Closed Thread
Page 1 of 5
1 2 3 ... LastLast
Results 1 to 20 of 94

Thread: ESE.com hijacked at moniker

  1. #1
    Last Activity Yesterday 12:52 PM
    alldig's Avatar

    Join Date
    Jul 2002
    Location
    Princeton, NJ
    Country
    Posts
    1,198
    DNF$
    130

    ESE.com hijacked at moniker

    On August 20th a person named "j p" ( originalprogz@gmail.com ) contacted me via email and I agreed to sell him ese.com for 33k via sedo.

    On September 2nd we entered into an agreement on sedo at US $33,000.

    On September 4th I received the following email from colin.finnan@sedo.com :

    Dear Mr. Ambrose,

    Congratulations on your purchase.

    Before you can begin the process to assume ownership of this domain you need to place your payment for this domain in escrow on our escrow account.

    For your records we have created a payment request for this transaction that you can access in your account under the "Billing" section. Please feel free to print or use this invoice as necessary. This invoice also contains information on the possible ways of paying the money into our account, as well as our own account/Paypal details.

    Shortly after we confirm receipt of payment we will inform the seller and send an email instructing you as to what steps are needed to process the ownership change. It is often the case that certain preparatory steps need to be taken with the seller prior to providing you with further instructions, so we ask for your patience in this matter.

    Should you have any questions or concerns please feel free to contact us at the email address listed below.

    This is an automatically generated notification. Please do not reply to this email.

    Best regards,

    Colin
    --
    Colin Finnan
    Key Accounts Manager/Transfer Consultant
    Sedo.com :: 161 First Street :: Cambridge, MA 02142
    tel: 617-499-7205 :: fax: 617-499-7203
    email: http://www.sedo.com :: colin.finnan@sedo.com

    Confidentiality Statement: This e-mail, including attachments,
    may include confidential and/or proprietary information, and may
    be used only by the person or entity to which it is addressed.
    If the reader of this e-mail is not the intended recipient or his or her
    authorized agent, the reader is hereby notified that any
    dissemination, distribution or copying of this e-mail is prohibited.
    If you have received this e-mail in error, please notify the sender
    by replying to this message and delete this e-mail immediately.
    I pushed ese.com to the moniker account listed in the email shortly after.

    On September 5th I received the following email from andygrow@yahoo.com :

    hi
    it this your domain ese.com?
    i wan't to buy this domain from some one ....
    i think he is hacked this domain ......
    im waiting your response

    thanks
    Just a few hours ago I received a phone call from Martin Osusky of Sedo notifying me that the email that was sent on September 4th from colin.finnan@sedo.com was a spoof email and that I had pushed ese.com to the hijackers Moniker account. Luckily Martin caught this early on and he has already contacted Moniker. The domain was on ACTIVE status but about 30 minutes ago it was changed to REGISTRAR LOCK.
    -Mike


  2. #2
    Success Is My Only Option
    Last Activity 12-03-2009 10:14 AM
    Carter's Avatar

    Join Date
    Jul 2008
    Location
    Italy
    Country
    Posts
    4,230
    DNF$
    27,107
    Bad story man! :(
    I've thinked to buy ESE.com in Latona newsletter few weeks ago.

    Tell me If I can help you.


  3. #3
    Last Activity Yesterday 12:52 PM
    alldig's Avatar

    Join Date
    Jul 2002
    Location
    Princeton, NJ
    Country
    Posts
    1,198
    DNF$
    130
    Quote Originally Posted by Carter View Post
    Bad story man! :(
    I've thinked to buy ESE.com in Latona newsletter few weeks ago.

    Tell me If I can help you.
    Monte and the Moniker have put the domain on lock and are investigating this case. When the domain is pushed back to my Moniker account it will be for sale again (an offer around the 30k mark will secure the domain). Thanks for the support.

    I copy / pasted the wrong email into my initial post. The email I received from colin.finnan@sedo.com on september 4th read:

    Dear Mr. Ambrose,

    Now that the buyer has made payment into Our escrow account you can push the ese.com domain
    into our Moniker account and finish your part of this transfer.

