Home / Blogs

Phishers Now Targeting Domain Registrars

Edward Falk

This is an issue of some concern and should be watched carefully: phishers are now trying to get passwords of domain registrants (domain owners). Currently, correspondents inform me that GoDaddy is the target, but there's no reason to think the phishers won't expand to other registrars.

Normally, phishers go after bank accounts or other financial information, or sometimes the online accounts of users so that they may send spam.

It's not known precisely why phishers are after domain registration information, but the possibilities are chilling. The most obvious danger is that the phishers might be trying to simply steal domains — recall the sex.com and register.com fiascoes.

One worst-case scenario which has been suggested is this: If a phisher were to successfully hijack the domain registration of a bank or credit union, they could surreptitiously redirect the domain name to their own servers and conduct a man-in-the-middle attack without the bank even realizing it's happening.

Dear GoDaddy Customer,

GoDaddy Customer Support Team requests you to complete GoDaddy Customer Online Form.

This procedure is obligatory for all customers of GoDaddy.

Please click hyperlink below to access GoDaddy Customer Online Form.

http://myaccount.session-47175729.godaddy.com/AccountConfirmation/account.aspx

Please do not respond to this email.

This mail generated by an automated service.

Copyright © 1999 - 2007 GoDaddy.com, Inc. All rights reserved.

Of course, the link provided actually goes to the phishing site, not to GoDaddy.

By Edward Falk, Computer professional. Visit the blog maintained by Edward Falk here.

Related topics: DNS, Domain Names, Email, Security, Spam

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Re: Phishers Now Targeting Domain Registrars The Famous Brett Watson  –  Aug 07, 2007 7:15 PM PST

Could it be that the target of the phishing here is not so much the domain name as access to the hosting facilities which GoDaddy also offers? The ability to construct websites under subdomains of existing domains would be quite useful from the perspective of the generic cybercriminal. After all, they aren't in the business of building brand recognition — they are in the business of churning through identities quite rapidly.

Re: Phishers Now Targeting Domain Registrars Suresh Ramasubramanian  –  Aug 07, 2007 10:38 PM PST

There is a lot of "take" in a registry + hosting facility that a phisher will find attractive, besides the scenarios you and Ed mentioned.

1. Access to the user's ID / name / address / CC etc stored in his whois profile.

2. Ability to sign up scam domains using the stolen accounts. If they signup several dozen domains using stolen cards, and use a single account to do it, the registrar can easily take them down.

3. How many people (e&oe domainers) check their accounts with a registrar carefully, every day?  As compared to checking, say, their gmail or ebay accounts?

srs

Re: Phishers Now Targeting Domain Registrars Robert Cannon  –  Aug 08, 2007 10:41 AM PST

There is a lot of energy behind DNSSEC for this purpose.  DNSSEC digitally signs and locks DNS records in order to secure the database.  There are many reasons for doing this, one of which is to thwart the man-in-the-middle attack.  Without the proper keys, altered DNS records will not verify and will not therefore resolve.  Alternatively, DNSSEC creates a single point of failure in an otherwise disaggregated system - the crypto key.  If the key for signing the DNS root gets compromised, first the database is now exposed and second the root must now engaged in a key roll-over (replace the old compromised key with a new key) which apparently quite hard.  Many are experimenting with DNSSEC but it is not without its doubters.  http://www.cybertelecom.org/dns/security.htm

Re: Phishers Now Targeting Domain Registrars The Famous Brett Watson  –  Aug 08, 2007 4:54 PM PST

DNSSEC protects against unauthorised changes to DNS records. If you've been phished, the attacker has your authentication credentials, and DNSSEC won't help you.

Re: Phishers Now Targeting Domain Registrars Dave Zan  –  Aug 09, 2007 12:21 AM PST

So Go Daddy has to worry about potential customers complaining of their searched domain names being swiped, their clients' domain names being hijacked, and now this. That's one price to pay for being arguably the most popular. :P

I've since read of people who have forwarded that same email to Go Daddy. I've yet to see any response from them as of this post, although I'm sure they're on top of it.

Re: Phishers Now Targeting Domain Registrars Suresh Ramasubramanian  –  Aug 09, 2007 3:12 AM PST

I’ve since read of people who have forwarded that same email to Go Daddy. I’ve yet to see any response from them as of this post, although I’m sure they’re on top of it.

Godaddy is part of the anti phishing working group (www.apwg.org) - so I am reasonably sure they have access to some good sound anti phishing best practices.

As do most of the other phish victims out there.

That doesnt stop phishers from targeting them.
And that doesnt stop ignoramuses from falling for phishes.

That's about all they can do to "be on top of it".. except possibly for something like "we wont ever send you email, any communication with us will be through our website" like several banks do.

Re: Phishers Now Targeting Domain Registrars Jack Durban  –  Nov 09, 2007 6:47 PM PST

Godaddy just gave away one of our most valuable domains. We can't figure out how they did it but godaddy is complicit in their failure to provide a simple verification email to us to confirm or deny the transfer. It was quite simple for the thief but not so easy to get it back. It will cost us thousands to get it back. Godaddy basically told us to go pound sand. To get this back we have to file a cease and desist letter through an attorney. Then after a predetermined period of time if the crook fails to comply then we have to file a formal action with ICANN or better put "ICANNT" and give them $1,500.00 to impanel a board of arbitrators!

Total bill with all legal fees could reach several thousand dollars.

I got hosed by godaddy and Bob Parsons didn't even send me flowers.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

StarHub to Acquire '.starhub' New Top-Level Domain

ARI Registry Services Signs 21 Contracts in the First Week of New TLD Applications

MarkMonitor to Exhibit at Internet Tech Policy Exhibition and Reception to be Held on Capitol Hill

Sedari Signs With Dot Moscow Bidders

.ORG, The Public Interest Registry Welcomes Nancy Gofus As Chief Operating Officer

Minds+Machines Works with .bayern

The New Domain For Japan, JP.NET, Launches With Exclusive Invitation to Trademark Owners

Verisign to Award New Infrastructure Research Grants

Being a .PRO When Choosing a Registry Services Partner

UK Cabinet Office Looks to BlueCat Networks' Expertise and Best Practices for Securing PSN

Afilias Acquires Registry Services Corporation, .PRO

Thoughts on Applying for a Generic Top-Level Domain

Sedari Launches "Guess the Numbers Game" for New TLD Program

dot Brand Makes Its Debut: Afilias Advises Companies to Act Now for Successful TLD Applications

BlueCat Networks Helps Organizations Transition to IPv6 with HP

BlueCat Networks to Host Webinar on DNS, DHCP and IPAM Featuring Independent Research Firm

Facets of gTLD Registry Technical Operations - Registry Services

Technology and Finance Industries to Dominate New gTLD Applications

.CO Internet Selects Sedo to Broker Previously Unreleased .CO Domain Names

Sedari and NCC Launch Programme to Assist New Registry Operators

Hot Topics

Verisign

Security

Sponsored by
Verisign
Afilias

DNSSEC

Sponsored by
Afilias
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
dotMobi

Mobile

Sponsored by
dotMobi