Closing Doman Auctions
DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars
HomeRegisterMembershipsGetting StartedDomain Tools Domain EbooksSEO Software Domain Resellers Advertise

Go Back   DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars > Domain News, Beginners Guides and Legal Stuff! > Domain Name Legal Issues
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 09-02-2007, 06:43 AM   #1 (permalink)
TheBest.com
 
GeorgeK's Avatar
 
Name: George Kirikos
Last Online: Today 08:47 AM
iTrader: (2)
Join Date: May 2002
Posts: 2,206
DNF$: 866
Location: Toronto, Canada
Country:


Exclamation More stolen domains: bo.com, pu.com, jy.com, showroom.com, samantha.com

I received an email this morning offering:

bo.com
pu.com
jy.com
showroom.com
samantha.com

for $300K.

All had recent WHOIS changes, changing registrars and admin emails. I contacted the true owner by phone (using the WHOIS history), and they were definitely stolen, and he's now in the process of recovering them.
__________________
George Kirikos
Home Page
GeorgeK is offline   Reply With Quote
Sponsored Ads
Old 09-02-2007, 06:47 AM   #2 (permalink)
Bloody lovely
 
Acro's Avatar
 
Last Online: Today 02:57 AM
iTrader: (394)
Join Date: Feb 2004
Posts: 23,904
DNF$: 4,079
Location: USA
Country:




Wasn't bo.com on eBay recently?

Seems that the thief parked samantha.com and showroom.com on Sedo (traffic is low, gotta love those "generics" )
The email jymbarnes @ gmail seems to be fake.
__________________

DomainGang.com - Domainers' Most Awesome News Source
Acroplex - Web & Graphics
Acro.net - My Blog
My Countdown Counting down to: Snapnames rebate hitting my mailbox
78 days 11 hours 35 minutes

Last edited by Acro; 09-02-2007 at 06:52 AM.. Reason: Automerged Doublepost
Acro is offline   Reply With Quote
Old 09-02-2007, 07:06 AM   #3 (permalink)
TheBest.com
 
GeorgeK's Avatar
 
Name: George Kirikos
Last Online: Today 08:47 AM
iTrader: (2)
Join Date: May 2002
Posts: 2,206
DNF$: 866
Location: Toronto, Canada
Country:


Yes, it was on eBay (not authorized by true owner). But, now the thief has control of the names.
__________________
George Kirikos
Home Page
GeorgeK is offline   Reply With Quote
Old 09-02-2007, 07:36 AM   #4 (permalink)
Domain Magnate™
 
DomainMagnate's Avatar
 
Name: Michael
Last Online: 11-22-2009 03:30 PM
iTrader: (68)
Join Date: Nov 2005
Posts: 3,637
DNF$: 6,457
Location: DnMagnate.com


Now that really wakes me worry. I've set all my domains whois to an email on my domain and installed roboform.. luckily I don't have any 2 letter .com

~MG
__________________
Domain Magnate Mind Reading
DomainMagnate is offline   Reply With Quote
Old 09-02-2007, 07:50 AM   #5 (permalink)
TheBest.com
 
GeorgeK's Avatar
 
Name: George Kirikos
Last Online: Today 08:47 AM
iTrader: (2)
Join Date: May 2002
Posts: 2,206
DNF$: 866
Location: Toronto, Canada
Country:


It's generally not good practice to have the admin email of a domain be on the same domain name (e.g. if you own example.com, don't use me@example.com as the admin). If you lose control of the domain name by various other means, the thief automatically controls the admin email, and thus the WHOIS and WHOIS history will show an unbroken chain of the admin email address not changing. If your DNS or hosting goes down (think major DDOS attack or something), your email will go down to the domain, and you'll then have issues to legitimately transfer it by responding from the admin email.
__________________
George Kirikos
Home Page
GeorgeK is offline   Reply With Quote
Old 09-02-2007, 07:56 AM   #6 (permalink)
Dances With Dogs
 
Doc Com's Avatar
 
Name: info [@] gerry.mobi
Last Online: Today 12:10 PM
iTrader: (73)
Join Date: Dec 2006
Posts: 10,308
DNF$: 25,537
Country:



Any idea how someone is getting control of these rather than assumptions?

Where were these registered?

Is it something that the true owner failed to do?

It would be great if you could shed some light on this.

