DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars
HomeRegisterMembershipsGetting StartedDomain Tools Domain EbooksSEO Software Domain Resellers Advertise

Go Back   DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars > Domain News, Beginners Guides and Legal Stuff! > Domain Name Legal Issues
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 01-24-2009, 12:34 AM   #1 (permalink)
No Avatar
 
Last Online: Today 11:47 AM
iTrader: (6)
Join Date: Feb 2004
Posts: 1,253
DNF$: 8,555


Something illegal going on here!

I own a very valuable domain name regged at moniker for years. I've had it parked with hitfarm for a year. I've checked the DNS at Moniker and they are correct; however, when I checked my stats today for the name, they were WAY WAY off!


After having a look, the name is NOT resolving to the hitfarm lander, it's resolving to www3.searchmirror.com/xxxxxxxxxxx

WTF?!?!? I changed absolutely nothing! What's going on?!?! Somebody is stealing my traffic!! This has to be illegal!

Any ideas??
wmloz is offline   Reply With Quote
Sponsored Ads
Old 01-24-2009, 12:37 AM   #2 (permalink)
 
Onward's Avatar
 
Last Online: Today 08:22 PM
iTrader: (45)
Join Date: Jul 2006
Posts: 3,050
DNF$: 15,822
Location: Washington DC
Country:


What does hitfarm say?
__________________
.

Find out who is sending that anonymous offer...
Search their e-mail address across over 40 social & business networking sites, blogs and forums.
Onward is offline   Reply With Quote
Old 01-24-2009, 12:42 AM   #3 (permalink)
No Avatar
 
Last Online: Today 11:47 AM
iTrader: (6)
Join Date: Feb 2004
Posts: 1,253
DNF$: 8,555


I just discovered it. They are closed right now, but I've sent them an email and another to Moniker. Everything is kosher at Moniker and I can see the log in history. The whois record is right too.
wmloz is offline   Reply With Quote
Old 01-24-2009, 01:10 AM   #4 (permalink)
Making Everything Click
 
Focus's Avatar
 
Name: Chris
Last Online: Today 01:19 PM
iTrader: (112)
Join Date: May 2005
Posts: 9,415
DNF$: 15,390
Location: Dirty South
Country:




At a big ISP level maybe?
Focus is offline   Reply With Quote
Old 01-24-2009, 01:27 AM   #5 (permalink)
Fiscal Conservative
 
Raider's Avatar
 
Name: RG
Last Online: 10-31-2009 01:56 AM
iTrader: (13)
Join Date: Aug 2006
Posts: 5,874
DNF$: 20,092
Location: California
Country:


You might want to try changing the DNS and see if it resolves.
Raider is offline   Reply With Quote
Old 01-24-2009, 08:15 AM   #6 (permalink)
Platinum Lifetime Member
 
DNBA's Avatar
 
Name: shahram
Last Online: Today 09:08 AM
iTrader: (8)
Join Date: May 2008
Posts: 502
DNF$: 0
Location: los angeles
Country:


well it dosent look like a hitfarm site.

1. make sure its still in your account
2. if it is with moniker make sure the dns is correct. there maybe a security issue with them cause it looks like a lot are popping off.
3. contact whois www3.searchmirror.com. looks like its pointing to a hostway.com server on ip 64.26.28.139
4. jusy because its right at moniker doesnt mean there could be an issue. keeping the same whois contact may not mean shit if its pointing to the right place
5. have you been working with any untrusted developers? someone that may have access to your accounts?

i wish you luck in finding out the situation. i manage quite a few huge portfolios and hot keys are not ones to just pass off on your account. so it seems like its root lever with the registrar.
__________________
Now Selling: KPH.com, Tag.Us, Podcasts.net, LaCantina.com, IronKettle.com, pixd.com, OilDriller.com, ExhibitPrints.com
Sign up for more info on becoming a licensed Domain Name Broker DNBA.org
DNBA is offline   Reply With Quote
Old 01-24-2009, 09:56 AM   #7 (permalink)
Exclusive Lifetime Member
 
ecomindia's Avatar
 
Name: Dipendra Srivastava
Last Online: Today 11:10 PM
iTrader: (18)
Join Date: Nov 2003
Posts: 809
DNF$: 1,492
Location: Ghaziabad,India
Country:

Send a message via Yahoo to ecomindia

to ensure your domains is rightly configured.

use the URL http://www.dnsqueries.com/en/domain_check.php

and you may find the bug!

i had problems like this many a times, and this site proved a gem for me.
__________________
Buying your expiring .net.in, .co.in, .in cctld. OFFER NOW . Bought 63+ domains already!
ecomindia is online now   Reply With Quote
Old 01-24-2009, 12:10 PM   #8 (permalink)
DNF Member
No Avatar
 
Last Online: 11-19-2009 02:54 PM
iTrader: (40)
Join Date: Dec 2005
Posts: 374
DNF$: 5,025


I think that there are at least to possible things going on here.