    Please log into your Moniker account, Go to your Domain management ,Click on Push Button

    And Do The Push with following information:

    Account number: 77514
    Authorization Code: FFC97F476A
    Email: transferserives@sedo.com
    domain name: ese.com

    As soon as the domain is in our Moniker account, we will be able to process
    your payment.

    Now would be a good time to ensure that your payment information with Sedo is
    accurate. Please click on the following link:

    http://www.sedo.com/member/bankdata.php4

    and login to your Sedo account, in order to verify your information.

    Should you have any questions or difficulties with this step please let us
    know.

    Best regards,

    Colin Finnan
    Domain-Transfers
    --
    Sedo GmbH :: Im Mediapark 6 ::50670 Cologne (Germany)
    tel +49 221.34030.188 :: fax +49 221.34030.109
    http://www.sedo.com :: mailto: colin.finnan@sedo.com

    District Court of Cologne HRB 35019
    Board of Management: Tim Schumacher, Ulrich Priesner, Marius W?

    Confidentiality Statement:
    This e-mail, including attachments, may include confidential and/or proprietary
    information, and may be used only by the person or entity to which it is
    addressed. If the reader of this e-mail is not the intended recipient or his or
    her authorized agent, the reader is hereby notified that any dissemination,
    distribution or copying of this e-mail is prohibited. If you have received this
    e-mail in error, please notify the sender by replying to this message and
    delete this e-mail immediately.
    Last edited by alldig; 09-06-2008 at 05:15 PM. Reason: Automerged Doublepost
    -Mike


  4. #4
    Bloody lovely
    Last Activity Today 01:59 PM
    Acro's Avatar

    Join Date
    Feb 2004
    Location
    USA
    Country
    Posts
    24,173
    DNF$
    5,217
    Yet another Sedo flaw that goes back to the days of the NetSol transfer email spoofing. Sedo should not send these emails out - some containing auth keys - they should ONLY send notifications asking you to log into your account to perform the task.

    Can you post the email headers here?
    Last edited by Acro; 09-06-2008 at 05:45 PM. Reason: Automerged Doublepost

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog


  5. #5
    T_T
    Last Activity 02-05-2010 12:08 PM
    rentdn's Avatar

    Join Date
    Aug 2004
    Location
    Armenia
    Country
    Posts
    797
    DNF$
    4,719
    I never thought about such scam before , that a**holes are making everything just to get something which they do not deserve to own


  6. #6
    DNF Addict
    Last Activity Today 02:01 PM
    randomo's Avatar

    Join Date
    Nov 2002
    Country
    Posts
    2,293
    DNF$
    8,857
    There were some dead giveaways in the September 4th email: the wording was rough, and the capitalization and punctuation were poor. Scammers seldom speak the Queen's English.

    Having said that ... whenever I receive a request to perform an action on a Sedo sale, I always log into my Sedo account and make sure that the progress of the transaction is correctly reflected there, before I make the payment or push the domain.

    Good luck, glad to hear that Moniker seems to have things under control for you!

    P.S. Sedo has been around a long time, and they have a much smaller Moniker account number than the one in that letter!
    Last edited by randomo; 09-06-2008 at 06:13 PM. Reason: Automerged Doublepost

    If you know someone with one of these names, I have a great domain for them:

    Eamonn / Harriet / Helen / Henry / Isadore / Joan / Piet / William / etc.!


  7. #7
    Success Is My Only Option
    Last Activity 12-03-2009 10:14 AM
    Carter's Avatar

    Join Date
    Jul 2008
    Location
    Italy
    Country
    Posts
    4,230
    DNF$
    27,107
    Acro it's time to create a new article on your blog about this new scam.


  8. #8
    Last Activity 01-30-2010 11:05 AM
    gemsergio's Avatar

    Join Date
    Apr 2003
    Country
    Posts
    693
    DNF$
    12,976
    Wow I would have probably fallen for it.
    Smiletrain.org

    250 USD can really change a life.

    Atheist and proud.

    On the first day, man created God.

    Religion is regarded by the common people as true, by the wise as false, and by the rulers as useful.

