IT.COM

Ars Technica: GoDaddy weakness let bomb threat scammers hijack thousands of big-name domains

Spaceship Spaceship
Watch
Impact
2,017
Remember the December 13 email blast that threatened to blow up buildings and schools unless recipients paid a $20,000 ransom? It triggered mass evacuations, closures, and lockdowns in the US, Canada, and elsewhere around the world.

An investigation shows the spam run worked by abusing a weakness at GoDaddy that allowed the scammers to hijack at least 78 domains belonging to Expedia, Mozilla, Yelp, and other legitimate people or organizations. The same exploit allowed the scammers to hijack thousands of other domains belonging to a long list of other well-known organizations for use in other malicious email campaigns. Some of those other campaigns likely included ones that threatened to publish embarrassing sex videos unless targets paid ransoms.

Read the story on Ars Technica
 
2
•••
The views expressed on this page by users and staff are their own, not those of NamePros.

The take-away from all of this is that for two years GoDaddy’s DNS service has supplied some of the most nefarious scammers on the Internet with an almost unlimited number of high-value domains. While the abuse relied on domain holders not properly locking down their DNS records, Bryant made a compelling argument that it was the DNS providers who are ultimately responsible for the abuse of their services.
 
2
•••
TL;DR

Spammers / criminals exploited a flaw that lets anyone create DNS records for a domain using Godaddy DNS but doesn't resolve. Maybe the domain was transferred or DNS subscription expired and DNS wasn't updated.

About 500K domains may be vulnerable. No update if the flaw was fixed or not.
 
Last edited:
3
•••
So glad I moved everything I had away from GoDaddy. Can't stand them anymore for various reasons
 
2
•••
So glad I moved everything I had away from GoDaddy. Can't stand them anymore for various reasons

It amazes me how strongly I feel about GoDaddy. The ways in which they levy fees and blatantly engage in false advertising creates the image of a very darkly intentioned company.

And it's not just their size, although of course that's what makes them immune to small complaints, or even one of this size ^^^. Plan to move whatever I have with them away at the next opportunity.
 
1
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back