These are some serious issues that we all need to be made aware of.
__________________



Conservative With A Conscience

Doc Com is online now   Reply With Quote
Old 09-02-2007, 09:33 AM   #7 (permalink)
TheBest.com
 
GeorgeK's Avatar
 
Name: George Kirikos
Last Online: Today 08:47 AM
iTrader: (2)
Join Date: May 2002
Posts: 2,206
DNF$: 866
Location: Toronto, Canada
Country:


I also submitted info to Sedo (maybe more than one person should, so that they don't miss it), advising them that the names are stolen, and not to resell them to innocent victims.
__________________
George Kirikos
Home Page
GeorgeK is offline   Reply With Quote
Old 09-02-2007, 10:19 AM   #8 (permalink)
jdk
DNF Addict
 
jdk's Avatar
 
Name: Doug
Last Online: Yesterday 07:44 PM
iTrader: (175)
Join Date: Jul 2004
Posts: 6,886
DNF$: 68,548
Location: Florida
Country:


BO.com ended at $300k on eBay the other day
jdk is offline   Reply With Quote
Old 09-02-2007, 10:32 AM   #9 (permalink)
 
TheLegendaryJP's Avatar
 
Last Online: Today 12:20 PM
iTrader: (35)
Join Date: Jul 2005
Posts: 3,166
DNF$: 6,336
Country:




Maroulis bid $300k to keep anyone from winning it so no it didn't sale to anyone.

Shame to hear the theif also got control of it and others. The owner seemed like a nice guy , wonder if he even knew he had been hacked yet ?
__________________
Gregory.com
$99k obo
TheLegendaryJP is online now   Reply With Quote
Old 09-02-2007, 11:11 AM   #10 (permalink)
Administrator
 
DotComGod's Avatar
 
Name: Adam Dicker
Last Online: Today 10:10 AM
iTrader: (39)
Join Date: Feb 2003
Posts: 10,761
DNF$: 4,589,567
Location: Toronto, Canada
Country:

Send a message via MSN to DotComGod

Quote:
Originally Posted by GeorgeK View Post
It's generally not good practice to have the admin email of a domain be on the same domain name (e.g. if you own example.com, don't use me@example.com as the admin). If you lose control of the domain name by various other means, the thief automatically controls the admin email, and thus the WHOIS and WHOIS history will show an unbroken chain of the admin email address not changing. If your DNS or hosting goes down (think major DDOS attack or something), your email will go down to the domain, and you'll then have issues to legitimately transfer it by responding from the admin email.
George,

How do you reccomend we setup the whois on our domains if we don't tie it to one we own?

I am open to any good security measures.

Thanks for the info!

Ok, just re-read your post, just not same admin as domain.

Thanks,

-=DCG=-
__________________
sm.com - Sports Maniacs!
The Ultimate Sports Website!
Official Launch December 1st, 2009
DotComGod is offline   Reply With Quote
Old 09-02-2007, 12:28 PM   #11 (permalink)
 
Ashaw's Avatar
 
Name: Andrew Shaw
Last Online: Today 12:12 PM
iTrader: (99)
Join Date: Sep 2005
Posts: 3,460
DNF$: 0
Location: Maryland
Country:

Send a message via AIM to Ashaw Send a message via MSN to Ashaw

This would be a good time for anyone who hasn't done so...
  1. In excel, notepad, or word... Make a list of domain names you own. If you own domain names in different registers, be sure to be specific. Make note of expiration dates, and when they were registered... THIS IS IMPORTANT.
  2. Though it may take hours... Dont save your personal information in your email, especially if you have freemail. (Gmail, hotmail, yahoo, etc...)
  3. If your email provider allows you to, export your email's, invest in a $20 flash drive, and store them there.

As everyone knows, every domain name in every register I own was hijacked about a week ago. A week before it happened, I had compiled a list of all the domain names that I own.

A lot of times, Hijacking is caused by hacking of your email account. A basic keylogging virus will get the hacker direct access.

If your email account is hacked. The list of domain names, registers, expiration dates and register dates will give the registers the information needed to do their investigation. Unless you have a really good memory, your domain names need to be recorded by other ways besides your email and register. Your register can simply take that list, and freeze those specific domain names untill they look into the matter further. From what I understand, registers cant look into your account and see which domain names have been pushed out, but thats just based on my conversations and experience with my issue. If you can contact your register and tell them "these 127 domain names have been pushed from my account without my authorization, they were registered on... and were not set to expire untill...." your chances of getting those domain names back are a lot higher.

Registers get a lot of emails from customers that accidently let there domain names drop. Letting them know right off the back, when your domain name was registered, and when it was suppose to expire, will seperate your email from those.

By exporting your emails, even if your email account IS hacked... You will rest easy knowing that your true personal information is safe in your pocket. If your email provider doesnt allow you to export your email's... I would suggest creating a seccond email account, and forwarding all personal emails there. Remember to delete your "sent box" after. Make sure your seccond email account IS NOT associated with your whois, or posted on any other public forums.

