Welcome to Welcome to DNF.com™ - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars

If you are new to domains and looking to buy, sell and learn about domains then you have come to the right place. DNForum is the largest domain name community on the internet and continues to grow every day. There are over 105,000 domainers on DNForum doing everything from buying domains, selling domains, learning about domains and discussing domains. Take a minute and Register.

Register Today on DNForum IT'S FREE!

Page 2 of 2 FirstFirst 12
Results 21 to 40 of 40
  1. #21
    DNF Addict
    south's Avatar
    Join Date
    Dec 2006
    Location
    33143/04930
    Posts
    4,994
    DNF$
    8,193
    Bank
    0
    Total DNF$
    8,193
    Donate  
    So I am to assume our EIN numbers, contact phone numbers, etc were stolen as well?
    Nice...
    All offers good for 72 hours except running auctions

    Progeria Research | Pulmonary Fibrosis | Dammit!

  2. #22
    Platinum Lifetime Member
    SedoCoUk's Avatar
    Join Date
    Aug 2002
    Location
    Cambridge, MA
    Posts
    1,146
    DNF$
    3,019
    Bank
    0
    Total DNF$
    3,019
    Donate  
    Hi all,

    The email was sent out to SedoPro members, but if you use multiple parking companies then it is important:

    We have been informed that due to a security problem at one of our competitors a list of their customer data including plaintext passwords is currently circulating on the web including relevant hacker forums.

    Our Security and Compliance Team has found several of our own customers matching the publicly available list. Due to the seriousness of this matter combined with the possibility that you might be using the same login data/password at more than one parking company, we strongly suggest you to change your password at sedo.

    sedo uses cryptographically unbreakable ciphertext for password checks and does not store your password in plaintext. This, and a variety of other security measures, ensures that your Sedo account is always safe from third parties.

    We generally recommend to always use different login IDs for different sites and never hand out login IDs to any third party.

    Should you have any further questions or needs, your dedicated account manager is looking forward to help.

    Kind regards,
    Your Sedo Security & Compliance Team


    With regards to some of the points made above... I think out of professional courtesy it is correct to not call out a particular organization. However, as we have clients who use multiple parking companies, it is our responsibility to advise people that it may be wise to update their password.

    Best,

    Tom

  3. #23
    Bloody Hell
    Acro's Avatar
    Join Date
    Feb 2004
    Location
    USA
    Posts
    28,665
    Country

    Holy See
    DNF$
    15,555
    Bank
    0
    Total DNF$
    15,555
    Donate  
    Tom, I think that it's more offending to call another PPC company a "competitor" than to name it directly, thus assisting in users taking direct steps in changing their passwords. I understand that even sending out that email is a step in the right direction, however I had to visit DNForum in order to find out which PPC company's data was leaked.

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog

  4. #24
    Platinum Lifetime Member

    Join Date
    Aug 2006
    Location
    Kingston, Jamaica
    Posts
    50
    DNF$
    270
    Bank
    0
    Total DNF$
    270
    Donate  
    This is why I have a different password for every single site that I login into lol

  5. #25
    þórr mjǫlnir
    draggar's Avatar
    Join Date
    Dec 2007
    Location
    South Florida
    Posts
    12,872
    Country

    Czech Republic
    DNF$
    6,957
    Bank
    116,559
    Total DNF$
    123,516
    Donate  
    I just got this form NameDrive:

    Hello,

    This is a mail to inform you that a minimal number of NameDrive accounts
    were the targets of a security breach recently.
    This affected less than 1% of our database.

    While we do not believe that your account has been affected and we have
    no indication of unauthorized access, we are informing you as a
    precaution that you should change your login passwords to any other
    online programs for which you use the same password as you do to log
    into NameDrive.com.

    Your NameDrive password has already been changed automatically for you.

    If you haven't already done so, you can retrieve your new password by
    logging into your account on the NameDrive homepage.

    While we have always had strict security measures in place, we have
    taken yet further measures to enhance our security measures with
    immediate effect.

    If you have any questions, please feel free to contact us at
    info@namedrive.com.

