news GoDaddy discloses recent security breach !

SpaceshipSpaceship
Watch

love4ever

Top Member
Impact
7,364


1637594708891.png


1637594753330.png




.
 
14
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
2
•••
1
•••
1
•••
Well if that's true we are all fcked.. proper fcked.
Sorry for cursing, was just quoting my fav movie Snatch
 
2
•••
Last edited:
1
•••
Last edited:
0
•••
Any GoDaddy Managed WordPress customers here who have received any form of email communication about this incident? If so, what was in it?
 
0
•••
1
•••
0
•••
Any ideas what we should do? Should we change passwords?
 
0
•••
1
•••
Just waiting for a similar explosion of rage from the same people who were furiously bashing Epik for exactly the same thing about a month ago.
 
3
•••
It doesn't hurt to change your password and turn on 2 factor authentication on (if you haven't turned it on).
 
1
•••
https://www.wordfence.com/blog/2021/11/godaddy-breach-plaintext-passwords/

It appears that GoDaddy was storing sFTP credentials either as plaintext, or in a format that could be reversed into plaintext. They did this rather than using a salted hash, or a public key, both of which are considered industry best practices for sFTP. This allowed an attacker direct access to password credentials without the need to crack them.

ugh!
 
3
•••
Last edited:
2
•••
@Joe Styler, @Dan Nicks, do you know if this breach affects only hosting customers or also domain registrants? Also, how was it possible that login credentials were stored either in plaintext or in a format that could be easily reversed into plaintext? I used to be a customer of Media Temple before GD acquired them and they seemed pretty technically and security savvy.
 
Last edited:
3
•••
Just waiting for a similar explosion of rage from the same people who were furiously bashing Epik for exactly the same thing about a month ago.
Exactly. Is Godaddy doomed? Everyone who uses them (who is that btw?) gonna move their domains and hosting now? Is it going to be some political smearing of the CEO?

Companies get breached, that's the lesson here. You can hope that breaches are handled professionally and that they do their best to secure your account.
 
4
•••
I was sent an email as why i know about it but i just deleted it as i have as many hacks as hot dinners. I spend most of my time now fixing things and trying to get rid of hackers i deleted most of my sites as overwhelmed with work. Getting to a point a one man show isn't worth the effort. My emails etc are in the thousands for data leaks most people wouldn't notice or look.
 
Last edited:
1
•••
Last edited:
1
•••

We're social

Spaceship
Domain Recover
CatchDoms
DomainEasy — Zero Commission
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back