540 karma · joined October 30, 2013
http://www.test.com https://www.test.com JavAscRipt://www.test.com%0aalert(1)
<a href="https://www.test.com">test</a> [test](https://www.test.com)
tst
Think you're on to something that this talk points out very well.
The idea would be that a user has simply deleted/released the zone for a specific domain under their account. This could have happened because they plan on moving it later or because a lack of payment/service termination has occurred. This allows an attacker to obtain thousands of fresh domains easily with very little effort and likely no payment at all which can be used in malware campaigns/etc. Some common things I saw were indeed older unused domains, domain portfolio's of domain resellers/squatters, and even domains in restricted TLD spaces such as .gov, .edu, etc. These would certainly have value despite no longer being used.
Let me know if I've been unclear or am missing something here.
The main idea of this post is to be informational/raise awareness since I'd argue a large majority of users don't expect this behavior to occur.
At the very least I'm happy that some people have seen this more as a study of this pattern of functionality being an issue instead of this being only a DigitalOcean problem. I've seen (and have been reached out by) multiple people realizing this affects their company as well which has been awesome to watch.
It was my plan to delete the domains (or at least null route them so others couldn't take them over with more malicious intent). However my account was banned before I could do so.
Wasn't really trying to be very "leet" with this hack, was just something fun I decided to do. Also deleting the accounts wouldn't be incredibly hard to do at all anyways.
I expected this type of feedback I suppose, the point wasn't to show a security vulnerability in GitHub. Was more just a lighthearted post.