Live data from Hacker News

We spent $20 to achieve RCE and accidentally became the admins of .mobi

labs.watchtowr.com

351–360 of 391 posts

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#351

The real solution to WHOIS is RDAP. Unfortunately, it isn't required for ccTlds, and there are plenty of non-ccTlds that aren't working. https://en.wikipedia.org/wiki/Registration_Data_Access_Proto... https://resolve.rs/domains/rdap-missing.html

How does it mitigate the issues outlined in the article?

The root cause for the PHP vulnerability is trying to parse unstructured text. The actual information in WHOIS has structure: emails, addresses, dates, etc. This info should be provided in a structured format, which is what RDAP defines.

IMHO, there is no reason for a registrar to not support RDAP, and to have the RDAP server's address registered with ICANN.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#352
post #343
post #313

Earlier quoted context omitted.

Wouldn't it be easy for those software project, or a single central authority, to expose that WHOIS list through DNS? mobi.whoisserverlist.info. IN CNAME whois.nic.mobi. org.whoisserverlist.info. IN CNAME whois.publicinterestregistry.org. The presence of a referral mechanism inside the WHOIS protocol strikes me as a little odd.

You mean like an SRV record? https://circleid.com/posts/whois_server_address_registry/

Yes that works too. Thanks!

Though this relies on registrar publishing their own, and some don't. I meant that some other authority could publish them all, if they are known.

edit: It seems like {tld}.whois-servers.net is exactly that, CNAME to whois servers. Your link mentioned it. Thanks again.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#353
post #328

Earlier quoted context omitted.

No kidding. I had a one letter .tm domain name back in the 90s and they (Turkmenistan) increased the fee to $1000/year.

Tbh this seems like a win—you want to incentivize making as much use of those short domains as possible.

Is this like forcing a tenant out of a property because you wish to raise the rent?

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#354

Earlier quoted context omitted.

Tbh this seems like a win—you want to incentivize making as much use of those short domains as possible.

Is this like forcing a tenant out of a property because you wish to raise the rent?

its the opposite, its an increase of rent, because you want to increase rent

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#355

Earlier quoted context omitted.

Tbh this seems like a win—you want to incentivize making as much use of those short domains as possible.

Is this like forcing a tenant out of a property because you wish to raise the rent?

Yea, but in this case the property is very special. I don't think anyone has a right to own a "name" for perpetuity, especially such a short one—that's just extending property rights to a nonsensical place.

Granted, I also have zero respect for people who think that trademarks, patents, and copyright are still working to promote rather than stifle the arts and sciences, so I can understand why my above sentiment might rankle.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#356
post #140

Conjecture: control over tlds should be determined by capture the flag. Whenever an organization running a registry achieves a level of incompetence whereby its tld is captured, the tld becomes owned by the attacker. Sure there are problems with this conjecture, like what if the attacker is just as incompetent (it just gets captured again), or "bad actor" etc. A concept similar to capture the flag might provide for e…

Do we include possibility of phisically capturing the server?

It is an interesting question. Physical security is significant. On the other hand, the physical server is not necessarily the set of digital controls that establish the server's authenticity. The significant part is performing something similar to a "Turing test" whereby the capturer continues services just as if they were the previous operator of the service (but without the security holes).

OTOH, if the capture failed to also capture banking flows from customers to the service, then the capturer would have a paddle-less canoe.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#357

Earlier quoted context omitted.

Tbh this seems like a win—you want to incentivize making as much use of those short domains as possible.

Is this like forcing a tenant out of a property because you wish to raise the rent?

Countries owning their ccTLDs seems basically correct to me. If you rent a `.tm` domain, you're doing business with the nation of Turkmenistan: might want to think about whether a TLD pun is worth taking on that relationship.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#358

Earlier quoted context omitted.

IPv6 deployment is extra hard because we need almost every network in the world to get on board. Dnssec shouldn't be as bad, but for dns resolvers and software that build them in. I think it's a bit worse than TLS adoption in part just because of DNS allowing recursive resolution and in part DNS being applicable to a bit more than TLS was. But the big thing seems to be that there isn't a central authority like web br…

No. IPv6 deployment is tricky (though accelerating), but not all that scary, because it's easy to run IPv4 and IPv6 alongside each other; virtually everybody running IPv6 does that. The problem with DNSSEC is that deploying it breaks DNS . Anything that goes wrong with your DNSSEC configuration is going to knock your whole site off the Internet for a large fraction of Internet users.

I didn't say deploying IPv6 was scary.

Very aware that dual stack deployment is a thing. It's really the only sane way to do the migration for any sizable network, but obviously increases complexity vs a hopeful future of IPv6 only.

Good point about dnssec, but this is par for the course with good security technologies - it could break things used to be an excuse for supporting plaintext http as a fallback from https / TLS. If course having an insecure fallback means downgrade attacks are possible and often easy, so defeats a lot of the purpose of the newer protocols

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#359

Earlier quoted context omitted.

IPv6 deployment is extra hard because we need almost every network in the world to get on board. Dnssec shouldn't be as bad, but for dns resolvers and software that build them in. I think it's a bit worse than TLS adoption in part just because of DNS allowing recursive resolution and in part DNS being applicable to a bit more than TLS was. But the big thing seems to be that there isn't a central authority like web br…

Plus IPv6 has significant downsides (more complex, harder to understand, more obscure failure modes, etc…), so the actual cost of moving is the transition cost + total downside costs + extra fears of unknown unknowns biting you in the future.

Definitely there are fear of unknowns to deal with. And generally some business won't want to pay the switching costs over something perceived to be working.

IPv6 is simpler in a lot of ways than ipv4 - fewer headers/extensions, no support for fragmentation. What makes it more complicated? What makes the failure modes more obscure? Is it just that dual stack is more complex to operate?

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#360

Obviously there are a lot of errors by a lot of people that led to this, but here's one that would've prevented this specific exploit: > As part of our research, we discovered that a few years ago the WHOIS server for the .MOBI TLD migrated from whois.dotmobiregistry.net to whois.nic.mobi – and the dotmobiregistry.net domain had been left to expire seemingly in December 2023. Never ever ever ever let a domain expire.…

But if companies did that then I never would have been able to buy coolchug.com!

[deleted]
Post reply on HN