DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars
HomeRegisterMembershipsGetting StartedDomain Tools Domain EbooksSEO Software Domain Resellers Advertise

Go Back   DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars > Industry Leaders > Domain Registrars > GODADDY.com
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 04-10-2009, 12:46 PM   #1 (permalink)
Bloody lovely
 
Acro's Avatar
 
Last Online: Today 06:23 PM
iTrader: (394)
Join Date: Feb 2004
Posts: 23,886
DNF$: 4,003
Location: USA
Country:




Exclamation CAUTION! GoDaddy phishing happening right now

The following email appears to come from support@godaddy.com but it points to:
http://205.234.236.23/~ytrindic/

It's a server in Pakistan mzwebhost.com. Contacting their upstream provider.

+++++++++++


Dear Customer,

This notification is generated automatically as a service to you.

Because of unusual number of invalid login attempts on you account, we had to believe that, their might be some security problem on you account. So we have decided to put an extra verification process to ensure your identity and your account security.
Please click on sign in to domain servers to continue to the verification process and ensure your account security. It is all about your security. Thank you. and visit the customer service section.

please contact us within 1 days.

If you need to address this matter, or in any way need further assistance or technical support, call us any time at (480) 505-8877 or email us at support@godaddy.com. We appreciate your business!

Sincerely,
GoDaddy.com DomainAlert team
__________________

DomainGang.com - Domainers' Most Awesome News Source
Acroplex - Web & Graphics
Acro.net - My Blog
My Countdown Counting down to: Snapnames rebate hitting my mailbox
82 days 3 hours 47 minutes
Acro is offline   Reply With Quote
Sponsored Ads
Old 04-10-2009, 01:00 PM   #2 (permalink)
iSpoof.com
 
biggedon's Avatar
 
Last Online: Today 05:32 PM
iTrader: (112)
Join Date: Sep 2002
Posts: 10,997
DNF$: 51,465
Location: 96.net


yeah

i got two of these emails yesterday

knew it was fake when i did a "hover over" the link

also who would attempt to steal my crap names at godaddy?
__________________
worldiptv.com * svc.net * belisted.com * mobi.us.com * sop.net
* qfm.net * upyo.com * vioz.com *
Need A SedoPro Account PM Me
biggedon is offline   Reply With Quote
Old 04-10-2009, 01:03 PM   #3 (permalink)
Bloody lovely
 
Acro's Avatar
 
Last Online: Today 06:23 PM
iTrader: (394)
Join Date: Feb 2004
Posts: 23,886
DNF$: 4,003
Location: USA
Country:




I got 5 so far. Complaint sent via http://www.servercentral.net/supportrequest
__________________

DomainGang.com - Domainers' Most Awesome News Source
Acroplex - Web & Graphics
Acro.net - My Blog
My Countdown Counting down to: Snapnames rebate hitting my mailbox
82 days 3 hours 47 minutes
Acro is offline   Reply With Quote
Old 04-10-2009, 01:07 PM   #4 (permalink)
jdk
DNF Addict
 
jdk's Avatar
 
Name: Doug
Last Online: Yesterday 06:09 PM
iTrader: (175)
Join Date: Jul 2004
Posts: 6,886
DNF$: 68,548
Location: Florida
Country:


I received 7 over the past two days. I forwarded them to Godaddy, but likely won't do any good.
jdk is offline   Reply With Quote
Old 04-10-2009, 01:09 PM   #5 (permalink)
 
PRED's Avatar
 
Last Online: Today 12:58 PM
iTrader: (118)
Join Date: May 2006
Posts: 7,960
DNF$: 1,065
Country:




Thumbs up

thanks very much Acro, as ever you are always on top of things
cheers. I actually just got 5!
If it had been one i would maybe have clicked but seen the redirect.
I havd already junked them as phishing and redirected one to godaddy support.
Spread the word on the forums guys!
PRED is offline   Reply With Quote
Old 04-10-2009, 01:12 PM   #6 (permalink)
Bloody lovely
 
Acro's Avatar
 
Last Online: Today 06:23 PM
iTrader: (394)
Join Date: Feb 2004
Posts: 23,886
DNF$: 4,003
Location: USA
Country:




NP Pred. The email is very well constructed, also the form page itself that takes the username/password is exceptionally done. I submitted a few pairs such as "fbi_is_coming/sore_loser" - hopefully they will be shut down soon. Just complain using the form above.
__________________

DomainGang.com - Domainers' Most Awesome News Source
Acroplex - Web & Graphics
Acro.net - My Blog
My Countdown Counting down to: Snapnames rebate hitting my mailbox
82 days 3 hours 47 minutes
Acro is offline   Reply With Quote
Old 04-10-2009, 01:14 PM   #7 (permalink)
Platinum Lifetime Member
 
