Welcome to Welcome to DNF.com™ - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars

If you are new to domains and looking to buy, sell and learn about domains then you have come to the right place. DNForum is the largest domain name community on the internet and continues to grow every day. There are over 105,000 domainers on DNForum doing everything from buying domains, selling domains, learning about domains and discussing domains. Take a minute and Register.

Register Today on DNForum IT'S FREE!

Page 1 of 2 12 LastLast
Results 1 to 20 of 23
  1. #1
    Exclusive Lifetime Member
    Mazkel's Avatar
    Join Date
    Mar 2008
    Location
    Massachusetts
    Posts
    1,135
    Country

    United States
    DNF$
    5,731
    Bank
    0
    Total DNF$
    5,731
    Donate  

    "ExclusiveMember" trying to sell me a domain he doesn't own

    FYI

    "ExclusiveMember" sent me a PM yesterday trying to sell me UXH (.) com for 3.5k and asking for an MSN email address. I've already contacted the owner (who is also a member on DNF) who states that she has not sold it.

    Mods - please move to appropriate section if needed.

  2. #2
    is out kiteboarding
    loscocco's Avatar
    Join Date
    Nov 2005
    Location
    San Francisco
    Posts
    2,205
    DNF$
    9,293
    Bank
    0
    Total DNF$
    9,293
    Donate  
    Thanks Mazkei for letting me know.. I am the real owner of UXH.com and have been so for the past year or so. It still shows as being locked in my account and i have changed all the passwords but if this person contacts anyone else please report the thread to the mods and me.
    Glad to have people with a watchful eye out there in the community like yourself.
    Erin

    ---------- Post added at 06:45 AM ---------- Previous post was at 06:42 AM ----------

    Edit.. just like the Whois just changed in the past few minutes
    this domain is STOLEN.
    i am on the phone with Moniker right now.
    Erin
    Photo-graphy.com <=== for Sale CLICK HERE

    BuyAGood.com <=== For Sale CLICK HERE

  3. #3
    GreenFriendly.com
    biggedon's Avatar
    Join Date
    Sep 2002
    Location
    96.net
    Posts
    13,257
    Blog Entries
    1
    Country

    United States
    DNF$
    59,380
    Bank
    0
    Total DNF$
    59,380
    Donate  
    which exclusive member sent the pm?
    Need A SedoPro Account PM Me * nev.org * pmm.org * svc.net * ispoof.com * umm.org * sop.net * qfm.net * upyo.com * vioz.com * uce.org * wta.net * eoso.com * Coming Soon: Appraise.xxx

  4. #4

    Join Date
    Apr 2003
    Location
    .us
    Posts
    1,855
    DNF$
    8,471
    Bank
    0
    Total DNF$
    8,471
    Donate  
    He sent me a pm also trying to trade it. Member name is 'ExclusiveMember'.

  5. #5
    Exclusive Lifetime Member
    Mazkel's Avatar
    Join Date
    Mar 2008
    Location
    Massachusetts
    Posts
    1,135
    Country

    United States
    DNF$
    5,731
    Bank
    0
    Total DNF$
    5,731
    Donate  
    Quote Originally Posted by biggedon View Post
    which exclusive member sent the pm?
    His member name is "ExlusiveMember". Has been around since 2006.

  6. #6
    Country hopper
    katherine's Avatar
    Join Date
    Jul 2005
    Location
    Free World
    Posts
    7,499
    Country

    Iceland
    DNF$
    30,536
    Bank
    0
    Total DNF$
    30,536
    Donate  
    That E-mail address is associated with at least one other LLL.com: Sqn.com

    Plus, that person appears to have owned teens.us: http://74.125.77.132/search?q=cache:...s&client=opera

    ---------- Post added at 05:05 PM ---------- Previous post was at 05:01 PM ----------

    Owns refund.us too.
    NameNewsletter.com - free lists of available domain names
    ZoneFiles.net (beta) - ccTLD and gTLD droplists

  7. #7
    Platinum Lifetime Member
    Millering's Avatar
    Join Date
    Sep 2009
    Location
    NanJing
    Posts
    285
    Country

    China
    DNF$
    1,406
    Bank
    0
    Total DNF$
    1,406
    Donate  
    Thank you Mazkel,
    how come a 2006 member doing this? Or his account was compromised?

  8. #8
    is out kiteboarding
    loscocco's Avatar
    Join Date
    Nov 2005
    Location
    San Francisco
    Posts
    2,205
    DNF$
    9,293
    Bank
    0
    Total DNF$
    9,293
    Donate  
    Moniker is currently doing an investigation regarding UXH.com
    thanks everyone for noticing this.
    Photo-graphy.com <=== for Sale CLICK HERE

    BuyAGood.com <=== For Sale CLICK HERE

  9. #9
    Bloody Hell
    Acro's Avatar
    Join Date
    Feb 2004
    Location
    USA
    Posts
    28,666
    Country

    Holy See
    DNF$
    15,567
    Bank
    0
    Total DNF$
    15,567
    Donate  
    Ah, "brilliant".