My domain names were registered in 3 seperate accounts. Based on my experience, here is what you should do if for any reason you have a hijacking issue.

If your domain names are hijacked from Godaddy: You will need to contact undo @ godaddy.com. Calling godaddy will only waste time, as they will tell you to do the same. This is where the information you logged in excel, notepad or word will come in handy. They will want to know when the domain name was created, and when it was set to expire... for the reasons stated above. Mark your email as URGENT. If they take more then a day to respond to your email, Email them again... Let them know that if they cant do something about your issue today, you will need to talk to Bob Parsons directly. Mark all emails as URGENT.

Domainsite: Email Jennifer @ domainsite.com, include all information above. Then call Domainsite's number at 303-459-6012, push 4 for customer service, and ask for jennifer. If she isnt available... you should explain your situation to whoever answers. Make sure you tell them you have a list of all information needed if they would like you to email it to them. Mark any emails as URGENT.

Moniker: Email support @ corp.moniker.com with the above information, then call 1-800-688-6311 and explain your situation. If you dont get a reply within 2 days, email them again, and insist that if they cant help you today, you would like to speak with Monte.
__________________
Domain Research Tool
Save $120 off your order with this link!
Find Traffic Domain names with ease!
My Countdown Counting down to: California
178 days 14 hours 41 minutes

Last edited by Ashaw; 09-02-2007 at 12:32 PM..
Ashaw is online now   Reply With Quote
Old 09-02-2007, 04:39 PM   #12 (permalink)
PremiumDomainNames.net
 
Argie's Avatar
 
Last Online: 10-12-2009 01:09 PM
iTrader: (20)
Join Date: Aug 2004
Posts: 1,489
DNF$: 1,881
Location: Barcelona
Country:

Send a message via MSN to Argie

Thanks Andrew. Very good information. Thanks for share.
__________________
Translate your Sites From English to Spanish

If you are reading this, you are the resistence.
Argie is offline   Reply With Quote
Old 09-02-2007, 06:56 PM   #13 (permalink)
Platinum Lifetime Member
No Avatar
 
Name: D. Giordano
Last Online: Today 07:40 AM
iTrader: (2)
Join Date: Apr 2007
Posts: 309
DNF$: 281
Location: Utah
Country:


Is it normally this bad and usually goes unnoticed, or are these thefts on the drastic increase? With FastFood.com, Story.com, NewsPaper.com, and a few others being found stolen last week, our premium domains are looking more at risk than ever!

I know lately I have been getting a few suspicious emails. All you need to do is click on a link or reply to an email and the recipient has your ip address, which is the raw foundation to hacking ones computer. Granted you didn't have a strong firewall. Personally, I have made all my passwords the maximum length possible. Now, if I can only remember what it is......
__________________
Linkin
Giode is offline   Reply With Quote
Old 09-03-2007, 10:03 PM   #14 (permalink)
EJS
Platinum Lifetime Member
 
EJS's Avatar
 
Last Online: Yesterday 11:01 PM
iTrader: (32)
Join Date: Feb 2006
Posts: 1,970
DNF$: 1,042
Location: Manhattan, NYC
Country:


Are there any email providers that allow you to get a password fob that changes every 60 seconds? I think Paypal just offered this for $5/each, but it would be great if some other services offered this.
__________________
Lowell
EJS is offline   Reply With Quote
Old 09-03-2007, 11:03 PM   #15 (permalink)
Dn Guru©
 
-ET-'s Avatar
 
Name: 3ldo Thomas
Last Online: 11-20-2009 03:17 PM
iTrader: (41)
Join Date: Nov 2006
Posts: 552
DNF$: 538
Location: Neighbourhood

Send a message via MSN to -ET-

He also stole stl.net from which he gained access to five other premium domain which was mentioned above.

Last edited by -ET-; 09-03-2007 at 11:39 PM..
-ET- is offline   Reply With Quote
Old 09-04-2007, 08:53 PM   #16 (permalink)
 
Ashaw's Avatar
 
Name: Andrew Shaw
Last Online: Today 12:12 PM
iTrader: (99)
Join Date: Sep 2005
Posts: 3,460
DNF$: 0
Location: Maryland
Country:

Send a message via AIM to Ashaw Send a message via MSN to Ashaw

Bump
__________________
Domain Research Tool
Save $120 off your order with this link!
Find Traffic Domain names with ease!
My Countdown Counting down to: California
178 days 14 hours 41 minutes
Ashaw is online now   Reply With Quote
Old 09-04-2007, 09:06 PM   #17 (permalink)
Platinum Lifetime Member
 
Domainmaster's Avatar
 
Name: Mike
Last Online: 02-21-2009 02:15 PM
iTrader: (1)
Join Date: Jun 2006
Posts: 42
DNF$: 288
Location: Midwest
Country:


Great thread even though it scares me a bit.