Seraphim's Avatar
 
Last Online: Today 05:10 PM
iTrader: (21)
Join Date: Jan 2006
Posts: 3,073
DNF$: 1,397
Location: Hillsboro, OR
Country:


Whoa, got several of these. Thanks for the heads up Theo.
__________________
...
Seraphim is offline   Reply With Quote
Old 04-10-2009, 01:15 PM   #8 (permalink)
Bloody lovely
 
Acro's Avatar
 
Last Online: Today 06:23 PM
iTrader: (394)
Join Date: Feb 2004
Posts: 23,886
DNF$: 4,003
Location: USA
Country:




The form and images are hosted at
Code:
 http://elpos.ba/galerija/albums/userpics2/msg/
.ba = Bosnia

Some photos of the sore losers implicated in this scam:

Code:
http://elpos.ba/galerija/albums/userpics2/ado.jpg
http://elpos.ba/galerija/albums/userpics2/enes.JPG
http://elpos.ba/galerija/albums/userpics2/square00.JPG
http://elpos.ba/galerija/albums/userpics2/square05.JPG
http://elpos.ba/galerija/albums/userpics2/normal_square06.JPG
http://elpos.ba/galerija/albums/userpics2/nijaz.JPG
http://elpos.ba/galerija/albums/userpics2/kancelarija1.JPG
__________________

DomainGang.com - Domainers' Most Awesome News Source
Acroplex - Web & Graphics
Acro.net - My Blog
My Countdown Counting down to: Snapnames rebate hitting my mailbox
82 days 3 hours 47 minutes

Last edited by Acro; 04-10-2009 at 01:20 PM.. Reason: Automerged Doublepost
Acro is offline   Reply With Quote
Old 04-10-2009, 01:20 PM   #9 (permalink)
Domain Magnate™
 
DomainMagnate's Avatar
 
Name: Michael
Last Online: Today 06:16 AM
iTrader: (68)
Join Date: Nov 2005
Posts: 3,637
DNF$: 6,457
Location: DnMagnate.com


I only got 4 so far, feeling a little left out :o
__________________
Domain Magnate Mind Reading
DomainMagnate is offline   Reply With Quote
Old 04-10-2009, 01:24 PM   #10 (permalink)
Platinum Lifetime Member
 
Seraphim's Avatar
 
Last Online: Today 05:10 PM
iTrader: (21)
Join Date: Jan 2006
Posts: 3,073
DNF$: 1,397
Location: Hillsboro, OR
Country:


Quote:
Originally Posted by Acro View Post
The form and images are hosted at
Code:
 http://elpos.ba/galerija/albums/userpics2/msg/
.ba = Bosnia

Some photos of the sore losers implicated in this scam:

Code:
http://elpos.ba/galerija/albums/userpics2/ado.jpg
http://elpos.ba/galerija/albums/userpics2/enes.JPG
http://elpos.ba/galerija/albums/userpics2/square00.JPG
http://elpos.ba/galerija/albums/userpics2/square05.JPG
http://elpos.ba/galerija/albums/userpics2/normal_square06.JPG
http://elpos.ba/galerija/albums/userpics2/nijaz.JPG
http://elpos.ba/galerija/albums/userpics2/kancelarija1.JPG
That is bizarre. A hijacked domain perhaps? They aren't actually using their own domain are they? Would be pretty funny if so.
__________________
...
Seraphim is offline   Reply With Quote
Old 04-10-2009, 01:25 PM   #11 (permalink)
Bloody lovely
 
Acro's Avatar
 
Last Online: Today 06:23 PM
iTrader: (394)
Join Date: Feb 2004
Posts: 23,886
DNF$: 4,003
Location: USA
Country:




Probably so.

Code:
link to a toolkit http://elpos.ba/galerija/albums/userpics2/boom.php
__________________

DomainGang.com - Domainers' Most Awesome News Source
Acroplex - Web & Graphics
Acro.net - My Blog
My Countdown Counting down to: Snapnames rebate hitting my mailbox
82 days 3 hours 47 minutes
Acro is offline   Reply With Quote
Old 04-10-2009, 01:29 PM   #12 (permalink)
Platinum Lifetime Member
 
Seraphim's Avatar
 
Last Online: Today 05:10 PM
iTrader: (21)
Join Date: Jan 2006
Posts: 3,073
DNF$: 1,397
Location: Hillsboro, OR
Country:


Quote:
Originally Posted by Acro View Post
Probably so.

