Enjoy unlimited access to all forum features for FREE! Optional upgrade available for extra perks.
Daily Diamond

How to steal a domain name....

Status
Not open for further replies.

GeorgeK

Leap.com
Legacy Exclusive Member
Joined
May 17, 2002
Messages
2,248
Reaction score
64
Feedback: 3 / 0 / 0
Today's lesson is on how to steal a domain name.....

Step 1. Find a high value domain name with an invalid administrative email address, preferably one that is not actively being used so that it won't be noticed.

Example: nigger.com, nigger.net, nigger.org (owned by NAACP)

Step 2. Note in the WHOIS that the admin email is [email protected], which until yesterday was on a domain (BAWAVE.com) that had long expired and been deleted.

Step 3. Register the aforesaid domain name in Step #2. Oh my, some folks have caught on, as you can see the WHOIS for BAWAVE.com, freshly registered yesterday:

Registrant:
Nigger Inc [email protected] +62.3189598
Hendra Gunawan
JL. Bengawan 56
Surabaya,Jawa Timur,Indonesia 60000

Domain Name:bawave.com
Record last updated at 2002-11-04 20:31:57
Record created on 2002/11/4

Step 3a: Ideally, make the registrant in step 3 very obscure, like in a far away land. ;)

Step 4: Activate the domain in Step #3 so that email is working, namely the email address in Step 2.

Step 5: Initiate a transfer request, and accept using the email in step 4.

Step 6: Enjoy

Given the NAACP's inability to fix the problem (I emailed them about this months ago), I acquired a SnapBack, in case someone tried to take the name. I imagine now that the process is unveiled, someone at Verisign (Chuck?) or at ICANN will do something.....(maybe someone in Washington, DC can give the NAACP a call, or something....
 
Domain Summit 2024

uncle

Level 5
Legacy Gold Member
Joined
Mar 22, 2002
Messages
271
Reaction score
1
Feedback: 0 / 0 / 0
it's a well known method and it's pretty annoying that the owners of the stolen domains often don't care..

maybe it should be legalized..
 

RON2

@domainbuyer
Legacy Exclusive Member
Joined
Apr 26, 2002
Messages
1,550
Reaction score
9
Feedback: 24 / 0 / 0
George, I guess I'm wondering why you'd pay $69 for a snap but not $8 to register BAWave.com yourself?
 

GeorgeK

Leap.com
Legacy Exclusive Member
Joined
May 17, 2002
Messages
2,248
Reaction score
64
Feedback: 3 / 0 / 0
Honour. :)
 

GeorgeK

Leap.com
Legacy Exclusive Member
Joined
May 17, 2002
Messages
2,248
Reaction score
64
Feedback: 3 / 0 / 0
(I had already paid for some SnapBacks previously, so the actual cost was zero; if NAACP reads their email, they could have avoided making it such a tempting target, as I warned them months ago, to no avail)
 

RON2

@domainbuyer
Legacy Exclusive Member
Joined
Apr 26, 2002
Messages
1,550
Reaction score
9
Feedback: 24 / 0 / 0
You might want to notify Verisign, although they could probably care less too. :rolleyes:
 

WildCard

Level 5
Legacy Platinum Member
Joined
Oct 27, 2002
Messages
340
Reaction score
0
Feedback: 0 / 0 / 0
Yes, verisign will need you to fax all that info to them - unless you want priority processing, which will cost $30. ;-)

Yes, I hate the way they move. Interesting post though. I didn't realize this type of action was available.

-WC-
 

GeorgeK

Leap.com
Legacy Exclusive Member
Joined
May 17, 2002
Messages
2,248
Reaction score
64
Feedback: 3 / 0 / 0
I posted it on the DNSO GA mailing list (cc'd to Verisign and ICANN), and also to ICANNWatch.com, so somebody should get the message.

NAACP will get the name back, if it's stolen, that's for sure. Those thieves give the rest of us a bad name, though. Would be nice to nail one of them.
 

jberryhill

Philadelphia Lawyer
Legacy Exclusive Member
Joined
Oct 8, 2002
Messages
2,571
Reaction score
4
Feedback: 1 / 0 / 0
You know, you can do this with IP address blocks as well.

