![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#51 |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
not good :-(
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#52 | |
Registered User
Join Date: Feb 2005
Posts: 20
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#53 |
Registered User
Join Date: Oct 2002
Location: New Orleans
Posts: 27
|
I'm the product development manager at directNIC, call me the head techie.
We log everything, so I will give you the description of what happened here. On January 28th, somebody (205.152.129.X) logged into account A, went to the transfer security page and unlocked all of the domains, they then went in and changed 2 contacts. At this point, I am assuming they went to registrar A and submitted transfers for some domains. We received requests about the transfers on January 30, then we sent an email to verify that they wanted to transfer the domains away and the same person who changed the information above approved the transfers. Then somebody (193.188.105.X) from another IP address came in and changed the email address on those 2 contacts back to what they originally where before they logged in. The email addresses were changed to [email protected], and then changed back to what they originally were. So was this a hack, personally, not on our end. The person already knew the username/password when they logged into the account. I could be wrong, but I bet what may be happening is people may be reusing the same usernames/passwords in different places and somebody is not playing nice. I could be wrong, but you never know. Shoot me an email and I'll see what I can do tomorrow, I know enom is not around today, I just tried to call them. Send me an email to donny AT intercosmos.com Donny |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#54 | |
Old broad
Join Date: Oct 2002
Location: Away
Posts: 13,933
|
Quote:
I was with Netsol at the beginning - back in the days when domains were $100. Besides being total idiots about their process, I also ended up with several domains that weren't mine. Neither I nor the rightful owner could ever get them moved over. It was a simple typo where some idiot there put in my customer number instead of the correct owner's. Then I went with another adult webmaster owned service. After having 3 domains of mine mysteriously changed to THEIR contact information and no response from them after several trouble tickets, emails and phone calls, I contacted Directnic, moved my domains there and I've been happy as a pig in shit ever since. In fact, it's probably been over 2 years that I've been there. IF there has been a problem (and I can only think of 2 - both my fault) I have been able to get a response immediately. However, if I do indeed work for them, could you please get my paycheck from them for me? I seem to be working for free. ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#55 | |
Old broad
Join Date: Oct 2002
Location: Away
Posts: 13,933
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#56 |
Master of Gfy.com
Industry Role:
Join Date: Feb 2002
Posts: 14,887
|
I like directnic alot, one of the few companies that will fight for you and try to get your stuff back, makes sense a ton of the adult companies are with them.. I just wish I knew better when I had a couple domains at registerfly and they got hijacked.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#57 |
The Profiler
Industry Role:
Join Date: Oct 2002
Location: ICQ 76281726 and I'm female
Posts: 14,618
|
Wow that's good news, hats off to Peaches and Directnic!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#58 | |
Old broad
Join Date: Oct 2002
Location: Away
Posts: 13,933
|
Quote:
![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#59 | |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
Quote:
![]() ![]() I was seriously considering removing my domains !!! thanks for the quick reply directnic
__________________
hatisblack at yahoo.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#60 |
Registered User
Join Date: Oct 2002
Location: New Orleans
Posts: 27
|
Well, keep my address incase something happens ever. I personally normally don't check gfy much anymore, just not enough time. But once grimm told me about it I was reading.
So just email me if you need anything. Donny directNIC.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#61 | |
Confirmed User
Join Date: Jul 2001
Location: See sig
Posts: 6,989
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#62 |
Confirmed User
Join Date: Feb 2004
Posts: 1,026
|
Absolutely delightful .. Directnic are superb
__________________
SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#63 |
Guest
Posts: n/a
|
i did not like directnic. I lost one .tv domain name because they have problems in software to renew .tv domains at this time.
|
![]() ![]() ![]() ![]() ![]() |
![]() |
#64 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Colorado
Posts: 3,973
|
wow very cool. Having all my domains with you guys I was really concerned but posting on here has restored my confidence with you guys.
![]() Thanks, Mark
__________________
IntenseCash - If you can't convert us then you might want to look for a new job . BrokeStraightBoys.com converting 1:124 stats counted by Nats |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#65 |
Confirmed User
Join Date: Feb 2003
Posts: 1,164
|
It's been a while since I've used directnic, but it sounds like you're not notifying owners of account changes. I apologize if I'm mis-assuming, but if change notices aren't being sent, I think that should be reconsidered. This could have provided an alert about the hijacking attempt before the transfer occurred, even if a hacker did break into the account. The drawback is it can be annoying to domain owners getting too many change notices, but that can be tempered by combining multiple change notices into consolidated messages.
To explain what I mean about change notices, when one or more domains are unlocked, locked, or have contacts, name servers, or other data changed, email the account holder's email address, as well as the current admin contact(s) of the domain(s) in question (if they're different from the account owner's address). Not one message per domain, because if a person does a bulk change, that gets annoying, but a single message saying "these domains were unlocked," or if it's more than a couple hundred, just saying "1,317 domains had their admin email contact changed." Also changes to the account info itself should be similarly confirmed by email. While I understand this was a hacker who got into the account, I think the registrars who are repeatedly losing domains to hijackers share some similar security weaknesses like this. Try changing domain details at Godaddy for an example of notifying domain owners...they have more domains registered than Directnic or Dotster, but I don't recall anybody reporting hijack losses from them on GFY. It could be coincidence, since the number of hijackings is still very small, but I think things like this can make a big difference. Thanks for posting details Donny. I'll send this by email in case you don't check back here. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#66 |
I'm Lenny2 Bitch
Join Date: Mar 2001
Location: On top of my soapbox
Posts: 13,449
|
I think a good countermeasure to this type of hack would be that if the contact email is changed in the account an email is sent to the previous email account with a confirm link that must be clicked for the change to be processed.
