A Recycled IP Address Caused Me to Pirate Books by Accident
nickjanetakis.com
nickjanetakis.com
I wonder -- has anyone written code to spin up EC2 instances and check for subdomains pointing to the IP? Not sure how you could do that efficiently (does rdns work after the IP has been recycled?), but a starting point might be gathering as many NXDOMAIN subdomains as possible, filtering the ones at cloud providers, and starting instances until you get a match.
You could probably do that quite efficiently with Passive DNS data. There are a bunch of providers (e.g. FarSight, RiskIQ, many others) that collect and aggregate DNS request data and make it searchable over time.
RDNS is probably not going to be helpful. I'm not aware of any cloud provider setting a PTR record by default, and I think most won't allow you to do that at all.
If you're fast enough, it could still be cached in bing when you search.
Is IPv6 big enough to not recycle IPs in the modern high-churn deployment world? (It's probably big enough to give every human (or payment card holding customer) a few million blocks of IPs that they can personally control, and recycle IPs within each accountable block that)
For IPv6, clearly yes, at least so far. It's pretty typical to get at least a /64 aka LAN with a VPS. That's 18 x 10^18 addresses. ISP customers typically get a /56 (256 LANs) or a /48 (65536 LANs).
As a cloud host, it's embarrassing to have to explain to your customers that their shiny new IP is on an RBL because it was last used to steal passwords.
Seems like a better (or at least, complementary) solution would be more proactive monitoring of the abuse@ email and prompt terminations of clients who generate too many complaints.
There was lots of room to automate things like this, but instead we had a robust internal Powershell library and numerous Slack bots. They embraced the "do things that don't scale" mantra a little too literally.
Received an email from campus IT that my phone was compromised.
On further digging I would load up a game every once in a while on the campus wireless. That game used a popular/legit Chinese CDN to host something on their news page which was flagged.
Easier to just use my wireless phone package instead of explaining my phone wasn't compromised.
https://www.reddit.com/r/netsec/comments/5wizf8/hillaryclint...
It’s also possible you exposed a web service that wasn’t meant to be public.
What if the person was simply serving those files for himself over the internet (I've done it countless times) and Google caught it because the author was careless with handling DNS entries? Now DO has an IP and an accusation, more power is given to the DMCA-strike-first-ask-later status quo, all for what? It's not child pornography we're talking about, it's books for Christ's sake. There's no harm, it does not affect your life, why go through the effort of bringing trouble to someone else because of your own lack of care with sensitive issues such as DNS entries?
Author here, I reached out to DO because as a fellow content creator I felt morally obligated to report this.
I wouldn't like someone pirating my content and the people who created those 390,000+ PDFs put a lot of their time into making their content.
> There's no harm, it does not affect your life, why go through the effort of bringing trouble to someone else because of your own lack of care with sensitive issues such as DNS entries?
It does affect my life. I noticed now that there has been a couple of copyright infringement notices submit towards my domain (because of this PDF incident).
When you run an online business and your website is your entire brand, something like that is a big deal.
Also if you Googled for my name before I removed the A record, that SSL subdomain was coming up which was competing with my actual site's content. Not good!
Maybe do 301 redirections from ssl.nickjanetakis.com to your homepage, it can help with SEO.
I did go back dozens upon dozens of pages (just skipping around) to spot check it and there were a ton of pages.
It's a lot less results now because I wrote this article 6 days before I published it. At this point the A record has been removed for almost a week.
There are a couple of reasons to believe that this is not the case.
First, there were thousands of them. Someone having thousands of books is not unreasonable, of course, but both the breadth and depth of this collection is such that it is extremely unlikely it is someone's personal library.
Second, the PDFs aren't the actual books. They are just short blurbs describing the book and containing download deep links into bookfreenow.com. A couple examples [1] [2]. Clicking to create an account so you can start downloading redirects through some ad companies (and possibly some shady affiliate marketing companies), eventually reaching some download site (I think) that tells you no free slots are available and asks you to make an account.
(The bookfreenow.com pages for each book all seem to be the same template with just the book info substituted. Even the comments on the each page are from the same people, at the same times, and say the exact same things except they have the correct book title on each page. They aren't even trying to make it look like the comments are legit).
[1] http://bookfreenow.com/downloads/the-lm3900-a-new-current-di...
[2] http://bookfreenow.com/downloads/essential-orthopaedics-by-j...
Sounds like my personal library actually.