Check out the IP address block in which cubaweb.cu, along with a bunch of Cuban government websites, is located.

Then, check out the whois for the domain name registration corresponding to the contact email address for that IP address block.

Cigars, anyone?
 

GeorgeK

Leap.com
Legacy Exclusive Member
Joined
May 17, 2002
Messages
2,248
Reaction score
64
Feedback: 3 / 0 / 0
Update -- admin emails now fixed

Kudos to Richard Lau of MyDomain.com, for helping to get this fixed. The NAACP has updated the admin email of the domains at risk, so that they can't be hijacked the 'easy' way.

Hopefully this is a lesson ICANN and others can learn from, in formulating policy regarding accurate WHOIS (scrubbed to fix data errors, to protect innocent registrants) and transparent WHOIS (to make it harder to commit cybercrimes, the average person can identify a crime that might be about to happen).
 

Fearless

Level 9
Legacy Exclusive Member
Joined
Jul 10, 2002
Messages
4,063
Reaction score
22
Feedback: 28 / 0 / 0
If I had detected this, I would have spent $6.95 and registered the deleted name. Then after I hijacked the names I would contact the NAACP and say, see I told you so. Maybe they would pay a reward. If not, I'm only out $6.95.
 
M

mole

Guest
Hahahahahaaaaa... that's not stealing, that's getting a name from someone who deserves to lose it.
 

Nic

Level 6
Legacy Platinum Member
Joined
Apr 23, 2002
Messages
628
Reaction score
0
Feedback: 0 / 0 / 0
Originally posted by GeorgeK
Today's lesson is on how to steal a domain name.....

Step 1. Find a high value domain name with an invalid administrative email address, preferably one that is not actively being used so that it won't be noticed.

Example: nigger.com, nigger.net, nigger.org (owned by NAACP)


What are you doing checking those domains (nigger.com, nigger.net, nigger.org ) anyway:? :)
 
S

Silverwire

Guest
Today's lesson is on how to steal a domain name.....

I prefer the old fashioned way: Force the guy to change the registration at gunpoint, then shoot him.
 
S

Silverwire

Guest
Never mind, what was I thinking?


(i'm giving away my best domain name strategy secrets)
 

thinkaholic

Level 4
Legacy Platinum Member
Joined
Sep 20, 2002
Messages
217
Reaction score
0
Feedback: 0 / 0 / 0
How to steal a domain name??

Get a job at NetSol...
 

ad-lib

Level 6
Legacy Gold Member
Joined
Mar 23, 2002
Messages
658
Reaction score
0
Feedback: 0 / 0 / 0
Just transferred Yahoo.com to my account. Thanks for the advice George. :)
 

RMF

Level 8
Legacy Platinum Member
Joined
Sep 9, 2002
Messages
1,437
Reaction score
0
Feedback: 0 / 0 / 0
I actually came across something like this the other day. I found a domain that had expired, and was used in the admin contact for a VERY large company. I sent them an email explaining what I found, and how they can fix it. I told them that they have a huge security problem that they should be aware of.

Sure, I could have registered that expired domain and stole their company domain from networksolutions, but I live in canada, doh. No, really though, I wouldn't want something like that to happen to me, and I would hope someone would contact me if I was in that situation ( However I doubt I would ever be in that situation :D ).

RMF
 

morel

Level 5
Legacy Platinum Member
Joined
May 21, 2002
Messages
428
Reaction score
0
Feedback: 0 / 0 / 0
Originally posted by Nic


What are you doing checking those domains (nigger.com, nigger.net, nigger.org ) anyway:? :)

Didn't we all look up naughty words in the dictionary as a kid :) ?
I think it's human nature.
 

ad-lib

Level 6
Legacy Gold Member
Joined
Mar 23, 2002
Messages
658
Reaction score
0
Feedback: 0 / 0 / 0
If I was to change a hijacked domains ownership, to my actual (non-fraudulent) personal info. And sold it. What's the worse thing that could happen?
 
Status
Not open for further replies.

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Sedo - it.com Premiums

IT.com

Premium Members

AucDom
UKBackorder
Be a Squirrel
MariaBuy

New Threads

Our Mods' Businesses

UrlPick.com

*the exceptional businesses of our esteemed moderators

Top Bottom