    The spanish gay
    community is now live. gay.es


  9. #9
    Last Activity Yesterday 12:52 PM
    alldig's Avatar

    Join Date
    Jul 2002
    Location
    Princeton, NJ
    Country
    Posts
    1,198
    DNF$
    130
    Quote Originally Posted by Acro View Post
    Yet another Sedo flaw that goes back to the days of the NetSol transfer email spoofing. Sedo should not send these emails out - some containing auth keys - they should ONLY send notifications asking you to log into your account to perform the task.

    Can you post the email headers here?
    Return-Path: <pejudgem@tmz.tmzhosting.com>
    Received: from smtp6.hushmail.com (smtp6.hushmail.com [65.39.178.137])
    by imap9.hushmail.com (Cyrus v2.2.12-Invoca-RPM-2.2.12-8.1.RHEL4) with LMTPA;
    Thu, 04 Sep 2008 16:06:54 +0000
    X-Sieve: CMU Sieve 2.2
    Received: from tmz.tmzhosting.com (2a.88.5546.static.theplanet.com [70.85.136.42])
    (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
    (No client certificate requested)
    by smtp6.hushmail.com (Postfix) with ESMTP
    for <admin@domainhighway.com>; Thu, 4 Sep 2008 16:06:52 +0000 (UTC)
    Received: from pejudgem by tmz.tmzhosting.com with local (Exim 4.69)
    (envelope-from <pejudgem@tmz.tmzhosting.com>)
    id 1KbFih-00039Q-1s; Thu, 04 Sep 2008 09:21:59 -0500
    To: admin@domainhighway.com
    Subject: Transfer of ese.com
    X-PHP-Script: www.foolex.com/fake/ese/email.php for 91.98.154.140
    From: "colin.finnan@sedo.com" <colin.finnan@sedo.com>
    Reply-To: "colin.finnan@sedo.com" <colin.finnan@sedo.com>
    To:<admin@domainhighway.com>
    Mime-Version: 1.0
    Content-type: text/html; charset=utf-8
    Content-Transfer-Encoding: 7bit
    Message-Id: <E1KbFih-00039Q-1s@tmz.tmzhosting.com>
    Date: Thu, 04 Sep 2008 09:21:59 -0500
    X-TmzHosting-MailScanner-Information: Please contact the ISP for more information
    X-MailScanner-ID: 1KbFih-00039Q-1s
    X-TmzHosting-MailScanner: Not scanned: please contact your Internet E-Mail Service Provider for details
    X-TmzHosting-MailScanner-SpamCheck:
    X-TmzHosting-MailScanner-From: pejudgem@tmz.tmzhosting.com
    X-Spam-Status: No
    X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
    X-AntiAbuse: Primary Hostname - tmz.tmzhosting.com
    X-AntiAbuse: Original Domain - domainhighway.com
    X-AntiAbuse: Originator/Caller UID/GID - [32209 32212] / [47 12]
    X-AntiAbuse: Sender Address Domain - tmz.tmzhosting.com

    It looks like the guy used www.foolex.com/fake/ese/email.php to generate/send the email. If you click on that link the same exact email that I received on Sept 4th will be sent to admin@domainhighway.com
    Last edited by alldig; 09-06-2008 at 06:47 PM. Reason: Automerged Doublepost
    -Mike


  10. #10
    Bloody lovely
    Last Activity Today 01:59 PM
    Acro's Avatar

    Join Date
    Feb 2004
    Location
    USA
    Country
    Posts
    24,173
    DNF$
    5,217
    http://whois.domaintools.com/foolex.com is a newly registered domain from Iran.

    The IP is also in Iran.
    Last edited by Acro; 09-06-2008 at 06:52 PM. Reason: Automerged Doublepost

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog


  11. #11
    DNStore.com
    Last Activity Today 09:07 AM
    owntag's Avatar

    Join Date
    Jul 2006
    Location
    U.K
    Country
    Posts
    1,492
    DNF$
    935
    The fake email script is hosted at tmzhosting? I have an account there on their server.


  12. #12
    Bloody lovely
    Last Activity Today 01:59 PM
    Acro's Avatar

    Join Date
    Feb 2004
    Location
    USA
    Country
    Posts
    24,173
    DNF$
    5,217
    Contact TMZHosting.com to let them know that they have a thief on their network.

