Closed Bug 1305332 Opened 9 years ago Closed 9 years ago

Heroku Subdomain takeover - http://connect.webmakerprototypes.org/

Categories

(Infrastructure & Operations :: DNS and Domain Registration, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: griffin.francis.1993, Unassigned)

References

Details

(Keywords: reporter-external, wsec-takeover)

Attachments

(2 files)

Attached file Images POC.zip
User Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36 Steps to reproduce: Domain - http://connect.webmakerprototypes.org/ This attack vector utilizes DNS-entries pointing to Service Providers where the pointed subdomain is currently not in use. Depending on the DNS-entry configuration and which Service Provider it points to, some of these services will allow unverified users to claim these subdomains as their own. Check your DNS-configuration for subdomains pointing to services not in use. https://labs.detectify.com/2014/10/21/hostile-subdomain-takeover-using-herokugithubdesk-more/ Actual results: I was able takeover the domain as there was an existing DNS record pointing to a Heroku record. Expected results: The CNAME record should be removed as this domain is no longer within use.
$ dig connect.webmakerprototypes.org +short webmaker-connect.herokuapp.com. us-east-1-a.route.herokuapp.com. 23.23.252.69
Thanks Griffin! We recently did an audit of these domains in bug 1268064. I also checked DNS and don't see any references to this domain. :digi - Any idea where else we would have DNS managed so we can audit those sources as well?
Flags: needinfo?(bhourigan)
(In reply to Jonathan Claudius [:claudijd] (use NEEDINFO) from comment #2) > Thanks Griffin! > > We recently did an audit of these domains in bug 1268064. I also checked > DNS and don't see any references to this domain. > > :digi - Any idea where else we would have DNS managed so we can audit those > sources as well? It looks like the domain webmakerprototypes.org is route53, I don't have any visibility into our AWS accounts. I'd ping r2 to find out if CloudHealth can export route 53 data. We also have limited DNS hosting at MarkMonitor.
Flags: needinfo?(bhourigan)
:r2 - can you please privately send me a full list of route53 domains that point to herokuapp.com or herokussl.com? I'd like to take a peek at them see what others are vulnerable to this issue.
Flags: needinfo?(riweiss)
I did a search for herokuapp.com and herokussl.com and came up with nothing. Then I searched for just heroku and also came up with nothing. At this time, CloudHealth only has access to the following metadata about a hosted zone: Account Hosted Zone Id Name Caller Reference Config Comment Config Private Zone Record Set Count Has Comment Tags First Discovered Last Discovered Active? If there is a CNAME record pointing to heroku, CloudHealth may not have knowledge of it.
Flags: needinfo?(riweiss)
:gene - Could you help me obtain a list of domains we have pointing at herokuapp.com and herokussl.com from route53? I'm being told you have visibility into this and I would like to audit for other abandoned domains.
Flags: needinfo?(gene)
Double-checked primary DNS records (non-route 53) to verify we're good there, no unclaimed domains pointing to Heroku destinations. Updating details on audit bug 1268064.
Assignee: nobody → infra
Group: websites-security → infra
Component: Other → Infrastructure: DNS
Product: Websites → Infrastructure & Operations
QA Contact: cshields
Can this be closed out now?
I'm still able to resolve the host using `dig connect.webmakerprototypes.org +short`, however, I don't know whether this points to a account we control or not. We should remove this record from Route53 if its not in use.
This particular needinfo was resolved in comment 6, so clearing it.
Flags: needinfo?(gene)
I believe I still have control over this subdomain. I'll double check it now.
I can confirm that I still have ownership over this subdomain. Would you like me to release it so Mozilla can reclaim it?
Attached image Subdomain Ownership.png
Some information to help with routing of this... $ dig connect.webmakerprototypes.org +short webmaker-connect.herokuapp.com. us-east-1-a.route.herokuapp.com. 23.23.165.47 $ whois webmakerprototypes.org | grep 'Name Server' Name Server: NS-1284.AWSDNS-32.ORG Name Server: NS-524.AWSDNS-01.NET Name Server: NS-1724.AWSDNS-23.CO.UK Name Server: NS-433.AWSDNS-54.COM :digi - can you help me understand who owns the delegation to Route53 for this domain? I'd like to trace the ownership route so we can get this fully resolved.
Status: UNCONFIRMED → NEW
Ever confirmed: true
Flags: needinfo?(bhourigan)
:claudijd I think it might be a MoFo account, CloudHealth has nothing but I found bug 1146925 which was filed by a foundation employee.
Flags: needinfo?(bhourigan)
:cade - can you help us with this? Basically, we have a DNS entry pointing to connect.webmakerprototypes.org, which had an unclaimed VHOST in Heroku that Griffin (a bounty contributor) was able to claim. He still has control over this domain and is willing to offer it back. It's possible however that the subdomain is no longer in use and the DNS entry might just need to be removed from Route53.
Flags: needinfo?(cade)
It's a dead domain, we can just remove the record in Route 53 - I'll do that now.
Flags: needinfo?(cade)
Record deleted.
:griffin - sounds like the claim is no longer relevant. You can hold or release, as the dangling DNS entry has been nuked. thanks again for reporting and making us aware of this issue!
Flags: sec-bounty?
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Flags: needinfo?(jclaudius)
Flags: sec-bounty?
Flags: sec-bounty+
Flags: needinfo?(jclaudius)
Verified NXDOMAIN connect.webmakerprototypes.org per comment 18, removing security group after checking with :claudijd.
Group: infra
See Also: → 1465982
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: