Phishers are hijacking legitimate cloud infrastructure
Posted by lschueller 1 day ago
Comments
Comment by illithid0 1 day ago
You can look at more of the capabilities we like to use at the LOTS project: https://lots-project.com/
Comment by Bender 1 day ago
local-zone: "workers.dev." always_null
local-zone: "pages.dev." always_null
local-zone: "vercel.app." always_null
local-zone: "netlify.app." always_null
local-zone: "dweb.link." always_null
local-zone: "ipfs.io." always_null
dig +short test.vercel.app
0.0.0.0Comment by embedding-shape 1 day ago
Considering you have ipfs.io on that list, I wonder if this is a typo for dweb.link actually?
Comment by Bender 1 day ago
Comment by ronsor 1 day ago
Comment by Bender 16 hours ago
1358 ublockorigin.github.io
446 curbengh.github.io
24 loathingkernel.github.io
22 ytdl-org.github.io
16 moomoohk.github.io
6 profanity-im.github.io
5 gtfobins.github.io
3 simonw.github.ioComment by psd1 20 hours ago
It's possible some submissions are hosted there on a user's domain and heavily themed, but i suspect it's just not a host for many submissions. I'm not verifying that; of course i may be wrong.
Comment by cutty_wise 1 day ago
Comment by heipei 1 day ago
Comment by crote 1 day ago
They simply believe doing the bare minimum of half-hearted anti-abuse is more profitable than doing proper KYC and risking missing out on a legitimate customer or two.
Comment by ronsor 1 day ago
Comment by crote 1 day ago
You've got to remember that those "free" cloud services are primarily intended as a way to do marketing. You try it out for free because the barrier to entry is so low, then you pay for it when you deploy it to prod. Alternatively: you start with it for free, then are tied to it when your site suddenly gets popular and they start extorting you.
For legitimate use KYC on something like Cloudflare really isn't that big of a deal, in my opinion. I already had to submit my real name and address for my domain registration, and the credit card used to pay for my hosting isn't exactly anonymous either. Heck, when I tried to switch to Hetzner they even asked for a copy of my ID card! We can pretend Cloudflare can't already figure out who I am, but we all know that isn't true.
And of course KYC isn't the only way to solve this. Cloudflare could've also chosen to give new (unpaying / unverified) users a restricted account, which would for example display a Cloudflare ad around it (like .tk domains back in the day), or restrict it to a certain IP range, or only display content after logging in, or after a click-through page. For the attack described in the article they could also force the potential user to supply a subdomain for the service to live on, so it isn't hidden behind Cloudflare's ".workers.dev" and ".pages.dev".
Cloudflare chooses not to do any of this - which in turn makes them the perfect platform for criminals. If that's what they want to, then that's totally fine - but then they should be treated like all the other "bulletproof hosting" organisations out there.
Comment by ronsor 1 day ago
I probably would not use Cloudflare if it had KYC simply because I do not want to be interrogated every time I try to do something meaningful online. It is a waste of time because criminals will integrate "verify with stolen identity" into their pipeline tomorrow, while legitimate users are stuck with the headaches.
An interstitial warning page is probably the happy medium, and what ngrok already uses now.
Comment by crote 1 day ago
No, it was 100% their own fraud prevention. They blocked my account almost immediately after registration, and they refused to unblock it even after I sent them my ID. My best guess is that they really didn't like that I signed up with a Protonmail address.
Comment by MyMemoryfails 23 hours ago
Malware can extract data from embedded metadata from media, there's even video by benn jordan about it.
Comment by psd1 20 hours ago
No, at worst they could conduct an astroturf campaign and manipulate the overton window. I suspect that Noam Chomsky attains correctness by volume and by forgetting the times he was wrong, but the whole "manufactured consent" concept looks prescient.
Comment by GolfPopper 1 day ago
Comment by KennyBlanken 1 day ago
Craigslist's revenue, and his wealth, heavily came from pimps and human traffickers. If anyone thinks they weren't aware of what was going on, they're fooling themselves.
When CL shut those sections down, it only did so because state AGs were starting to make a lot of noise about prosecuting them. Now Craig Newmark makes a lot of noise about all the good things he's doing, and it's primarily for SEO because the only other thing he and the other guy were getting in the news for was running a site that was profiting off human trafficking and prostitution.
All those ads went to Backpages, which most people had never heard of until state DAs start going after them. And how strange that Backpages never did anything on its own about the huge influx of sexual solicitation content...
Comment by psd1 20 hours ago
Is Craig driving a slightly nicer car from it, or is it more of a megayacht thing?
Comment by inigyou 1 day ago