Then we'd get emails from directnic when someone was trying to hack our shit.
__________________
sig too big |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#67 | |
No Refunds Issued.
Industry Role:
Join Date: Feb 2001
Location: GFY
Posts: 28,300
|
Quote:
I got a few domains at godaddy too (God, I hate their interface) but I get a notification email about ANY changes in my account. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#68 | |
Confirmed User
Join Date: Sep 2003
Posts: 4,209
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#69 |
sell me your banners
Industry Role:
Join Date: Dec 2003
Location: on the tubes
Posts: 12,931
|
I agree with arg... a notice should be sent when anything vital has been changed. I think even RegisterFly does that and we all know they're not safe lol.
I have recently decided to keep all my own names @ Moniker, they do not allow any transfers away from them without prior notice and verification. Also NO hijacks have been attempted/succeeded on domains @ Moniker.
__________________
Media Buyer - Sell me your traffic! FREE to register domains... Better than 99% of the crap sold here! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#70 | |
Registered User
Join Date: Feb 2005
Posts: 20
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#71 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Colorado
Posts: 3,973
|
I think entering a pin code to transfer domains as an option would be great. This would go well with the other security features you already have.
![]() Mark
__________________
IntenseCash - If you can't convert us then you might want to look for a new job . BrokeStraightBoys.com converting 1:124 stats counted by Nats |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#72 | |
Confirmed User
Industry Role:
Join Date: Feb 2002
Location: Deep in the heart o' Texas
Posts: 1,478
|
Quote:
domainnamesystems also has one of only 10 people in the world who have a degree in computer security forensics working for them ;)
__________________
If at first you do succeed - try to hide your astonishment. HR merchant accounts from 3.45% solid biz since 98 victoriakozub AT gmail.com skype: victoria.kozub | ICQ: 74296746 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#73 | |
sell me your banners
Industry Role:
Join Date: Dec 2003
Location: on the tubes
Posts: 12,931
|
Quote:
![]()
__________________
Media Buyer - Sell me your traffic! FREE to register domains... Better than 99% of the crap sold here! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#74 | |||
Registered User
Join Date: Oct 2002
Location: New Orleans
Posts: 27
|
I'll respond to everything below.
Quote:
Quote:
Quote:
Sorry for the long reply, but just so everybody knows, I do have a very good idea the person was that stole domain and guess what, he's an adult webmaster. Interesting, I wonder if he reads gfy? It's funny when certain people use web-based email clients and don't realize that sometimes web bugs are in the html to see if somebody actually looked at the email or not. Open email via a non-proxy ip address, then click the link in the email 30 seconds later via a proxy ip. Amazing! ![]() Donny |
|||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#75 |
Confirmed User
Join Date: Feb 2003
Posts: 1,164
|
Great that you've got more improvements in the works, whatever they are. I understand many of the challenges you mentioned, though for many there are also mitigating solutions.
Annoyance factor for every change for big domain holders would be huge. Just allow users to reduce the level of notification if they choose to, but by default, have notifications for all the main changes. Just like domains should be locked by default. Which email address to send to? By default, admin and account, just one message if they're the same, two messages if they differ. But again allow an advanced user to choose. Also, consolidating messages would help, some registrars send out thousands of messages for a bulk request on the same account; there are some common sense approaches to reducing annoyance. I think I'd also consider an auto-relocking feature. If a domain has been unlocked for two weeks, with no transfer requests, send a notice to the user and automatically relock it. Again, the annoyance factor would be huge for certain customers, so allow them to disable auto-relocking, but have it on by default. I have no idea if Directnic does this, but when a domain is transferred in, I think it should also be automatically locked...some registrars lock all new regs by default, but not transferred-in regs. Hijacked email, I agree, there's little you can do, especially if a domain is already unlocked. Most registrars have account password protection as well, but when you lose the password, many just send it to the email address, so basically if your email account is compromised, you can lose all your domains. There are added checks you can put in place, but they can be complex and costly, and still aren't foolproof. (Automated phone confirmation, for example, but phone numbers change too). Your point is taken about relatively fewer webmasters using GoDaddy here...I'm pretty sure directnic has a higher marketshare among GFYers than among domain holders as a whole. Still, I think Godaddy's system would have prevented the sort of hijack in this particular instance. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#76 | |
Registered User
Join Date: Oct 2002
Location: New Orleans
Posts: 27
|
Quote:
Some have good systems for security, some I don't even think have security at all. But about 99.9% of the time, it's registrant error, either the current registrant did something wrong or the new registrant did something wrong. But as a registrar, I can only do so much to protect as many people as I can, and that's what I try to do. Donny directNIC.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#77 |
Registered User
Join Date: Oct 2002
Location: New Orleans
Posts: 27
|
Just as an FYI, we have implemented all of our security enhancements, I was working on. You can now turn them on in the Customer Settings area once you are logged into directNIC.
Donny directNIC.com |
![]() |
![]() ![]() ![]() ![]() ![]() |