TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Taking Over 20K DigitalOcean Domains via a Lax Domain Import System (2016)

114 pointsby johnx123-upover 4 years ago

18 comments

zenincognitoover 4 years ago
I did the same to Shopify about 12 months ago or less and their response was , first please remove the takeover from your panel and then second we are aware but wont fix.<p>It is absolutely bewildering that they wouldn&#x27;t take this seriously. The owner of my takeover tried to add the domain to their panel and they couldn&#x27;t. This adds a whole new level of customer service to their backlog which should essentially be mitigated by an automation of sorts via a txt record or cname confirmation. Seems to me that they are more interested in not fixing it but happy to waste hours of their agents trying to fix such takover problems.
评论 #25223914 未加载
评论 #25219595 未加载
SheinhardtWigCoover 4 years ago
Nobody looks good here. The researcher did far more damage than was necessary to demonstrate the vulnerability, and DO’s response sucks.
评论 #25218594 未加载
评论 #25218586 未加载
Neil44over 4 years ago
I did similar on 123 Reg a few years ago to rescue a client.<p>Their ex IT guy had half transferred their domain from namecheap to 123, changing the IPS tags to 123 but not accepting from 123&#x27;s end. Then he got fired. The NS&#x27;s were still pointing to Namechearp so everything continued to work, until the domain expired because neither company felt able to renew it, both referring me to nominet to resolve. Meanwhile the client was hard down.<p>After retiring to the bathroom to have a think I realised that 123 didn&#x27;t really care who accepted the domain as long as the tags were right. So I created a new account, initiated a transfer and went through the steps, and the domain popped into my account, able to be renewed.<p>I did wonder if there would be a way to mass import domains that people hadn&#x27;t accepted into their accounts yet but didn&#x27;t actually try anything.
评论 #25222160 未加载
tzsover 4 years ago
The article says that Route 53 uses randomly generated name server names, so if at your registrar you are pointing your domain to Route 53 name servers, and then you remove the records for your domain at Route 53 but leave the record at your registrar pointing to Route 53, it is unlikely that another Route 53 customer could add your domain and get your traffic. Their randomly generated Route 53 name server names would probably not match yours.<p>I wonder how effective that actually is? As far as I know there is nothing in the DNS protocol like the &quot;Host&quot; header of HTTP that allows the name server to tell what name the client knows the name server by. Two differently named name servers will actually be distinct only if they have different IP addresses.<p>The question then is how many IP addresses does Route 53 have for name servers?<p>Ideally, you&#x27;d want to have a separate IP address for each customer&#x27;s name server. Do any of the big hosting companies do that?<p>I&#x27;d expect that they could do it without needing a lot of extra IP addresses by giving each customer who has a static IP address for the hosts an option to have traffic to port 53 of that IP address transparently sent to the hosting provider&#x27;s name servers along with tagging to let the name servers identify what IP address it was for so it can serve the right name data.<p>That would allow each customer to have as many apparently dedicated name servers as they have hosts with static IP addresses.
评论 #25220833 未加载
Vespasianover 4 years ago
Maybe I&#x27;m missing something here, but isn&#x27;t this only a problem if you migrate your domain DNS away from DO and forget to also change the nameserver with your registrar?<p>So of course, if you tell the world &quot;These guys over there are responsible for resolving my domains&quot; you shouldn&#x27;t be surprised if they actually do this.
评论 #25218834 未加载
评论 #25220544 未加载
trolliedover 4 years ago
Discussion from 4 years ago: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12364297" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12364297</a>
评论 #25219166 未加载
londons_exploreover 4 years ago
GitHub pages has the exact same issue right?<p>Nobody seems to complain at that... If I point my domain at GitHub, but then don&#x27;t complete the setup process in the GitHub UI, I can&#x27;t really complain if someone else sets it up...
评论 #25219069 未加载
评论 #25219177 未加载
Lunrtickover 4 years ago
This was posted in 2016, but their process hasn&#x27;t changed. I&#x27;m not sure if it&#x27;s actually caused any real damage yet (usually you&#x27;d add your domain fairly quickly), but it seems crazy that in between declaring DO as your DNS provider and importing the domain on DO, it can be stolen.
cr3ativeover 4 years ago
DigitalOcean have a HackerOne programme which... is a much better way of getting an issue like this flagged in a reasonable manner. I&#x27;m not surprised the account got banned. <a href="https:&#x2F;&#x2F;hackerone.com&#x2F;digitalocean" rel="nofollow">https:&#x2F;&#x2F;hackerone.com&#x2F;digitalocean</a>
评论 #25218784 未加载
评论 #25218871 未加载
mattlover 4 years ago
I wish Digital Ocean would do something about the amount of abuse from their network.
评论 #25221339 未加载
t0astbreadover 4 years ago
I&#x27;m surprised DO even allows you to add 20 thousand domains to your account in one go without prior communication.
评论 #25220214 未加载
Aeolunover 4 years ago
Clearly this an issue, and clearly AWS has at least mitigated it. How hard is it for other probiders to do the same?<p>If they’re not doing it, I suppose they feel that the reputation hit they take if someone misuses it is better than the lost dollars from a little bit more friction during setup.
评论 #25218825 未加载
评论 #25218995 未加载
manojldsover 4 years ago
Wait, just doing it on one of those 20k domains wouldn&#x27;t have sufficed to show proof?
ChrisArchitectover 4 years ago
2016! why post this?<p>lots of previous discussion: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12364297" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12364297</a>
yayrover 4 years ago
this article should be flagged [2016]
vegardxover 4 years ago
I don&#x27;t think there are any solutions to this on a technical level. There&#x27;s no way for you to prove that you own the domain, besides setting the NS-records.<p>You can partially mitigate the issue the way Amazon does it. But even that isn&#x27;t foolproof and I suspect they have other reasons than just this for their approach.
评论 #25219200 未加载
fakeyguyover 4 years ago
Can someone share what happened? I don&#x27;t understand.
评论 #25219145 未加载
shripadkover 4 years ago
2016 article