    Your NameDrive team
    Save the wolves - join The Wolf Army today!
    Please follow the rules or suffer the wrath of Thor's Hammer.

  6. #26
    Bloody Hell
    Acro's Avatar
    Join Date
    Feb 2004
    Location
    USA
    Posts
    28,665
    Country

    Holy See
    DNF$
    15,555
    Bank
    0
    Total DNF$
    15,555
    Donate  
    Yeah I got it too about an hour ago.

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog

  7. #27
    Success Is My Only Option
    Carter's Avatar
    Join Date
    Jul 2008
    Location
    Italy
    Posts
    4,249
    Country

    Italy
    DNF$
    28,074
    Bank
    0
    Total DNF$
    28,074
    Donate  
    Acro it's time you write an article on your blog about this scandalous fact.

  8. #28
    DNF Addict
    nts's Avatar
    Join Date
    Jul 2005
    Location
    Canada
    Posts
    1,064
    Country

    Canada
    DNF$
    751
    Bank
    0
    Total DNF$
    751
    Donate  
    Quote Originally Posted by SedoCoUk View Post
    a list of their customer data including plaintext passwords
    Plaintext passwords, really? I find it very disturbing that any site, let alone namedrive, would take the risk of storing passwords without hashing them...

  9. #29
    Bloody Hell
    Acro's Avatar
    Join Date
    Feb 2004
    Location
    USA
    Posts
    28,665
    Country

    Holy See
    DNF$
    15,555
    Bank
    0
    Total DNF$
    15,555
    Donate  
    There is no indication the plaintext passwords were stored as such with ND or if they were bruteforced. Hashed passwords are more secure in the sense that they require reversal but they are not uncrackable. The hackers apparently compromised a ND server that contained customer data and perused it for their benefit. Anyone knows where the data was posted at?

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog

  10. #30
    Country hopper
    katherine's Avatar
    Join Date
    Jul 2005
    Location
    Free World
    Posts
    7,496
    Country

    Iceland
    DNF$
    30,528
    Bank
    0
    Total DNF$
    30,528
    Donate  
    Quote Originally Posted by nts View Post
    Plaintext passwords, really? I find it very disturbing that any site, let alone namedrive, would take the risk of storing passwords without hashing them...
    I know of a few registrars, including one that puts great emphasis on security, that don't see anything wrong with storing passwords in plain text (cough cough).
    Last edited by sdsinc; 02-06-2009 at 06:49 PM. Reason: typo
    NameNewsletter.com - free lists of available domain names
    ZoneFiles.net (beta) - ccTLD and gTLD droplists

  11. #31
    dvdrip's Avatar
    Join Date
    Jul 2002
    Location
    Athens Greece
    Posts
    2,713
    DNF$
    14,482
    Bank
    0
    Total DNF$
    14,482
    Donate  
    Quote Originally Posted by sdsinc View Post
    I know of a few registrars, including one that puts great emphasis on security, that don't see anything wrong with storing passwords in plain text (cough cough).
    Which one? Please PM if you don't want to say.
    www.bluepixel.gr I like .info!
    Now accepting .gr domain registrations from any foreign company or individual. Contact me for details.

  12. #32
    Making Everything Click
    Focus's Avatar
    Join Date
    May 2005
    Location
    South Florida
    Posts
    9,616
    DNF$
    17,352
    Bank
    0
    Total DNF$
    17,352
    Donate  
    these companies are totally frickin wreckless with our important & sensitive data, geez
    I'm buying credit, banking, loan, insurance related generics in .com, .net, .org with high search volumes/traffic. Will consider typos too! - PLEASE PM with name, info, & asking price!

