Closing Doman Auctions
DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars
HomeRegisterMembershipsGetting StartedDomain Tools Domain EbooksSEO Software Domain Resellers Advertise

Go Back   DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars > Industry Leaders > Traffic Monetization PPC > Domainsponsor.com
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 02-08-2007, 02:17 AM   #1 (permalink)
stu
Platinum Lifetime Member
 
stu's Avatar
 
Last Online: 08-03-2009 04:18 PM
iTrader: (100)
Join Date: Dec 2005
Posts: 541
DNF$: 933
Location: Subic Bay


Anybody else get this?

I just received this email from security.admin@dsredirection.com

Quote:
Dear Dsredirection valued Members

Regarding our new security regulations, as a part of our yearly maintenance we have provided a security guard script in the attachment.

So, to secure your websites, please use the attached file and (for UNIX/Linux Based servers) upload the file "guard.php" in: "./public_html" or (for Windows Based servers which use ASP) upload the file "guard.asp" in: "./wwwroot" in your site.

If you do not know how to use it, you can use the following instruction:

For Unix/Linux based websites that use PHP/CGI/PERL:
1) Download the attachment named "guard.zip"
2) Extract file "guard.php"
3) Login to your site Control panel.
4) Open "File Manager" window.
5) Go through "Public_html" or "htdocs"
6) Choose "Upload Files"
7) Upload the file "guard.php"
8) Check its URL too "http://www.yoursite.com/guard.php", if it is ok

For Windows based websites that use ASP:
1) Download the attachment named "guard.zip"
2) Extract file "guard.asp"
3) Login to your site Control panel.
4) Open "File Manager" window.
5) Go through "wwwroot" directory
6) Choose "Upload Files"
7) Upload the file "guard.asp"
8) Check its URL too "http://www.yoursite.com/guard.asp", if it is ok

Thank you for using our services and products. We look forward to providing you with a unique and high quality service.

Best Regards

Dsredirection Inc

http://www.dsredirection.com
The attachmement guard.asp is a VBscript. I don't read VBScripts, so don't understand what it's doing. But what I fail to understand is why would we need such a protection because when we are using their dsredirection nameservers, we don't have any website to upload the script to? The website doesn't resolve either.

Smells fishy to me.
__________________
Free Whois

Last edited by stu; 02-08-2007 at 02:22 AM..
stu is offline   Reply With Quote
Sponsored Ads
Old 02-08-2007, 03:35 PM   #2 (permalink)
Platinum Lifetime Member
No Avatar
 
Last Online: 03-09-2007 05:28 PM
iTrader: (0)
Join Date: Jan 2007
Posts: 1
DNF$: 103
Location: los angeles
Country:


Re: Anybody else get this?

I can tell you that the email you're referencing DID NOT come from DomainSponsor. I've checked interally and no one has sent out anything like what's being described. Most, if not all, communication from DomainSponsor will come from DSSupport@domainsponsor.com.

At this point it's unclear to me whether this email is attempting to intentionally misrepresent itself as being sent from DomainSponsor, but we obviously take this very seriously and are in the process of investigating further.

Thanks,

DSSupport
DSSupport is offline   Reply With Quote
Old 02-08-2007, 04:24 PM   #3 (permalink)
DNF Regular
 
donsimon's Avatar
 
Name: Donny Simonton
Last Online: Today 08:55 PM
iTrader: (1)
Join Date: Feb 2004
Posts: 1,108
DNF$: 4,063
Location: Florida
Country:


Re: Anybody else get this?

We received one as well and decrypted the script. It's pretty good, basically it emails your server name to a gmail account and they then come to the site and basically have full access to your server. I don't recommend installing it.

Donny
donsimon is offline   Reply With Quote
Old 02-08-2007, 06:59 PM   #4 (permalink)
stu
Platinum Lifetime Member
 
stu's Avatar
 
Last Online: 08-03-2009 04:18 PM
iTrader: (100)
Join Date: Dec 2005
Posts: 541
DNF$: 933
Location: Subic Bay


Re: Anybody else get this?

Welcome to DNF, DSSupport. Nice to know there is someone from DS on this forum.
__________________
Free Whois
stu is offline   Reply With Quote
Old 02-08-2007, 07:05 PM   #5 (permalink)
www.LOL.biz
 
Bender's Avatar
 
Name: Daniel
Last Online: Today 11:43 PM
iTrader: (14)
Join Date: Apr 2004
Posts: 1,891
DNF$: 5,654
Location: .ro
Country:


Re: Anybody else get this?

Quote:
Most, if not all, communication from DomainSponsor will come from DSSupport@domainsponsor.com
the sender email can be easily forged- don't consider that safe.
__________________
Refinance Leads|
Bender is online now   Reply With Quote
Old 02-10-2007, 12:52 AM   #6 (permalink)
stu
Platinum Lifetime Member
 
stu's Avatar
 
Last Online: 08-03-2009 04:18 PM
iTrader: (100)
Join Date: Dec 2005
Posts: 541
DNF$: 933
Location: Subic Bay


Re: Anybody else get this?

I got exactly the same email from verisign.com today. So it looks like somebody's out to do some mischief.
__________________
Free Whois
stu is offline   Reply With Quote
Old 02-10-2007, 01:01 AM   #7 (permalink)
Platinum Lifetime Member
 
lazyleo's Avatar
 
Last Online: 05-21-2009 07:33 AM
iTrader: (35)
Join Date: Jun 2006
Posts: 813
DNF$: 0
Country:


Re: Anybody else get this?

Someone has been naughty and many chances are they watched you here as i checked your profile most of you posts are asking about DS payments so i think they handpicked you.

anyways be extra careful now

regards
lazyleo is offline   Reply With Quote
Old 02-12-2007, 11:27 PM   #8 (permalink)
stu
Platinum Lifetime Member
 
stu's Avatar
 
Last Online: 08-03-2009 04:18 PM
iTrader: (100)
Join Date: Dec 2005
Posts: 541
DNF$: 933
Location: Subic Bay


Re: Anybody else get this?

Anyone else subscribe to this theory?
__________________
Free Whois
stu is offline   Reply With Quote
Old 02-13-2007, 06:33 AM   #9 (permalink)
DNF Regular
 
donsimon's Avatar
 
Name: Donny Simonton
Last Online: Today 08:55 PM
iTrader: (1)
Join Date: Feb 2004
Posts: 1,108
DNF$: 4,063
Location: Florida
Country:


Re: Anybody else get this?

Actually, I don't think it has anything to do with DNForum. They seemed to have went after hosting companies (nameservers) and registrars. So they probably bought WHOIS information or stole it and just sent out the emails.

Donny
donsimon is offline   Reply With Quote
Old 02-14-2007, 05:26 PM   #10 (permalink)
The Bishop
 
namestrands's Avatar
 
Last Online: 09-16-2009 03:42 PM
iTrader: (117)
Join Date: Jan 2005
Posts: 3,954
DNF$: 2,515
Location: UK
Country:


Re: Anybody else get this?

im jealous I did not get one.. Stu can you send me the email, I would not mind seeing its footprint and adding it to my Security Gateway.
namestrands is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 11:47 PM.
Copyright @2001-2009 DNForum.com