Exactly. I know I have overlooked important email alerts before. It's only human when you are so used to deleting so much spam all the time. Other than that I would say that the thief has to be in cahoots with the registrar. I dunno...
Exactly. I know I have overlooked important email alerts before. It's only human when you are so used to deleting so much spam all the time. Other than that I would say that the thief has to be in cahoots with the registrar. I dunno...
He is most definetly in "cahoots" The registrar in Sleazy dreams case was directi, an Indian Registrar. I think you'll find this newest jack was transferred there too.
I'm not positive, but I was under the impression that under the new rules, an ICANN-accredited registrar can jack your names regardless of lock status..."locked" means "please don't jack this domain," but it's just a request, not enforced by ICANN. I can't find anything that confirms or refutes this on ICANN's site. They say the current registrar can deny a transfer based on lock status if the domain owner can turn the lock on and off, but I can't find where they go into the technical details. Any registrar gurus know how this works?
I like ICANN's answer in a FAQ for what to do if your name is jacked and the previous registrar won't do anything: "What happens if my registrar does not want to initiate a dispute for me? Registrars are not required to initiate disputes. If your chosen registrar is uninterested in helping you with your case, look for a new registrar who is. There are over 200 ICANN-accredited registrars. See the full list here." ICANN won't let domain holders dispute a domain hijacking; only registrars can.
I registered a new domain last weekend at Registerfly. It was automatically locked. At least it was reported as being locked without having to lock it after registration.
When I read about Sleazy's problem, I went back and double-checked all my domains, which had all been locked. The new one was not locked, and a handful of others were also open.
This is really disturbing.
I'm guessing it's bugs in the lock updating code. It is very new and probably hasn't been tested enough in the real world (I'm talking about the routines to do the bulk locking at the registrar, not the locking of domains themselves).
I can tell you some things that the guys over at DomainNameSystems.com see ..
people call customer support and try to 'convince' them they are the owner and ask them to 'remind' them of login info (it doesn't work at his place as he requires faxed proof hehe)
People use the same password for their domains as they do with alot of affiliate programs or hosting sites. If you have an untrustworthy employee at a sponsor program they can give that info a shot at a registrar and get lucky. (do NOT use the same password on your registrar that you use ANYWHERE else!)
People use unscrupulous registrars or registrars with unscrupulous employees ... could be lots of palm greasing if its a good domain.
Best solutions is to use a registrar with a good solid reputation and use a totally unique password.
If at first you do succeed - try to hide your astonishment.
HR merchant accounts from 3.45%
solid biz since 98
victoriakozub AT gmail.com
skype: victoria.kozub | ICQ: 74296746
if it is locked and noone hacks your registrar and email account?
Thanks, and only serious replies please
keep in mind... the more you discuss this topic, the more hijackers you create.
imho, it would be wise to keep these discussions private instead of creating "how to guides" for people.
there is no simple solution to combat this problem... if a hijacker wants your domain bad enough they will KEEP trying to steal it. keep rechecking your lock status and performing daily checkups on your domains. test your registrar's security... secret shop them trying to get info... if they fail, move out of there asap or get that person FIRED/reprimanded. it pays to be paranoid.
"Just because you're paranoid doesn't mean they aren't after you"
For more details on WDPRS do a search for it here (I've posted more details in previous posts) and/or on Google ... in a nutshell, the doors are still wide open -and, again to reiterate, registrar-lock, passwords, etc will NOT protect one's domains from exploitation via the WDPRS.
Ron
Domagon - Website Management and Domain Name Sales
Comment