Second, the PDFs aren't the actual books. They are just short blurbs describing the book and containing download deep links into bookfreenow.com. A couple examples [1] [2]. Clicking to create an account so you can start downloading redirects through some ad companies (and possibly some shady affiliate marketing companies), eventually reaching some download site (I think) that tells you no free slots are available and asks you to make an account.
Well that’s a lot harder to explain in charitable terms! So is this even piracy, or just some kind of scam based on the promise of piracy?
You'll never actually get the book, because they don't have it. It's a scam to try to trap people who are trying to find free downloads of ebooks rather than paying for them.
(It's also kind of a funny definition of "save" you have there. With all due respect, if you want to save paid books, you should -- crazy as this may sound -- pay for them.)
Thus, in a "the enemy of my enemy is my friend" sort of way, I'm thankful for the OP for removing another fake ebook site from the Internet.
Nowhere near the scale of this though, just some background noise I'll ignore
I rebooted the VM to get a new IP address and the traffic stopped. It's somebody else's problem now.
Essentially don’t do anything you wouldn’t do in a wrong number call or if someone is knocking on your door looking for the previous tenant.
Same situation here. However being on the receiving end of a "formerly" Russian camgirl site makes this a little more than just noise. Any good ideas of what one could do with that?
That said ...
> A few months ago I started to receive an absurd amount of notifications, but I ignored them.
Really? I find it pretty amazing that he chalked it up to “Google is probably on drugs”, without even investigating at all!
Still, I should have clicked through to see what was up, but then again, the links looked very suspicious. I don't make a habit of clicking a bunch of unknown links sent via email, especially not when running Windows.
One of my old staging subdomains had an old Digital Ocean address left in it for a bit while we migrated some servers, and Google indexed some random ebook pirate site too, here[1] is a snap of the logs for anyone who is curious. Once I updated the DNS, Googlebot started to blow us up.
[1] https://node.zeneval.com/snaps/a79fe276b688da7b589ce539c9a4a...
I never would have even noticed, had it not been for Googlebot indexing the crap out of us, and causing 10s of thousands of sessions to be created in a short time which threw our Munin graphs off the charts.
The site we were staging ran fine, redis handled it without breaking a sweat, but we're not a public facing service, so I just straight up blocked Google Bot w/ an nginx rule.
There is plenty of reasons why one will prefer HTML verification over TXT DNS verification. It's usually faster, and more predictable. Plus DNS are far from being completely secure.
Google has probably already crawled that domain previously, and when it asked for that IP address, it found some other persons website.
I just double checked all of my old stuff - and there's not a trace left out there. Apparently, I cleaned up all my old DNS entries as things moved on, even though none of those domains are my 'brand' (as the author states it is his). As a non-security minded person, I find it hard to believe a security-minded person, whose good at his trade, forgets to do this.
If it has happened before, you'd be foolish to think that it's impossible to happen again.
I'm pointing out that his server isn't as uncompromisable as he's trying to lead the reader to believe.
> As the /var/log/nginx directory is owned by www-data, it is possible for local attackers who have gained access to the system through a vulnerability in a web application running on Nginx (or the server itself) to replace the log files with a symlink to an arbitrary file.
This assumes the web application is also running as www-data, which wouldn't be that smart.
[1] https://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-P...
My site is static too, which means it’s only being hosted through nginx from a non-root user.
The whole point is that these domain/IP combinations are forgotten which means it could take a long time before the issue is discovered.
I googled my own domain (site:flurdy.com) and it appends "- flurdy" to some of my static pages. But not for all, especially not for subdomain apps. So I am not 100% sure.
I don't think that's exactly what was going on though, although perhaps somebody else can chime in.
I don't think the "- Nick Janetakis" is actually in the title of the PDF, rather google has appended it to the actual title (the end of which has been replaced with an ellipsis).
I think google can get this from either the title of a html page or from a og:site_name entry of a html page (I'm not 100% on all this). It's possible that google took these from the "actual" ssl.nickjanetakis.com and still remembers the og:site_name and applies it to the pdf files?
But yes, PDFs are exploitable, like any file format.
https://www.sans.org/security-resources/malwarefaq/pdf-overv...
Does HE ever leave his office?
Between this quote and the bozo-level advice in the "Domain Validation Should Be More Strict" section ("I would like to see more services only allow for DNS based authentication by adding TXT records" is going to solve this problem? permanently decommissioning IPv6 addresses?), the one lesson I can take away from this article is to stay as far away as possible from any of this guy's security related courses.