George K. brings up a good point I never thought too much about. I've used several different admin emails in the past but was in the process of consolidating them. Now I'm thinking that might not be such a good idea.

Which email addresses would be the best for admin. email purposes?
__________________
Cyberspace Developers
Domainmaster is offline   Reply With Quote
Old 09-04-2007, 09:43 PM   #18 (permalink)
Platinum Lifetime Member
No Avatar
 
Name: Dave Zan
Last Online: 11-12-2009 09:55 PM
iTrader: (1)
Join Date: Aug 2004
Posts: 1,663
DNF$: 0
Location: Manila


Quote:
Originally Posted by Domainmaster View Post
Which email addresses would be the best for admin. email purposes?
The one you have full control over and consistently protect.

Grudgingly, one thing I like about Netsol (cough cough) is they let you assign
2 sets of contact data: one for the WHOIS and a second for your account. I
confirmed with a few of their reps the WHOIS one doesn't necessarily provide
your actual login information (yet still complies with the WHOIS thingie) if you
put in a different set within.

I did this with my one remaining domain name with them. It shows one set of
contact data (including a throw-away email address), yet my account has a
different one inside.
__________________
Vidi, Vici, Veni!
Dave Zan is offline   Reply With Quote
Old 09-05-2007, 12:56 PM   #19 (permalink)
Kuwaiti UNIX Geek
 
Bashar's Avatar
 
Name: Bashar Al-Abdulhadi
Last Online: 11-12-2009 02:12 PM
iTrader: (6)
Join Date: Aug 2002
Posts: 638
DNF$: 3,780
Location: Kuwait
Country:

Send a message via ICQ to Bashar Send a message via AIM to Bashar Send a message via MSN to Bashar Send a message via Yahoo to Bashar Send a message via Skype™ to Bashar

http://blog.domaintools.com/2007/09/...tolen-domains/

UPDATE: Here are some more stolen domains:

* Newspaper.com
* FastFood.com
* Right.net
__________________
KuwaitNET Internet Services - www.KuwaitNET.net
Bashar Al-Abdulhadi - C.E.O.
Kuwait's First Hosting Services Provider since 1997, an ICANN accredited Registrar
Bashar is offline   Reply With Quote
Old 09-06-2007, 01:51 AM   #20 (permalink)
Philadelphia Lawyer
 
jberryhill's Avatar
 
Last Online: 09-18-2009 01:17 AM
iTrader: (1)
Join Date: Oct 2002
Posts: 2,987
DNF$: 6,350

Send a message via ICQ to jberryhill

Quote:
Originally Posted by Dave Zan View Post
Grudgingly, one thing I like about Netsol (cough cough) is they let you assign
2 sets of contact data: one for the WHOIS and a second for your account.

Dave, the account email can be readily determined by a minor security bug.

If you want to know the actual account email for a domain name at Netsol, as opposed to the admin contact email, you use the "lost userid or password" function at the Netsol login.

You then identify the domain name.

And, here's the boneheaded part, Netsol then asks you which method you want to use to retrieve or reset the password. Among the options it lists is "send an email to <the account control email address>"

And, before you rag on me about posting that, any hi-jacker knows this (the feature has useful purposes as well, particular where the domain name is owned by an organization, and nobody remembers whose email was being used). Accordingly, it's better that you know it too, in case you were relying on security through obscurity.
__________________
John Berryhill Ph.d., esq.
John-AT-johnberryhill.com
Please do not send private messages via dnforum.com, email me directly.
jberryhill is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
WALL STREET JOURNAL: Domains are a hot commodity again Harry Domain Name News 6 03-14-2007 03:54 AM
Domain Research Tool - The tool the PROS use ~ 3 left at this price ~ TOO LOW TO LIST jdk Advertising and Related Offers 13 07-16-2006 12:50 AM
Find available Traffic, overture, Google Page ranked domains and MUCH more! Ashaw Advertising and Related Offers 18 05-26-2006 05:03 PM
300 New .Info Domains: Annexation.info BroadbandConnection.info LOTS of Tourism Names daddypi Domains for Sale (Domain Sales) - Fixed Prices Above $100 16 11-30-2005 07:35 PM


All times are GMT -5. The time now is 12:23 PM.
Copyright @2001-2009 DNForum.com