Live data from Hacker News

We spent $20 to achieve RCE and accidentally became the admins of .mobi

labs.watchtowr.com

321–330 of 391 posts

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#321

The article puts the blame on > Never Update, Auto-Updates And Change Are Bad as the source of the problem a couple of times. This is pretty common take from security professionals, and I wish they'd also call out the other side of the equation: organizations bundling their "feature" (i.e. enshittification) updates and security updates together. "Always keep your programs updated" is just not feasible advice anymore…

In essence, you are agreeing that this is the root cause, you just seem to believe it's unrealistic to fix it. I actually think it's viable to fix, I am simply not sure if anyone would pay for it — basically, old LTS model from Linux distributions where a set of packages gets 5 or 10 years of guaranteed security updates (backported, maintaining backwards compatibility otherwise). If one was to start a business of "gi…

Aren't you just reinventing Red Hat?

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#322
post #219

Earlier quoted context omitted.

This is the most obvious reason why Verisign is a monopolist and should be regulated like a utility. They make false claims about choice and not being locked in. You buy a domain, you use it, you're locked in forever. And they know it. That's why they fight tooth and nail to protect their monopoly.

It’s worse if you stop using the phrase ‘buy’ and instead use the term ‘rent’. A DNS provider could 10,000x your domain cost and there’s nothing you can do about it.

> A DNS provider could 10,000x your domain cost

DNS providers can't do this.

It's domain registries that can.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#323

Earlier quoted context omitted.

Can you point me to a blog or feature of them that does this? I used to work at R7 up until last year and there was none of this functionality in their products at the time and nothing on the roadmap related to this. It was all static content.

must've been another company then which i got confused with the name

Good thing you have tons of examples.

Right?

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#324

Earlier quoted context omitted.

In essence, you are agreeing that this is the root cause, you just seem to believe it's unrealistic to fix it. I actually think it's viable to fix, I am simply not sure if anyone would pay for it — basically, old LTS model from Linux distributions where a set of packages gets 5 or 10 years of guaranteed security updates (backported, maintaining backwards compatibility otherwise). If one was to start a business of "gi…

Aren't you just reinventing Red Hat?

That's the other way around (and also SuSE, Ubuntu LTS and even Debian stable): here are the things you can get security backports for vs here are the security backports for things you need.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#325

Earlier quoted context omitted.

Hey now if you're just gonna count lines no need to sort it at all.

you need to sort it in order to uniq it, because uniq only removes duplicate consecutive lines.

You know, it's been so long since I've used it, I completely forgot that fact. Alright, you win the battle of best correct bad sql to bash pipeline :).

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#326
post #140

Conjecture: control over tlds should be determined by capture the flag. Whenever an organization running a registry achieves a level of incompetence whereby its tld is captured, the tld becomes owned by the attacker. Sure there are problems with this conjecture, like what if the attacker is just as incompetent (it just gets captured again), or "bad actor" etc. A concept similar to capture the flag might provide for e…

Do we include possibility of phisically capturing the server?

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#327

Earlier quoted context omitted.

Not true. If you are hosting user content, you want their content on a completely separate domain, not a subdomain. This is why github uses githubusercontent.com. https://github.blog/engineering/githubs-csp-journey/

interesting, why is this?

Another aspect are HSTS (HTTP Strict Transport Security) headers, which can extend to subdomains.

If your main web page is available at example.com, and the CMS starts sending HSTS headers, stuff on subdomain.example.com can suddenly break.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#328
post #219

Earlier quoted context omitted.

This is the most obvious reason why Verisign is a monopolist and should be regulated like a utility. They make false claims about choice and not being locked in. You buy a domain, you use it, you're locked in forever. And they know it. That's why they fight tooth and nail to protect their monopoly.

It’s worse if you stop using the phrase ‘buy’ and instead use the term ‘rent’. A DNS provider could 10,000x your domain cost and there’s nothing you can do about it.

No kidding. I had a one letter .tm domain name back in the 90s and they (Turkmenistan) increased the fee to $1000/year.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#329
The cost of managing a domain portfolio is like compound interest — the more domains you add, the higher the renewal costs climb year after year.

It’s tempting to hold onto every domain ‘just in case,’ but cutting domains without a proper risk assessment can open the door to serious security issues, as this article points out.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#330
post #219

Obviously there are a lot of errors by a lot of people that led to this, but here's one that would've prevented this specific exploit: > As part of our research, we discovered that a few years ago the WHOIS server for the .MOBI TLD migrated from whois.dotmobiregistry.net to whois.nic.mobi – and the dotmobiregistry.net domain had been left to expire seemingly in December 2023. Never ever ever ever let a domain expire.…

This is the most obvious reason why Verisign is a monopolist and should be regulated like a utility. They make false claims about choice and not being locked in. You buy a domain, you use it, you're locked in forever. And they know it. That's why they fight tooth and nail to protect their monopoly.

There is an alternative to such regulation though. In the Netherlands, all registrars are required to support automatic transfer between registrars. You can lookup your "transfer code", which you can enter at a new registrar, and they will handle that your domain is transferred (with proper DNS etc) and your old subscription stops.
Post reply on HN