    They also own this domain http://whois.domaintools.com/pejudgement.com
    Last edited by Acro; 09-06-2008 at 06:55 PM. Reason: Automerged Doublepost

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog


  13. #13
    Success Is My Only Option
    Last Activity 12-03-2009 10:14 AM
    Carter's Avatar

    Join Date
    Jul 2008
    Location
    Italy
    Country
    Posts
    4,230
    DNF$
    27,107
    These bastards...


  14. #14
    Bloody lovely
    Last Activity Today 01:59 PM
    Acro's Avatar

    Join Date
    Feb 2004
    Location
    USA
    Country
    Posts
    24,173
    DNF$
    5,217
    Last edited by Acro; 09-06-2008 at 07:06 PM. Reason: Automerged Doublepost

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog


  15. #15
    DNF Addict
    Last Activity 01-10-2010 02:13 PM

    Join Date
    Nov 2003
    Location
    Montreal
    Country
    Posts
    1,742
    DNF$
    1,313
    I recently was contacted also by a gmail address asking me to sell my domains via sedo.
    We agreed on a price for both domains, but Sedo canceled the transactions letting me know that something did not seem right about the bidder.
    The bidder never replied to Sedo's emails, and 1 day after my accounts were all hacked.
    I don't know if there is a link between the buyer and my hacked accounts, but it seems like these bidders are throwing you into sedo and then causing some damage somehow...


  16. #16
    DNF Addict
    Last Activity Yesterday 11:30 AM
    James's Avatar

    Join Date
    Feb 2004
    Location
    NEPA.US
    Country
    Posts
    2,198
    DNF$
    9,513
    So how was it hijacked from moniker as stated in the thread title ??
    You pushed it to a user account and moniker locked it when notified from sedo ??
    Sorry but hijacked..to me ..means taken from..not pushed to
    But at least it was caught..thanks for the heads-up..will more closely at those sedo emails

    jim
    Note:My posted Sales Prices are valid for 3 Days only
    Most my domains listed for sale are available at sedo.com


  17. #17
    Success Is My Only Option
    Last Activity 12-03-2009 10:14 AM
    Carter's Avatar

    Join Date
    Jul 2008
    Location
    Italy
    Country
    Posts
    4,230
    DNF$
    27,107
    Quote Originally Posted by bdjuf View Post
    I recently was contacted also by a gmail address asking me to sell my domains via sedo.
    We agreed on a price for both domains, but Sedo canceled the transactions letting me know that something did not seem right about the bidder.
    The bidder never replied to Sedo's emails, and 1 day after my accounts were all hacked.
    I don't know if there is a link between the buyer and my hacked accounts, but it seems like these bidders are throwing you into sedo and then causing some damage somehow...
    Same thing happen to me more than one month ago.
    I've had to change all my usernames, passwords, accounts.
    Here too.


  18. #18
    Domaining on steroids
    Last Activity Today 01:27 PM
    sdsinc's Avatar

    Join Date
    Jul 2005
    Location
    unfree world
    Country
    Posts
    4,954
    DNF$
    22,279
    Any E-mail can be faked, including paypal notifications.
    Always log in to your paypal account to check if the money actually is there.

    Also have look at this:
    http://www.foolex.com/fake/

    The scummer is ready to strike against other domains


  19. #19
    Bloody lovely
    Last Activity Today 01:59 PM
    Acro's Avatar

    Join Date
    Feb 2004
    Location
    USA
    Country
    Posts
    24,173
    DNF$
    5,217
    Looks like EYS.com is being worked on!!
    http://whois.domaintools.com/eys.com

    Check out the whois.

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog


  20. #20
    Success Is My Only Option
    Last Activity 12-03-2009 10:14 AM
    Carter's Avatar

    Join Date
    Jul 2008
    Location
    Italy
    Country
    Posts
    4,230
    DNF$
    27,107
    Quote Originally Posted by Acro View Post
    Looks like EYS.com is being worked on!!
    http://whois.domaintools.com/eys.com

    Check out the whois.
    This rat love LLL.com's starting with "E"


Closed Thread
Page 1 of 5
1 2 3 ... LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts