ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

A Year Ago: Hijacked Web addresses show weak link in Net

Rupert Goodwins ZDNet.co.uk

Published: 09 Jun 2001 06:28 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Web.net, an email and information site for 3,500 charities and volunteer groups, and holiday website Bali.com had their domain names re-registered to people in Hong Kong and Madrid respectively.

The registrar handling those names, Network Solutions, eventually restored the sites to their rightful owners, but during the outage the owners estimated 400,000 emails went astray from web.net and $100,000 in bookings were lost from bali.com.

"It happened through a simple spoofing," said Brian O'Shaughnessy, program director, policy and registry at Network Solutions. "In these cases, individuals spoofed emails to us, automated systems recognised the fake email header information and made someone else the owner. These things are incredibly unfortunate but very infrequent."

When a site is registered with Network Solutions, the owner can elect to set up a password or a PGP-based system to authenticate messages requesting changes. However, the default is just to accept requests if they appear to be emailed from the original registration address. "We suggest stronger security measures", said O'Shaughnessy, "but we have over ten million people using us, and 30,000 registrations a day. 99.9 percent of the time it works incredibly well. I don't want to minimise the problem, but it doesn't mean the system failed. Obviously, all the major commercial clients use stronger protection than the 'mail from' field in an email header."

Chris Lewis, ZDNet's technical director, recommends that anyone registering a domain name should ensure that at least a password is required to reassign the name, but PGP is preferable. "You'd have to be an idiot not to use the strongest security available to you."

Take me to Hackers

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
46 out of 74 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:












Related Jobs

Emebdded Engineer - Linux Kernel Specialist - England/Germany l

You will be working for one of the biggest and most respected names in software and is an opportunity to further enhance your CV with this ...

SAP HR Practice Lead

As an SAP HR Practice Lead proven experience of running at least two major transformation programmes in the Human Capital domain is required - ...

Account Director

Account Director OTE 150,000+ highly achievable and uncapped Basic 75,000 dependant on experience Reading Distribution Technology is an exciting, ...

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal