Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 01-18-2005, 07:12 AM   #1
polish_aristocrat
Too lazy to set a custom title
 
Join Date: Jul 2002
Posts: 40,377
:2cents Can anyone explain to me how a domain can be hijacked if...

if it is locked and noone hacks your registrar and email account?

Thanks, and only serious replies please
polish_aristocrat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:15 AM   #2
LasseKongos
Confirmed User
 
Join Date: Aug 2003
Posts: 4,668
Quote:
Originally Posted by polish_aristocrat
if it is locked and noone hacks your registrar and email account?

Thanks, and only serious replies please
I like to know to....




pimpimp
LasseKongos is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:16 AM   #3
e-god
Confirmed User
 
e-god's Avatar
 
Join Date: Jan 2003
Location: BabeLand
Posts: 1,736
human factor
__________________
e-god is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:17 AM   #4
NickPapageorgio
Confirmed User
 
Join Date: Apr 2004
Location: NC
Posts: 8,323
Quote:
Originally Posted by e-god
human factor
Exactly. I know I have overlooked important email alerts before. It's only human when you are so used to deleting so much spam all the time. Other than that I would say that the thief has to be in cahoots with the registrar. I dunno...
__________________
NickPapageorgio is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:18 AM   #5
DEA - banned for life
V.I.P.
 
Join Date: Nov 2004
Location: InYour Head
Posts: 7,886
its happening all the time now...its the next big thing
DEA - banned for life is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:19 AM   #6
Darth Vader
Confirmed User
 
Join Date: Jan 2005
Location: A Galaxy Far Far Away...
Posts: 144
The ability to jack domains is insignificant against the power of GeorgeK
__________________
Everything is going according to plan.
Darth Vader is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:20 AM   #7
LasseKongos
Confirmed User
 
Join Date: Aug 2003
Posts: 4,668
Quote:
Originally Posted by DEA
its happening all the time now...its the next big thing
And that is funny????
LasseKongos is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:21 AM   #8
Darth Vader
Confirmed User
 
Join Date: Jan 2005
Location: A Galaxy Far Far Away...
Posts: 144
Quote:
Originally Posted by NickPapageorgio
Exactly. I know I have overlooked important email alerts before. It's only human when you are so used to deleting so much spam all the time. Other than that I would say that the thief has to be in cahoots with the registrar. I dunno...
He is most definetly in "cahoots" The registrar in Sleazy dreams case was directi, an Indian Registrar. I think you'll find this newest jack was transferred there too.

I find your lack of domains disturbing.
__________________
Everything is going according to plan.
Darth Vader is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:23 AM   #9
hydro
Confirmed User
 
Join Date: Dec 2003
Location: Dirty 3rd
Posts: 4,216
$50,000 and ill direct lycos.com to your paysite
hydro is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:29 AM   #10
xclusive
Too lazy to set a custom title
 
Join Date: Apr 2004
Location: Buffalo, NY
Posts: 35,218
you can also call support on some registrars and talk your way into it i'm sure
__________________

I support MediumPimpin.com / Shemp's Outlawtgp.com /


xclusive is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:42 AM   #11
DarkJedi
No Refunds Issued.
 
DarkJedi's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: GFY
Posts: 28,300
Quote:
Originally Posted by Darth Vader
.
A fellow sith ? Oh, capital !
DarkJedi is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:44 AM   #12
Napolean
Old school
 
Napolean's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: Kettering, OH
Posts: 4,327
social engineering
__________________
Need a programmer? (Desktop/Web Applications) --- Skype: napoleande
Napolean is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 07:47 AM   #13
Darth Vader
Confirmed User
 
Join Date: Jan 2005
Location: A Galaxy Far Far Away...
Posts: 144
Quote:
Originally Posted by DarkJedi
A fellow sith ? Oh, capital !

You have a high post count, but you are not a Jedi yet.
__________________
Everything is going according to plan.
Darth Vader is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 09:05 AM   #14
arg
Confirmed User
 
Join Date: Feb 2003
Posts: 1,164
I'm not positive, but I was under the impression that under the new rules, an ICANN-accredited registrar can jack your names regardless of lock status..."locked" means "please don't jack this domain," but it's just a request, not enforced by ICANN. I can't find anything that confirms or refutes this on ICANN's site. They say the current registrar can deny a transfer based on lock status if the domain owner can turn the lock on and off, but I can't find where they go into the technical details. Any registrar gurus know how this works?

I like ICANN's answer in a FAQ for what to do if your name is jacked and the previous registrar won't do anything: "What happens if my registrar does not want to initiate a dispute for me? Registrars are not required to initiate disputes. If your chosen registrar is uninterested in helping you with your case, look for a new registrar who is. There are over 200 ICANN-accredited registrars. See the full list here." ICANN won't let domain holders dispute a domain hijacking; only registrars can.
arg is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 09:07 AM   #15
EscortBiz
Fuck Checks, CASH only!
 
Join Date: May 2002
Location: New York City
Posts: 19,422
Quote:
Originally Posted by Napolean
social engineering
exactly

same way you can call almost any hosting company or billing company and get anything done if you know what your doing

people need to train their employees better
EscortBiz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 09:08 AM   #16
nofx
Too lazy to set a custom title
 
Join Date: Nov 2002
Location: Virgin Mary's womb
Posts: 16,826
Quote:
Originally Posted by Napolean
social engineering
that is one way
__________________

Often times I wonder why
There's love and hate, theres live or die.
When sickness comes I must decide:
When feelings go, theres suicide.
nofx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 09:10 AM   #17
NemesisEnforcer
Confirmed User
 
NemesisEnforcer's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: Vegas and Los Angeles
Posts: 2,122
Quote:
Originally Posted by polish_aristocrat
if it is locked and noone hacks your registrar and email account?

Thanks, and only serious replies please
It is very easy. You hijack the domain through the registrars customer service, not via e-mail.
NemesisEnforcer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 09:12 AM   #18
Furious_Male
Doing the grind since 99
 
Furious_Male's Avatar
 
Industry Role:
Join Date: Oct 2003
Location: Buffalo NY
Posts: 16,881
Quote:
Originally Posted by DEA
its happening all the time now...its the next big thing
Its not funny but yes it does seem to be the in thing.
__________________
Living in Virtual Reality
Contact: Email (preferred): furiousmale .at. gmail - Skype: live:shanedws
Furious_Male is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 09:13 AM   #19
fusionx
Confirmed User
 
Industry Role:
Join Date: Nov 2003
Location: Olongapo City, Philippines
Posts: 4,618
I registered a new domain last weekend at Registerfly. It was automatically locked. At least it was reported as being locked without having to lock it after registration.

When I read about Sleazy's problem, I went back and double-checked all my domains, which had all been locked. The new one was not locked, and a handful of others were also open.

This is really disturbing.

I'm guessing it's bugs in the lock updating code. It is very new and probably hasn't been tested enough in the real world (I'm talking about the routines to do the bulk locking at the registrar, not the locking of domains themselves).

I'm going to check mine weekly from now on.
fusionx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 09:31 AM   #20
rebel23
Confirmed User
 
Join Date: Dec 2002
Posts: 817
im more worried about rogue Registrars than anything else... I think there is trouble ahead but nothing will be done
__________________
ICQ: 37378183
rebel23 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 10:42 AM   #21
vicki
Confirmed User
 
Industry Role:
Join Date: Feb 2002
Location: Deep in the heart o' Texas
Posts: 1,478
I can tell you some things that the guys over at DomainNameSystems.com see ..

people call customer support and try to 'convince' them they are the owner and ask them to 'remind' them of login info (it doesn't work at his place as he requires faxed proof hehe)

People use the same password for their domains as they do with alot of affiliate programs or hosting sites. If you have an untrustworthy employee at a sponsor program they can give that info a shot at a registrar and get lucky. (do NOT use the same password on your registrar that you use ANYWHERE else!)

People use unscrupulous registrars or registrars with unscrupulous employees ... could be lots of palm greasing if its a good domain.

Best solutions is to use a registrar with a good solid reputation and use a totally unique password.
__________________
If at first you do succeed - try to hide your astonishment.

HR merchant accounts from 3.45%
solid biz since 98
victoriakozub AT gmail.com
skype: victoria.kozub | ICQ: 74296746
vicki is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 10:44 AM   #22
Manowar
jellyfish  
 
Join Date: Dec 2003
Posts: 71,528
Quote:
Originally Posted by Napolean
social engineering
Seconded
Manowar is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 11:45 AM   #23
Gator
Confirmed User
 
Industry Role:
Join Date: Feb 2002
Location: Don't live on GFY
Posts: 1,119
Quote:
Originally Posted by rebel23
im more worried about rogue Registrars than anything else... I think there is trouble ahead but nothing will be done
Yup and it seems like more and more are popping up to cash in on the expired domain auctions.
Gator is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 11:46 AM   #24
fl_prn_str
Confirmed User
 
fl_prn_str's Avatar
 
Industry Role:
Join Date: Aug 2004
Location: Tampa, FL
Posts: 5,736
Quote:
Originally Posted by polish_aristocrat
if it is locked and noone hacks your registrar and email account?

Thanks, and only serious replies please

very good question.......if no one knows on this board....well
fl_prn_str is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 11:55 AM   #25
Napolean
Old school
 
Napolean's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: Kettering, OH
Posts: 4,327
Quote:
Originally Posted by fl_prn_str
very good question.......if no one knows on this board....well
theres 22 answers if you scroll up...
__________________
Need a programmer? (Desktop/Web Applications) --- Skype: napoleande
Napolean is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 11:58 AM   #26
TheMob
Confirmed User
 
Join Date: Jan 2003
Location: 2006
Posts: 8,584
it's leet stuff that goes on
TheMob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 12:07 PM   #27
nojob
The Original NoJob
 
nojob's Avatar
 
Join Date: Feb 2004
Location: Jerzzey
Posts: 3,682
when you have 100's of domains i am sure that you would not check them all the time, i do not check mine. another thing to worry about.
nojob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-18-2005, 12:31 PM   #28
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
halcyon from flashcash simply called up a registrar and had them unlock the domain without giving his name or any information whatsoever.
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-19-2005, 09:12 AM   #29
Taboo
Confirmed User
 
Join Date: Jul 2004
Location: I'd rather be networking than not working.
Posts: 3,700
Quote:
Originally Posted by polish_aristocrat
if it is locked and noone hacks your registrar and email account?

Thanks, and only serious replies please
keep in mind... the more you discuss this topic, the more hijackers you create.

imho, it would be wise to keep these discussions private instead of creating "how to guides" for people.

there is no simple solution to combat this problem... if a hijacker wants your domain bad enough they will KEEP trying to steal it. keep rechecking your lock status and performing daily checkups on your domains. test your registrar's security... secret shop them trying to get info... if they fail, move out of there asap or get that person FIRED/reprimanded. it pays to be paranoid.

"Just because you're paranoid doesn't mean they aren't after you"
Taboo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-19-2005, 10:07 AM   #30
Ron Bennett
Confirmed User
 
Join Date: Oct 2003
Posts: 1,653
Via the WDPRS, one can even steal domains that are locked down tight; registrar-lock doesn't even matter!

http://wdprs.internic.net/

For more details on WDPRS do a search for it here (I've posted more details in previous posts) and/or on Google ... in a nutshell, the doors are still wide open -and, again to reiterate, registrar-lock, passwords, etc will NOT protect one's domains from exploitation via the WDPRS.

Ron
__________________
Domagon - Website Management and Domain Name Sales
Ron Bennett is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.