Closed
Bug 1305332
Opened 9 years ago
Closed 9 years ago
Heroku Subdomain takeover - http://connect.webmakerprototypes.org/
Categories
(Infrastructure & Operations :: DNS and Domain Registration, task)
Infrastructure & Operations
DNS and Domain Registration
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: griffin.francis.1993, Unassigned)
References
Details
(Keywords: reporter-external, wsec-takeover)
Attachments
(2 files)
User Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
Steps to reproduce:
Domain - http://connect.webmakerprototypes.org/
This attack vector utilizes DNS-entries pointing to Service Providers where the pointed subdomain is currently not in use. Depending on the DNS-entry configuration and which Service Provider it points to, some of these services will allow unverified users to claim these subdomains as their own.
Check your DNS-configuration for subdomains pointing to services not in use.
https://labs.detectify.com/2014/10/21/hostile-subdomain-takeover-using-herokugithubdesk-more/
Actual results:
I was able takeover the domain as there was an existing DNS record pointing to a Heroku record.
Expected results:
The CNAME record should be removed as this domain is no longer within use.
Comment 1•9 years ago
|
||
$ dig connect.webmakerprototypes.org +short
webmaker-connect.herokuapp.com.
us-east-1-a.route.herokuapp.com.
23.23.252.69
Comment 2•9 years ago
|
||
Thanks Griffin!
We recently did an audit of these domains in bug 1268064. I also checked DNS and don't see any references to this domain.
:digi - Any idea where else we would have DNS managed so we can audit those sources as well?
Flags: needinfo?(bhourigan)
Comment 3•9 years ago
|
||
(In reply to Jonathan Claudius [:claudijd] (use NEEDINFO) from comment #2)
> Thanks Griffin!
>
> We recently did an audit of these domains in bug 1268064. I also checked
> DNS and don't see any references to this domain.
>
> :digi - Any idea where else we would have DNS managed so we can audit those
> sources as well?
It looks like the domain webmakerprototypes.org is route53, I don't have any visibility into our AWS accounts. I'd ping r2 to find out if CloudHealth can export route 53 data. We also have limited DNS hosting at MarkMonitor.
Flags: needinfo?(bhourigan)
Comment 4•9 years ago
|
||
:r2 - can you please privately send me a full list of route53 domains that point to herokuapp.com or herokussl.com? I'd like to take a peek at them see what others are vulnerable to this issue.
Flags: needinfo?(riweiss)
Comment 5•9 years ago
|
||
I did a search for herokuapp.com and herokussl.com and came up with nothing. Then I searched for just heroku and also came up with nothing. At this time, CloudHealth only has access to the following metadata about a hosted zone:
Account
Hosted Zone Id
Name
Caller Reference
Config Comment
Config Private Zone
Record Set Count
Has Comment
Tags
First Discovered
Last Discovered
Active?
If there is a CNAME record pointing to heroku, CloudHealth may not have knowledge of it.
Flags: needinfo?(riweiss)
Comment 6•9 years ago
|
||
:gene - Could you help me obtain a list of domains we have pointing at herokuapp.com and herokussl.com from route53? I'm being told you have visibility into this and I would like to audit for other abandoned domains.
Flags: needinfo?(gene)
Comment 7•9 years ago
|
||
Double-checked primary DNS records (non-route 53) to verify we're good there, no unclaimed domains pointing to Heroku destinations. Updating details on audit bug 1268064.
Updated•9 years ago
|
Assignee: nobody → infra
Group: websites-security → infra
Component: Other → Infrastructure: DNS
Product: Websites → Infrastructure & Operations
QA Contact: cshields
Comment 8•9 years ago
|
||
Can this be closed out now?
Comment 9•9 years ago
|
||
I'm still able to resolve the host using `dig connect.webmakerprototypes.org +short`, however, I don't know whether this points to a account we control or not. We should remove this record from Route53 if its not in use.
Comment 10•9 years ago
|
||
This particular needinfo was resolved in comment 6, so clearing it.
Flags: needinfo?(gene)
| Reporter | ||
Comment 11•9 years ago
|
||
I believe I still have control over this subdomain. I'll double check it now.
| Reporter | ||
Comment 12•9 years ago
|
||
I can confirm that I still have ownership over this subdomain. Would you like me to release it so Mozilla can reclaim it?
| Reporter | ||
Comment 13•9 years ago
|
||
Comment 14•9 years ago
|
||
Some information to help with routing of this...
$ dig connect.webmakerprototypes.org +short
webmaker-connect.herokuapp.com.
us-east-1-a.route.herokuapp.com.
23.23.165.47
$ whois webmakerprototypes.org | grep 'Name Server'
Name Server: NS-1284.AWSDNS-32.ORG
Name Server: NS-524.AWSDNS-01.NET
Name Server: NS-1724.AWSDNS-23.CO.UK
Name Server: NS-433.AWSDNS-54.COM
:digi - can you help me understand who owns the delegation to Route53 for this domain? I'd like to trace the ownership route so we can get this fully resolved.
Status: UNCONFIRMED → NEW
Ever confirmed: true
Flags: needinfo?(bhourigan)
Comment 15•9 years ago
|
||
:claudijd
I think it might be a MoFo account, CloudHealth has nothing but I found bug 1146925 which was filed by a foundation employee.
Flags: needinfo?(bhourigan)
Comment 16•9 years ago
|
||
:cade - can you help us with this? Basically, we have a DNS entry pointing to connect.webmakerprototypes.org, which had an unclaimed VHOST in Heroku that Griffin (a bounty contributor) was able to claim. He still has control over this domain and is willing to offer it back. It's possible however that the subdomain is no longer in use and the DNS entry might just need to be removed from Route53.
Flags: needinfo?(cade)
Comment 17•9 years ago
|
||
It's a dead domain, we can just remove the record in Route 53 - I'll do that now.
Flags: needinfo?(cade)
Comment 18•9 years ago
|
||
Record deleted.
Comment 19•9 years ago
|
||
:griffin - sounds like the claim is no longer relevant. You can hold or release, as the dangling DNS entry has been nuked. thanks again for reporting and making us aware of this issue!
Flags: sec-bounty?
Updated•9 years ago
|
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Updated•9 years ago
|
Flags: needinfo?(jclaudius)
Updated•9 years ago
|
Flags: sec-bounty?
Flags: sec-bounty+
Flags: needinfo?(jclaudius)
Comment 20•8 years ago
|
||
Verified NXDOMAIN connect.webmakerprototypes.org per comment 18, removing security group after checking with :claudijd.
Group: infra
Updated•7 years ago
|
Keywords: wsec-takeover
Updated•2 years ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Description
•