|
#1
|
||||
|
||||
|
Gmail - Hack Leads to Domain Theft
Go Daddy steps in to return domain stolen as a result of flaw in Gmail.
A hacker used a deficiency in Gmail to steal a domain name this month. The theft was of DavidAirey.com, a popular graphic designer’s personal site that attracts a couple thousand unique visitors a day. So how did it happen, and what can you do to protect yourself? Furthermore, how could a popular domainer site lead to even more lost domains? First, here’s how it happened in a nutshell: 1. DavidAirey.com was registered through a webhost, ICDSoft. 2. The hacker contacted the webhost through a support ticket asking to unlock the domain and send the EPP transfer code. 3. The hacker compromised David Airey’s Gmail account to forward any domain transfer requests to his own email account. 4. The hacker transfered the domain to a GoDaddy account without Airey’s knowledge. 5. He then forwarded the domain to Bebu.net, a parked page at Sedo Fortunately, Airey was able to work with GoDaddy to get the domain back. He’s lucky the domain was transferred to GoDaddy. Despite some of its flaws, at least GoDaddy isn’t a fly-by-night registrar. The hacker was able to add a forwarding rule to Airey’s Gmail account, as Airey recounts on his blog. Airey also explains how to check that your account hasn’t been compromised. Here’s what you can do to protect yourself: 1. Never use a free or hosted email account as your whois address. Instead, use a pop email address from a domain you own. Lock the heck out of that domain. 2. Never register a domain through a webhosting company. Webhosts are good (sometimes) at hosting web sites, but they are typically just domain resellers with lax domain security controls. A good domain registrar would never let someone simply e-mail them to unlock a domain and send the transfer code. Now here’s the really scary part. A popular domain web site, DomainTools, could compromise your entire portfolio of domains. DomainTools offers a product called “Registrant Search” that allows anyone to purchase a list of domains registered by a particular person or with a particular email address. If Airey had a portfolio of domains, the hacker could have easily stolen all of his domains. About Go Daddy GoDaddy.com is the world's largest domain name registrar and is the flagship company of The Go Daddy Group, Inc. The Go Daddy Group of companies also includes Wild West Domains, Inc., a reseller of domains and domain-related products and services; Domains by Proxy, a private registration service; Starfield Technologies, a research and development affiliate; and Blue Razor Domains, a membership-based discount registrar. Website: www.godaddy.com
__________________
James Ketchell - Serchen Interactive - Web Host Directory Serchen Interactive - www.serchen.com www.webhostdir.com | www.dedicatedserverdir.com | www.saasdir.com www.domainsdir.com | www.onlinebackupdir.com Submit your news and articles here James Ketchell - Serchen Interactive - Web Host Directory James Ketchell James Ketchell |
|
#2
|
|||
|
|||
|
Just to clarify on this:
Quote:
The transfer request was submitted using the approprate means. The fact that the hacker had access to David's passwords is disturbing, but it has nothing to do with ICDSoft's security. |
![]() |
| Bookmarks |
«
Previous Thread
|
Next Thread
»
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Why you need domain names | ashish | Domain Name Issues | 53 | Yesterday 09:40 PM |
| Don't Risk Losing Your Business Domain Name! | NewsDesk | Web Hosting & Internet Articles | 0 | Sep 4th, 2006 07:13 AM |
| Information Highwaymen and Your Domain | NewsDesk | Web Hosting & Internet Articles | 0 | Sep 15th, 2005 10:08 AM |
| The Domain Name Gold Rush | NewsDesk | Web Hosting & Internet Articles | 0 | Aug 5th, 2005 05:39 AM |
| New Wave of Internet Domain Name Theft Identified | NewsDesk | Web Hosting & Internet News | 0 | Jan 26th, 2005 04:58 AM |
All times are GMT -6. The time now is 08:59 PM.




A hacker used a deficiency in Gmail to steal a domain name this month. The theft was of DavidAirey.com, a popular graphic designer’s personal site that attracts a couple thousand unique visitors a day. 




Linear Mode



