Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Australia Crime Security The Internet IT Your Rights Online

Domain Theft-for-Ransom Hits css-tricks.com and Others 147

An anonymous reader writes "Chris Coyer at css-tricks.com has had his domain transferred from GoDaddy.com to a registrar in Australia where it's being held for ransom. Several other domains have experienced the same theft by what seems to be the same person, and the registrars seem helpless to do anything about it."
This discussion has been archived. No new comments can be posted.

Domain Theft-for-Ransom Hits css-tricks.com and Others

Comments Filter:
  • Don't Use GoDaddy (Score:5, Interesting)

    by sexconker ( 1179573 ) on Friday December 02, 2011 @08:54PM (#38246258)

    Don't use GoDaddy.
    If you needed any more reasons to stay far away from GoDaddy and their shitty advertising, RTFA.

            So far they have found this has happened to around 12 accounts, all within the "Web Design" genre (so most likely a targeted attack).
            There is no accessible log from with your GoDaddy account to see what/when things happened.
            They do [claim to] have access logs, but they can't [won't] share that information with me.
            The domain was transferred away from GoDaddy the evening of Nov 20th
            They [claim to] have, but cannot [won't] provide me with, the email address used to transfer the domain away.
            GoDaddy confirmed my global account email has never been changed, but it WAS changed for the domain css-tricks.com prior to the move.
            The request to unlock the domain happened on Nov. 14th at 4:30pm Mountain Time. Normally there is a 5-7 day waiting period, but GoDaddy offers instant transfer and they remarked that it was unusual that the hacker chose not to do that.
            They confirmed no other domains have left my account.

    [Stuff in brackets is mine.]

  • Re:Umm.... (Score:4, Interesting)

    by Meshach ( 578918 ) on Friday December 02, 2011 @09:00PM (#38246324)

    From TFA: "We have reviewed your claim and we will contact PlanetDomain and request an FOA (Form of Authorization) for the transfer. If their records also show the same registrant at the time of transfer, we will work with them to see if they can transfer the domain name back. However, they are not required to transfer the domain name back." Not required? As in, he paid for it, it's legally registered to him, and then someone just stole it away and they don't have to give it back? Isn't that theft?

    I don't know about theft as much as mismanagement by GoDaddy. If the domain was not expired then it should be reverted back to the rightful owner. If it actually did expire he may be SOL (although that is pretty low of GoDaddy to not at least give him notice).

  • Gmail problem (Score:5, Interesting)

    by Albanach ( 527650 ) on Friday December 02, 2011 @09:29PM (#38246540) Homepage

    it looks like the big problem here is that 4 years on it's still apparently possible for websites to silently create filters on gmail accounts if a logged in user visits their site. That effectively allows a malicious site to compromise hosting accounts, bank accounts and much more.

  • by Urza9814 ( 883915 ) on Friday December 02, 2011 @09:37PM (#38246586)

    If only I had mod points. Gandi is by far and without a doubt the best domain registrar out there. Hell, if they were double or even triple the price of GoDaddy, I'd still be using them. (From what I've seen their prices are on par with everyone else.)

  • by Nethead ( 1563 ) <joe@nethead.com> on Friday December 02, 2011 @09:39PM (#38246610) Homepage Journal

    http://www.wired.com/politics/law/news/2000/01/33571 [wired.com]

    Network Solutions' administrative policies are once again being blamed for Internet domain hijackings that took at least brief control over some major Web domains.
    Beginning Saturday, an unidentified individual began attempts, some successful, to seize control over domains including major Web hosting service Exodus, Web standards body World Wide Web Consortium and Emory University.
    And all the misappropriation required was a simple spoofing of email addresses.

    The only good thing about it was getting my name in Wired.

  • by jamesh ( 87723 ) on Friday December 02, 2011 @09:54PM (#38246666)

    Did anyone else notice that the phone number looks like a hex string?

    43:54:35:34:55 => CT54U

    it doesn't look particularly meaningful unless they were stupid enough to encode a password or something in it.

  • Re:Gmail problem (Score:3, Interesting)

    by headkase ( 533448 ) on Friday December 02, 2011 @10:19PM (#38246812)
    I don't even bother to moderate anymore. I read the comments at -1 because that is the only way to combat moderator abuse. It happens too often that you see a completely worthwhile comment moderated -1. Slashdot's game has been fixed. I blame the "Friend/Foe" system: that let's you instantly know whether to mod up/down if you were so inclined.
  • ICANN (Score:4, Interesting)

    by DaMattster ( 977781 ) on Friday December 02, 2011 @10:33PM (#38246886)
    Does ICANN offer any assistance with this matter? Can't they just yank the domain back?
  • Re:Don't Use GoDaddy (Score:5, Interesting)

    by Anonymous Coward on Friday December 02, 2011 @11:54PM (#38247224)

    Don't use GoDaddy.

    To be fair, this wasn't strictly a GoDaddy Issue. TFA stated:

    This is not isolated to GoDaddy. Original registrants varied, see below.

    Which then listed multiple GoDaddy's, a 1and1.com, and a NetworkSolutions.com. This sounds more like the fact that GoDaddy happens to be the big horse (ala Microsoft) so it's likely going to be attacked me most. Not using GoDaddy might be good advice but it seems like it's also not a guarantee.

    The bigger issue is that there's no authoritative way to quickly re-gain such lost domains. And domain name disputes are always a huge PITA. Given the value of a domain name and how easy it is to sit on it once stolen, costing some business tons of money, I wouldn't be surprised if this starts happening more.

    One thing that keeps popping out is the fact that they're all being xfered to PlanetDomain.com. ICANN needs to revoke their ability to register domains.

  • Re:Umm.... (Score:5, Interesting)

    by wygit ( 696674 ) on Saturday December 03, 2011 @12:13AM (#38247308)

    And the perps haven't deprived the victims of their property? Not sure what you mean here.

    With copyright infringement, the original owners still have their stuff. With this, the victim doesn't.

  • Re:Gmail problem (Score:5, Interesting)

    by houstonbofh ( 602064 ) on Saturday December 03, 2011 @02:09AM (#38247836)
    It is only temporary... Go ahead and moderate. Read at -1 and just give points to people unfairly trolled.

The moon is made of green cheese. -- John Heywood

Working...