  13. #33
    Country hopper
    katherine's Avatar
    Join Date
    Jul 2005
    Location
    Free World
    Posts
    7,496
    Country

    Iceland
    DNF$
    30,528
    Bank
    0
    Total DNF$
    30,528
    Donate  
    It's easy to find out.
    Try the password reminder feature of your registrar.
    If your password is on file it can be mailed to you. If it's encrypted using a hash (one-way) algorithm than you have to choose another one.
    Hashing doesn't really help if your password is weak - it can be reverse-engineered easily - but it helps mitigate the risk in case of data breach.
    NameNewsletter.com - free lists of available domain names
    ZoneFiles.net (beta) - ccTLD and gTLD droplists

  14. #34
    Gold Lifetime Member

    Join Date
    Feb 2009
    Posts
    4
    DNF$
    201
    Bank
    0
    Total DNF$
    201
    Donate  
    Noted

    Last edited by draggar; 02-07-2009 at 06:43 AM. Reason: Link removed

  15. #35
    Moderator
    Johnn's Avatar
    Join Date
    Apr 2004
    Location
    Pennsylvania
    Posts
    15,007
    Country

    United States
    DNF$
    5,417
    Bank
    0
    Total DNF$
    5,417
    Donate  
    Quote Originally Posted by kamilaseo View Post
    Noted
    Stop spamming

  16. #36
    Country hopper
    katherine's Avatar
    Join Date
    Jul 2005
    Location
    Free World
    Posts
    7,496
    Country

    Iceland
    DNF$
    30,528
    Bank
    0
    Total DNF$
    30,528
    Donate  
    Today I requested my new Namedrive password and I notice something funny.
    The new password actually reads like this:

    {my previous password}_1137884883

    I though to myself, this password is not random and the number looks like a Unix timestamp.
    So let's run it in mySQL:
    Code:
    SELECT FROM_UNIXTIME( 1137884883 )
    
    => 2006-01-22 01:08:03
    I believe this is my registration date !

    So I think Namedrive just ran a quick & dirty SQL query instead of using a random sequence.
    Let me reverse-engineer the SQL that was used:
    Code:
    UPDATE members SET user_password = concat( user_password, '_', UNIX_TIMESTAMP( reg_date ) )


    BTW I'm not keeping that default password, thank you.
    NameNewsletter.com - free lists of available domain names
    ZoneFiles.net (beta) - ccTLD and gTLD droplists

  17. #37
    Bloody Hell
    Acro's Avatar
    Join Date
    Feb 2004
    Location
    USA
    Posts
    28,665
    Country

    Holy See
    DNF$
    15,555
    Bank
    0
    Total DNF$
    15,555
    Donate  
    NameDrive, please fire that programmer. There are plenty of alternatives in the market today.

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog

  18. #38
    Country hopper
    katherine's Avatar
    Join Date
    Jul 2005
    Location
    Free World
    Posts
    7,496
    Country

    Iceland
    DNF$
    30,528
    Bank
    0
    Total DNF$
    30,528
    Donate  
    So it means that if the hackers have got these two fields from the database:
    • old_password (in plain text)
    • reg. date time

    they already have the new passwords. They just have to derive them.

    BTW nobody from Namedrive has posted here yet
    NameNewsletter.com - free lists of available domain names
    ZoneFiles.net (beta) - ccTLD and gTLD droplists

  19. #39
    Bloody Hell
    Acro's Avatar
    Join Date
    Feb 2004
    Location
    USA
    Posts
    28,665
    Country

    Holy See
    DNF$
    15,555
    Bank
    0
    Total DNF$
    15,555
    Donate  
    I hope the NameDrive database programmmer is working extra time this weekend to save his ass. This is extremely bad programming practices and when I ripped sedo in the past for something similar they fixed it in 24 hours quite well.

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog

  20. #40
    Country hopper
    katherine's Avatar
    Join Date
    Jul 2005
    Location
    Free World
    Posts
    7,496
    Country

    Iceland
    DNF$
    30,528
    Bank
    0
    Total DNF$
    30,528
    Donate  
    Now that I changed my password, I asked for a reminder.
    I got my password mailed to me so they are still stored in plain text.
    When will people ever learn ?
    NameNewsletter.com - free lists of available domain names
    ZoneFiles.net (beta) - ccTLD and gTLD droplists

Page 2 of 2 FirstFirst 12

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Domain name forum recommended by Domaining.com