Code:
link to a toolkit http://elpos.ba/galerija/albums/userpics2/boom.php
Wow, what the hell is that? What's a toolkit?
__________________
...
Seraphim is offline   Reply With Quote
Old 04-10-2009, 01:31 PM   #13 (permalink)
Bloody lovely
 
Acro's Avatar
 
Last Online: Today 06:23 PM
iTrader: (394)
Join Date: Feb 2004
Posts: 23,886
DNF$: 4,003
Location: USA
Country:




Looks like a root toolkit that can perform other penetration tasks remotely. Also it links to http://milw0rm.com which is a known repository of exploits. These ****ers need to be shut down.
__________________

DomainGang.com - Domainers' Most Awesome News Source
Acroplex - Web & Graphics
Acro.net - My Blog
My Countdown Counting down to: Snapnames rebate hitting my mailbox
82 days 3 hours 47 minutes
Acro is offline   Reply With Quote
Old 04-10-2009, 01:35 PM   #14 (permalink)
Domain Magnate™
 
DomainMagnate's Avatar
 
Name: Michael
Last Online: Today 06:16 AM
iTrader: (68)
Join Date: Nov 2005
Posts: 3,637
DNF$: 6,457
Location: DnMagnate.com


Good research there Acro, just blogged about it
__________________
Domain Magnate Mind Reading
DomainMagnate is offline   Reply With Quote
Old 04-10-2009, 01:38 PM   #15 (permalink)
Bloody lovely
 
Acro's Avatar
 
Last Online: Today 06:23 PM
iTrader: (394)
Join Date: Feb 2004
Posts: 23,886
DNF$: 4,003
Location: USA
Country:




Nice pic, Michael
__________________

DomainGang.com - Domainers' Most Awesome News Source
Acroplex - Web & Graphics
Acro.net - My Blog
My Countdown Counting down to: Snapnames rebate hitting my mailbox
82 days 3 hours 47 minutes
Acro is offline   Reply With Quote
Old 04-10-2009, 02:01 PM   #16 (permalink)
Dances With Dogs
 
Doc Com's Avatar
 
Name: Dances With Dogs
Last Online: Today 05:13 PM
iTrader: (73)
Join Date: Dec 2006
Posts: 10,268
DNF$: 25,357
Country:



Yea, DNFers, Mobility, NPers post on your twitter accounts also.

Many noobs (and veterans) may fall for this.

Phew, what a relief.

And to think I had to acually renew domain names.






















=)
__________________



Conservative With A Conscience


Last edited by Doc Com; 04-10-2009 at 02:03 PM.. Reason: Automerged Doublepost
Doc Com is offline   Reply With Quote
Old 04-10-2009, 02:43 PM   #17 (permalink)
Domains Biatch!
 
Poker's Avatar
 
Last Online: Today 11:44 AM
iTrader: (13)
Join Date: Oct 2002
Posts: 3,150
DNF$: 12,243
Location: Nirvana
Country:


Quote:
Originally Posted by biggedon View Post
also who would attempt to steal my crap names at godaddy?
people with crap mentalities (or crack problems)...
Poker is offline   Reply With Quote
Old 04-10-2009, 08:02 PM   #18 (permalink)
Bloody lovely
 
Acro's Avatar
 
Last Online: Today 06:23 PM
iTrader: (394)
Join Date: Feb 2004
Posts: 23,886
DNF$: 4,003
Location: USA
Country:




Looks like the hacking tools have been removed. The IP that was sending the emails has also been turned off.
__________________

DomainGang.com - Domainers' Most Awesome News Source
Acroplex - Web & Graphics
Acro.net - My Blog
My Countdown Counting down to: Snapnames rebate hitting my mailbox
82 days 3 hours 47 minutes
Acro is offline   Reply With Quote
Old 04-10-2009, 08:06 PM   #19 (permalink)
DotAgent
 
Domainator's Avatar
 
Last Online: 11-16-2009 11:57 PM
iTrader: (27)
Join Date: Sep 2004
Posts: 991
DNF$: 6,554
Country:


We reported these to GD yesterday and they confirmed was a scam..
__________________
DOMAINator
Domainator is offline   Reply With Quote
Old 04-10-2009, 08:29 PM   #20 (permalink)
Platinum Lifetime Member
 
Seraphim's Avatar
 
Last Online: Today 05:10 PM
iTrader: (21)
Join Date: Jan 2006
Posts: 3,073
DNF$: 1,397
Location: Hillsboro, OR
Country:


Quote:
Originally Posted by Acro View Post
Looks like the hacking tools have been removed. The IP that was sending the emails has also been turned off.
You and LegendaryJP need to start your own DN-PI service, you both have solid research skills. I know it's inevitable I'd send some cash your way.
__________________
...
Seraphim is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 08:11 PM.
Copyright @2001-2009 DNForum.com