First, if the name is resolvable from elsewhere (and I'm fairly sure this is not the problem given your drop in hits) and not from your own client, then your local DNS resolver has been compromised.

If the name resolves badly from everywhere, then your DNS authoritative host server has been compromised.

The good news is that those problems are easily fixable and by now should have been fixed by you (if you support your own authoritative host and resolving DNS servers) or by your ISP if they paid any attention at all to the huge story last summer about this topic.

FWIW, the authoritative DNS and the resolver DNS servers are using the same type of software (DNS), but they are doing different functions. The authoritative server is there to serve "answers" to requests about your domain (from its host file) and the other serves to ask "questions" about domains from other DNS authoritative servers. Any good administrator will setup their DNS servers to allow them to only resolve the names they serve (as authoritative) and only resolve names for clients in its known network. Sadly there are a huge number that act as what is called an open resolver, meaning that as an authoritative server, it was also answer for other domain names (though it should not do so authoritiatively) and as a resolver will serve anyone out there. Both are probably unwise and certainly not recommended configurations these days without a darn good reason to do so.

If this is the case of an ISP who did not "get it", then they are reaping the harvest of paying no attention to a critical infrastructure problem. The bug relates to randomness of UDP ports for a DNS server. Patched versions of every major ISP have been out since mid-to later last year (in fact it was the biggest coordinated infrastructure applications fix in the history of the Internet).

Don't feel bad, your ISP is not alone. The stats on current DNS servers which actually address the bug are dismal. To me, if you want to be in the Internet business, you should know that something as basic as this kind of attack must be addressed if there is an answer.

While something else more nafarious could be going on, this would be the most logical guess and probably the starting point I would check first.

-Commerce
Commerce is offline   Reply With Quote
Old 01-24-2009, 11:50 PM   #9 (permalink)
No Avatar
 
Last Online: Today 11:47 AM
iTrader: (6)
Join Date: Feb 2004
Posts: 1,253
DNF$: 8,555


changed dns to parked.com and it took. Not sure what the heck the problem was. I'll try putting back to hitfarm tomorrow and see what happens.
wmloz is offline   Reply With Quote
Old 01-25-2009, 06:00 PM   #10 (permalink)
Success Is My Only Option
 
Carter's Avatar
 
Last Online: 11-21-2009 06:25 AM
iTrader: (43)
Join Date: Jul 2008
Posts: 4,231
DNF$: 27,103
Location: Italy
Country:


Quote:
Originally Posted by wmloz View Post
changed dns to parked.com and it took. Not sure what the heck the problem was. I'll try putting back to hitfarm tomorrow and see what happens.
Let us know.
Carter is offline   Reply With Quote
Old 01-26-2009, 02:16 AM   #11 (permalink)
Platinum Lifetime Member
No Avatar
 
Last Online: 11-22-2009 01:30 PM
iTrader: (143)
Join Date: Jan 2004
Posts: 4,220
DNF$: 3,405
Country:


godaddy is good at changing dns when your name is going to expire even if they are
not the owners of the domain name. It is done automaticly. no concern about your use.
__________________
http://Domainturn.com
DomainTurn.com is offline   Reply With Quote
Old 01-27-2009, 08:12 PM   #12 (permalink)
Platinum Lifetime Member
No Avatar
 
Last Online: Today 09:54 PM
iTrader: (0)
Join Date: Jun 2002
Posts: 440
DNF$: 10


Yahoo kicked the name off, that is what happens at hitfarm in a situation like that.

If it is not truly a "sensitive" name (what Yahoo uses to describe such cases) then ask your rep at hitfarm to appeal it with yahoo.

That other lander is what it will default to in cases like this.
Cartoonz is offline   Reply With Quote
Old 01-27-2009, 08:45 PM   #13 (permalink)
No Avatar
 
Last Online: Today 11:47 AM
iTrader: (6)
Join Date: Feb 2004
Posts: 1,253
DNF$: 8,555


This is exactly what happened according to hitfarm.

Guys, this is absolutely ridiculous. The name is as generic as it freaking gets!! www(.)assurance(.)com! Now, a few weeks ago I got a C&D letter from Assurant Corp. I replied back with the assistance of Hitfarm and I thought it went away. They were moaning that links to their agents or their websites with the word "Assurant" were showing up on the links. Obviously, they or their agents are manipulating the keywords they pay for to get those links on the lander. Do you think maybe they escalated their complaint with Yahoo?

Quote:
Originally Posted by Cartoonz View Post
Yahoo kicked the name off, that is what happens at hitfarm in a situation like that.

If it is not truly a "sensitive" name (what Yahoo uses to describe such cases) then ask your rep at hitfarm to appeal it with yahoo.

That other lander is what it will default to in cases like this.
wmloz is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 11:55 PM.
Copyright @2001-2009 DNForum.com