploit: > As part of our research, we discovered that a few years ago the WHOIS server for the .MOBI TLD migrated from whois.dotmobiregistry.net to whois.nic.mobi – and the dotmobiregistry.net domain had been left to expire seemingly in December 2023. Never ever ever ever let a domain expire.…

I like the point you are making in this post. It makes me think about the Backblaze blog posts where they discuss the likelihood of enough drive failures to lose user data. Then, they decided the calculation result hardly matters, because people are more likely to forget to pay due to an expired credit card or email spam filtering (missed renewal reminders!). How do mega corps remember to pay their domain bills? Do t…

Mega corps have their own top-level domains. For example there're .apple, .google, .amazon, .youtube and probably some more I had forgotten.

Even when companies don't have their own top-level domain, they can have their own domain registrar. For example "facebook.com" is registered with "registrarsafe.com" as registrar. The latter registrar is a wholly owned subsidiary of Facebook. I learned this from this HN thread https://news.ycombinator.com/item?id=28751497

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#296

Earlier quoted context omitted.

[flagged]

Do you have any references/examples of this?

tons

rapid7 for example use LLMs to analyze code and identify vulnerabilities such as SQL injection, XSS, and buffer overflows. Their platform can also identify vulnerabilities in third-party libraries and frameworks from what i can see

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#297
post #280

Earlier quoted context omitted.

Can they? I thought ICANN prevented such steep increases?

Only for a few TLD's, stuff like ccTLD's there's no limit on how much a registry can charge.

To be clear, that's because the country that represents that ccTLD has sovereignty over it. That's also why they can have arbitrary, unusual requirements on them.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#298

Obviously there are a lot of errors by a lot of people that led to this, but here's one that would've prevented this specific exploit: > As part of our research, we discovered that a few years ago the WHOIS server for the .MOBI TLD migrated from whois.dotmobiregistry.net to whois.nic.mobi – and the dotmobiregistry.net domain had been left to expire seemingly in December 2023. Never ever ever ever let a domain expire.…

I like the point you are making in this post. It makes me think about the Backblaze blog posts where they discuss the likelihood of enough drive failures to lose user data. Then, they decided the calculation result hardly matters, because people are more likely to forget to pay due to an expired credit card or email spam filtering (missed renewal reminders!). How do mega corps remember to pay their domain bills? Do t…

The megacorp that I work at requires us to surrender domain names payment that we own to a central authority who takes care of this in perpetuity. Any domain names we buy we also have to tell them about it. Your triple boss gets a good Stern talking to if you're not following these procedures.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#299

Earlier quoted context omitted.

I think it's a sane practice to keep the marketing landing page on a separate domain than the product in case of SaaS.

Why? I always get frustrated when I end up in some parallel universe of a website (like support or marketing) and I can't easily click back to the main site.

One potential reason is that marketing teams often want to do things that are higher risk than you may want to do on your main application domain. For example, hosting content (possibly involving a CNAME pointing to a domain outside your control) on a third party platform. Using a framework that may be less secure and hardened than your main application (for example WordPress or drupal with a ton of plugins) using third party Javascript for analytics, etc.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#300

Earlier quoted context omitted.

Yes, port it to Google voice.

I think that costs $20.

Yes, as a one-time charge.

Though AFAIK there's no law or contract term preventing Google from starting to charge a monthly fee in the future.

And after some time — for me it was 5+ years, porting from a baby Bell land line to a postpaid T-Mobile family plan for a couple years and then to Google Voice — your number will be tarred and feathered as a "VoIP" number and rejected for identity verification by some parties until it's ported back to a paid service (again, after some time).

Even so, it's nice that Google lets me keep the number I was born with for $0/month for as long as it lasts.

Post reply on HN