    So by using the moniker "ExclusiveMember" he tried to pull the same trick Odysseas did with Cyclops Polyphemus; when asked what is his name, he said "Nobody". When Odysseas and his mates blinded him, Polyphemus screamed to his brothers that "Nobody was blinding him"

    So "ExclusiveMember" is faking his status. With 2 posts since 2006 it looks like a compromised account.

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog

  10. #10
    Platinum Lifetime Member
    Seraphim's Avatar
    Join Date
    Jan 2006
    Location
    Hillsboro, OR
    Posts
    3,609
    DNF$
    18,201
    Bank
    0
    Total DNF$
    18,201
    Donate  
    Quote Originally Posted by Acro View Post
    So by using the moniker "ExclusiveMember" he tried to pull the same trick Odysseas did with Cyclops Polyphemus; when asked what is his name, he said "Nobody". When Odysseas and his mates blinded him, Polyphemus screamed to his brothers that "Nobody was blinding him"
    Poland City Portfolio For Sale: Bialystok.com | Gdynia.com | Sosnowiec.com | Torun.com | Zabrze.com | Olsztyn.com | Rybnik.com | Tychy.com | Elblag.com | Opole.com | ZielonaGora.com | Wloclawek.com

  11. #11
    Bloody Hell
    Acro's Avatar
    Join Date
    Feb 2004
    Location
    USA
    Posts
    28,666
    Country

    Holy See
    DNF$
    15,567
    Bank
    0
    Total DNF$
    15,567
    Donate  
    Odyssey is full of lessons

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog

  12. #12
    Platinum Lifetime Member
    Nathan King's Avatar
    Join Date
    Jul 2009
    Posts
    253
    Country

    United States
    DNF$
    1,101
    Bank
    0
    Total DNF$
    1,101
    Donate  
    If the account was compromised then dnforum has serious problems. The forum software blocks brute-force attempts so if accounts are being compromised it is most like via sql injection. SQL injection means often times that the hacker has full access to the database. Any information that is not properly encrypted would be available to the hacker.

    If the account was compromised via SQL injection, it is most likely because the hacker has acquired the password from the database (md5 or sha1 hashed). A hashed password is not as secure as one that is properly encrypted as it can easily be brute forced if not long/obscure enough.

    This is why it is important to have a long password containing numbers and symbols. Short passwords or passwords containing a dictionary word (such as "swordfish" or "mousepad3") can quickly and easily be brute forced. Make sure that your password contains capital letters, numbers, and symbols. The longer the better, but at least 9-10 characters long is necessary to prevent brute-forcing.

    Many people use the same password for multiple sites. Think about what kind of damage could be done if this were the case and a hacker got a hold of your password.

  13. #13
    GreenFriendly.com
    biggedon's Avatar
    Join Date
    Sep 2002
    Location
    96.net
    Posts
    13,257
    Blog Entries
    1
    Country

    United States
    DNF$
    59,380
    Bank
    0
    Total DNF$
    59,380
    Donate  
    Quote Originally Posted by Acro View Post
    Ah, "brilliant".

    So by using the moniker "ExclusiveMember" he tried to pull the same trick Odysseas did with Cyclops Polyphemus; when asked what is his name, he said "Nobody". When Odysseas and his mates blinded him, Polyphemus screamed to his brothers that "Nobody was blinding him"

    So "ExclusiveMember" is faking his status. With 2 posts since 2006 it looks like a compromised account.
    theo, i like the analogy




    one thing i suggested a while back, was that the forum should restrict the use of certain dn forum "user" names.

    as such, a user's name can i cases "confuse" others into thinking "what we/i thought" ( as in "exclusivemembers'" level of membership) as well as put members into a state of "assumption" about one's "extertise" in a field when using a "user" name for example "seoexpert"...if you have no proven seo skills ( no offense to seoexpert) or "platinummember or platinumember" etc..


    also, this gold member was trying to sell via pm and i'm wondering if it was reported. since gold members aren't allowed to "solicit domains for sale"?

    if the seller was legit and was willing to go thru escrow or other secure means, as a gold member, they would never have to upgrade, since they were conducting biz via pm's.

    who's going to report a member when they are getting great deals?

    maybe no one...until they get scammed!



    netsniff.....do i smell a loophole somewhere



    if so, how you gonna fill it?
    Need A SedoPro Account PM Me * nev.org * pmm.org * svc.net * ispoof.com * umm.org * sop.net * qfm.net * upyo.com * vioz.com * uce.org * wta.net * eoso.com * Coming Soon: Appraise.xxx

  14. #14
    Bloody Hell
    Acro's Avatar
    Join Date
    Feb 2004
    Location
    USA
    Posts
    28,666
    Country

    Holy See
    DNF$
    15,567
    Bank
    0
    Total DNF$
    15,567
    Donate  
    Quote Originally Posted by Nathan King View Post
    If the account was compromised then dnforum has serious problems.
    There is no "need" for a BF attack; your password can be stolen locally - from your machine. Install a good antivirus and never chat with strangers over AIM etc.

