Advertisement
Promo

Industry watch Toolkit

A Year Ago: Hijacked Web addresses show weak link in Net

Rupert Goodwins ZDNet.co.uk

Published: 09 Jun 2001 06:28 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Web.net, an email and information site for 3,500 charities and volunteer groups, and holiday website Bali.com had their domain names re-registered to people in Hong Kong and Madrid respectively.

The registrar handling those names, Network Solutions, eventually restored the sites to their rightful owners, but during the outage the owners estimated 400,000 emails went astray from web.net and $100,000 in bookings were lost from bali.com.

"It happened through a simple spoofing," said Brian O'Shaughnessy, program director, policy and registry at Network Solutions. "In these cases, individuals spoofed emails to us, automated systems recognised the fake email header information and made someone else the owner. These things are incredibly unfortunate but very infrequent."

When a site is registered with Network Solutions, the owner can elect to set up a password or a PGP-based system to authenticate messages requesting changes. However, the default is just to accept requests if they appear to be emailed from the original registration address. "We suggest stronger security measures", said O'Shaughnessy, "but we have over ten million people using us, and 30,000 registrations a day. 99.9 percent of the time it works incredibly well. I don't want to minimise the problem, but it doesn't mean the system failed. Obviously, all the major commercial clients use stronger protection than the 'mail from' field in an email header."

Chris Lewis, ZDNet's technical director, recommends that anyone registering a domain name should ensure that at least a password is required to reassign the name, but PGP is preferable. "You'd have to be an idiot not to use the strongest security available to you."

Take me to Hackers

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
46 out of 74 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:












Discussions

J.A. Watson J.A. Watson

Bumbling Imbeciles? Yes.

Thursday 17 December 2009, 6:57 AM

3 comments
CA CA

Well..

Thursday 17 December 2009, 12:51 AM

3 comments
CA CA

The sooner...

Thursday 17 December 2009, 12:42 AM

1 comment
CA CA

aye..

Thursday 17 December 2009, 12:30 AM

4 comments
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters