Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jboger
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
jboger
13y ago
Indeed. I believe it might still be possible to arp spoof, if the arp table is leaking MAC. There seem to be no more IP packets leaking in this manner, though, which was the real concern, imo. DO has probably already remedied the rest, and
2.
▲
by
jboger
13y ago
It was, indeed, a matter of leaked packages intended for another recipient, but sent to all when not received properly. You are doing it correctly, but it should as of today no longer work. Can you try again? jb.
3.
▲
by
jboger
13y ago
I have now talked to Digitalocean, the issue has been identified and a fix has been applied. Fast, courteous, responsive. There is something to learn here for other cloud shops.
4.
▲
by
jboger
13y ago
Where do you want me to email logs? Thank you for your reply! I will send you user-id, so you can check tickets, and I will email you a full tcp-dump from my vps. Best Regards, Johan Boger
5.
▲
by
jboger
13y ago
I also want to point out that this entry was truncated. My full disclosure is, suitably, on full disclosure (the list). There, I explain that I consider DO one of the best cloud shops out there, and I will happily continue using them. I am
6.
▲
by
jboger
13y ago
As per guidelines of responsible disclosure, I contacted digitaloceans a good 10 hours before going public. I also contacted them again -before- going public, telling them I would do so, and why. I feel I have done my best to ensure this do
7.
▲
by
jboger
13y ago
I can confirm it is still displaying sensitive information.
8.
▲
Potential security flaw in network (digitalocean.com)
17 points
by
jboger
13y ago
|
14 comments