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog

  15. #15
    Platinum Lifetime Member
    Nathan King's Avatar
    Join Date
    Jul 2009
    Posts
    253
    Country

    United States
    DNF$
    1,101
    Bank
    0
    Total DNF$
    1,101
    Donate  
    Quote Originally Posted by Acro View Post
    There is no "need" for a BF attack; your password can be stolen locally - from your machine. Install a good antivirus and never chat with strangers over AIM etc.
    If the account was not logged-in to but a couple times a couple years ago, I wouldn't think the password would still be on the computer. And packet sniffing wouldn't work either if the account was never accessed.

  16. #16
    Bloody Hell
    Acro's Avatar
    Join Date
    Feb 2004
    Location
    USA
    Posts
    28,666
    Country

    Holy See
    DNF$
    15,567
    Bank
    0
    Total DNF$
    15,567
    Donate  
    The last time I saw BF being used by script kiddies was 10 years ago. Today's commercial products, including vBulletin, have methods in place to prevent the storage of weak passwords to begin with. Never underestimate the ability of trojans though or of social networking.

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog

  17. #17
    Platinum Lifetime Member
    Nathan King's Avatar
    Join Date
    Jul 2009
    Posts
    253
    Country

    United States
    DNF$
    1,101
    Bank
    0
    Total DNF$
    1,101
    Donate  
    Quote Originally Posted by Acro View Post
    The last time I saw BF being used by script kiddies was 10 years ago. Today's commercial products, including vBulletin, have methods in place to prevent the storage of weak passwords to begin with. Never underestimate the ability of trojans though or of social networking.
    The 2nd example of a weak password that I provided would be accepted by vbulletin and this site. vBulletin does use a salt when storing the password which makes it considerably more secure, but don't underestimate sql injection. Some of the biggest sites you've hear of have had major sql injection exploits in recent years.

  18. #18
    Bloody Hell
    Acro's Avatar
    Join Date
    Feb 2004
    Location
    USA
    Posts
    28,666
    Country

    Holy See
    DNF$
    15,567
    Bank
    0
    Total DNF$
    15,567
    Donate  
    SQL injection depends on severe flaws of the underlying software; with vBulletin's update cycle there is literally no time for 'zero day' exploits. What I'm trying to say is, that this looks like an isolated incident of an account that was either created a long time ago to create malice when time would come, or an account theft from someone's computer.

    DomainGang.com - Digital Entertainment for Domainers
    Acroplex - Web & Graphics
    Acro.net - My Blog

  19. #19
    Country hopper
    katherine's Avatar
    Join Date
    Jul 2005
    Location
    Free World
    Posts
    7,499
    Country

    Iceland
    DNF$
    30,536
    Bank
    0
    Total DNF$
    30,536
    Donate  
    Another possibility is the hijacking of the E-mail account of the member. Or his password(s) leaked due to being infected by a keylogger.
    NameNewsletter.com - free lists of available domain names
    ZoneFiles.net (beta) - ccTLD and gTLD droplists

  20. #20
    Platinum Lifetime Member
    Nathan King's Avatar
    Join Date
    Jul 2009
    Posts
    253
    Country

    United States
    DNF$
    1,101
    Bank
    0
    Total DNF$
    1,101
    Donate  
    The account was last logged into 4 years ago and even then only 2 posts were made. So I don't see where people get the idea it was a trojan or keylogger as these require the account owner to log in to be effective. If the account was recent then yes these are likely possibilities but the account has been inactive for 4 years.

    ---------- Post added at 04:52 PM ---------- Previous post was at 04:46 PM ----------

    Most likely the original account owner is the scammer however if the account was compromised it was done via different means than trojans or keyloggers or packet sniffers. I've seen many accounts get hijacked on other major forums via sql injection (even vbulletin, but that was 3-4 years ago) so if you ask me that would be the most likely scenario given the facts. Any plugin or custom coding done could create sql injection vulnerabilities, so it is not limited to vbulletin exploits.

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Domain name forum recommended by Domaining.com