NameSilo

DynaDot.com Domain hijack Exploit

SpaceshipSpaceship
Watch

Iravan

TSAS HostEstablished Member
Impact
109
Just Saw this on Digg

http://www.berlettefx.com/2007/01/5/exploiting-dynadot/

This person found a way to acess any domain that is registered at dynadot and change the account to his own

Very bad news, watch your domains folks

- Iravan

** This should really go under alerts but I felt that it should be noticed by as many people as possible just in case anyones domains are at risk. Please feel free to move as necessary
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
Iravan said:
Just Saw this on Digg

http://www.berlettefx.com/2007/01/5/exploiting-dynadot/

This person found a way to acess any domain that is registered at dynadot and change the account to his own

Very bad news, watch your domains folks

- Iravan

** This should really go under alerts but I felt that it should be noticed by as many people as possible just in case anyones domains are at risk. Please feel free to move as necessary
Thats berlette :hehe:
 
0
•••
0
•••
**
 
0
•••
and somebody said that this never existed....
So this was real or not?
 
0
•••
I hope a company wouldn't let a security flaw as OBVIOUS as this get by them. I tried the same "technique" with afternic:
http://www.afternic.com/nameE.php?id=xxxxxxxx

Type in an 8 digit number, and if there is a name with that code, then it will say access violation.
 
0
•••
Yes, DynaDot fixed this. Nobody needs to worry about their domains, and I wouldn't take them anyways. After several attempts at reporting it, they finally decided it'd be good to fix. Joy.
 
0
•••
if the hacker changed a domain to his own name, it should be easy to catch him, right?
 
0
•••
Nice find. I never have/will use dynadot. So lets hope it doesn't happen to godaddy.
 
0
•••
Really? Hope it was a bad joke anyway. :-/
 
0
•••
-NB- said:
Yes, DynaDot fixed this. Nobody needs to worry about their domains, and I wouldn't take them anyways. After several attempts at reporting it, they finally decided it'd be good to fix. Joy.
Nice find, Nick.

Doesn't surprise me in the slightest. All my dealings with Dynadot have been troublesome to say the least.

Needless to say, there's one registrar I won't be recommending or using ever again, although that was already decided long before this issue and their subsequent denial on their forum (which is what I've come to expect from them...)
 
0
•••
Having a problem is one thing, but taking so long to fix it is another. That's too bad they were so slack in responding to the situation.
 
0
•••
Dynadot replied me that they don't have any "domain stolen" complaints.
 
0
•••
glad t osee its been fixed

- Iravan
 
0
•••
-NB- said:
Yes, DynaDot fixed this. Nobody needs to worry about their domains, and I wouldn't take them anyways. After several attempts at reporting it, they finally decided it'd be good to fix. Joy.
Did the exploit actually work for you gaining access to a domain name you do not own? Or, could you only access the other domain names within your account with changing the domainid in the URL?
 
0
•••
Dynadot — .com TransferDynadot — .com Transfer
Appraise.net

We're social

Escrow.com
Spaceship
Rexus Domain
CryptoExchange.com
Domain Recover
CatchDoms
DomainEasy — Payment Flexibility
DomDB
NameFit
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back