Live data from Hacker News

We spent $20 to achieve RCE and accidentally became the admins of .mobi

labs.watchtowr.com

341–350 of 391 posts

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#341
post #205

Obviously there are a lot of errors by a lot of people that led to this, but here's one that would've prevented this specific exploit: > As part of our research, we discovered that a few years ago the WHOIS server for the .MOBI TLD migrated from whois.dotmobiregistry.net to whois.nic.mobi – and the dotmobiregistry.net domain had been left to expire seemingly in December 2023. Never ever ever ever let a domain expire.…

> If you're a business and you're looking to pick up a new domain because it's only $10/year, consider that you're going to be paying $10/year forever, because once you associate that domain with your business, you can never get rid of that association. Please elaborate... Also, what about personal domains? Does it apply there as well?

A friend of mine recently let the domain used for documentation of Pykka, a Python actor library, expire. Some of course registered the domain, resurected the content and injected ads/spam/SEO junk.

Since the documentation is Apache License 2.0 there isn't much one can do, other than complain to the hosting about misuse of the project name/branding. But so far we haven't heard back from the hosting provider's abuse contact point (https://github.com/jodal/pykka/issues/216 if anyone is interested).

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#342

Earlier quoted context omitted.

I think that costs $20.

Yes, as a one-time charge. Though AFAIK there's no law or contract term preventing Google from starting to charge a monthly fee in the future. And after some time — for me it was 5+ years, porting from a baby Bell land line to a postpaid T-Mobile family plan for a couple years and then to Google Voice — your number will be tarred and feathered as a "VoIP" number and rejected for identity verification by some parties…

Google has already killed my sister's business's Enterprise Workspace plan, because they decided to change their mind, and make "unlimited storage" not a thing. She was paying $200/month and they now wanted $1,600/month. I decided to build a NAS for her instead.

This is despite written emails from their support confirming the use case (videography) and storage needs were suitable, and a written statement that she is "permanently grandfathered" once Google stopped offering the plan to new customers.

To make matters worse, they gave her 30 days to download all data before everything would be deleted permanently. This is how Google treats "enterprise" customers.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#343
post #313
post #69

This is a fantastic exploit and I am appalled that CAs are still trying to use whois for this kind of thing. I expected the rise of the whois privacy services and privacy legislation would have made whois mostly useless for CAs years ago. > This is the approach taken by whois on Debian. Years ago I did some hacking on FreeBSD’s whois client, and its approach is to have as little built-in hardcoded knowledge as possib…

Wouldn't it be easy for those software project, or a single central authority, to expose that WHOIS list through DNS? mobi.whoisserverlist.info. IN CNAME whois.nic.mobi. org.whoisserverlist.info. IN CNAME whois.publicinterestregistry.org. The presence of a referral mechanism inside the WHOIS protocol strikes me as a little odd.

You mean like an SRV record?

https://circleid.com/posts/whois_server_address_registry/

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#344

Earlier quoted context omitted.

Yes, port it to Google voice.

Its Google. They can kill any services with no reason

This wouldn't be surprising. It's sad they've let it atrophy the way that they have. My understanding is that they purchased it to train their digital assistant on the voicemails (where we would correct the transcripts for free)

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#345
post #271

Earlier quoted context omitted.

Thankfully you can still get them without ID, for cash. Unlike in Germany, where you can’t get one without a passport or ID card.

I’m wondering how feasible would it be to just use a SIM card from another country (e.g. in Estonia, you can get a prepaid card for 1 € that works in EU roaming just fine, with domestic-like prices on local calls). How many services in Germany require you to use specifically German number?

Several do require it.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#346
It's grotesquely insecure and not authoritative to rely on rando, unsecured WHOIS in the clear scraping contact details to "authenticate" domain ownership rather than ask the owner to provide a challenge cookie by DNS or hosted in content.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#348

> We recently performed research that started off "well-intentioned" (or as well-intentioned as we ever are) - to make vulnerabilities in WHOIS clients and how they parse responses from WHOIS servers exploitable in the real world (i.e. without needing to MITM etc). R̶i̶g̶h̶t̶ o̶f̶f̶ t̶h̶e̶ b̶a̶t̶, S̶T̶O̶P̶. I̶ d̶o̶n̶'t̶ c̶a̶r̶e̶ w̶h̶o̶ y̶o̶u̶ a̶r̶e̶ o̶r̶ h̶o̶w̶ "w̶e̶l̶l̶-̶i̶n̶t̶e̶n̶t̶i̶o̶n̶e̶d̶" s̶o̶m̶e̶o̶n̶e̶ i̶s̶.…

[deleted]

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#349
post #236

Earlier quoted context omitted.

See also personal phone numbers, which are now "portable" and thus "required for every single identity verification you will ever perform", without being regulated, which means your identity is one $30 bill autopayment or one dodgy MVNO customer service interaction from being lost forever.

Not regulated? They're portable because they're regulated.

Lose access to your number by any category of errors on your part or your carrier's part, and see what happens.

They're not tied to your person with much more permanency than a DHCP IP address. There's no process to verify your identity or recover your number or help you regain your accounts. The actual process for migrating your number is "Sign up with this other brand you've never tried before and tell them to politely ask your former brand to release the number to them".

If I lose my phone to a trash compactor, the process to change anything in my phone carrier account with regard to SIM cards is going to forward things to my Gmail account, which at random times for random reasons is going to begin to demand 2 factor identification for logging in on a new device via texting my phone number.

There are all sorts of crazy scenarios that can arise with double binds like this.

If we had a resilient authoritative identity verification (say, the DMV, or US Passport Office), or if we had a diverse variety of low-trust identity factors that we could check multiple aspects of ("text my mother" / "Here's a bill showing my address" / "here's a video of my phase saying my phone number"), there would be a way out, but all of corporate America heard "2fa is required for security now" and said "So we just text them right?"

That makes your phone not "another thing that people can use to talk to you in circumstances when you're not accessible", which the FCC's portability plan was maybe sufficient for, but a fragile single point of failure for your entire identity.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#350
post #328

Earlier quoted context omitted.

It’s worse if you stop using the phrase ‘buy’ and instead use the term ‘rent’. A DNS provider could 10,000x your domain cost and there’s nothing you can do about it.

No kidding. I had a one letter .tm domain name back in the 90s and they (Turkmenistan) increased the fee to $1000/year.

Tbh this seems like a win—you want to incentivize making as much use of those short domains as possible.
Post reply on HN