Skip to main content

Australian Firm Takes Blame for U.S. Domain Name Hijack

Domain registrar admits approving unauthorized domain transfer.

Paul Roberts, IDG News Service
Tuesday, January 18, 2005

An Australian company that manages Internet domain name registrations acknowledged that it was partially responsible for a Web domain hijacking that left Public Access Networks, a New York Internet hosting company, without an Internet address over the weekend.

An error by Melbourne IT allowed fraudsters using stolen credit cards to take control of Panix.com, Public Access Networks' Internet domain, early Saturday, according to Ed Ravin, a Panix system administrator. The hijacking deprived some Panix customers of e-mail access for two days, and shone a light on what some contend are holes in the system for managing Internet domain transfers, according to Ravin and others.

Panix regained control of its Internet domain Monday, after Melbourne IT reversed the registration change that transferred ownership of Panix.com to an unknown party Saturday night. However, some customers were still experiencing problems Tuesday as the transfer changes worked their way through the worldwide network of Domain Name System servers that manage requests for Internet addresses, Ravin said.

The hijackers somehow exploited a loophole in the process used to verify requests for domain transfers with the party that owns a Web domain, according to an e-mail message sent to Panix's founder and President Alexis Rosen from Bruce Tonkin, chief technology officer at Melbourne IT. About 5,000 customers were affected and some of them may have lost 100 or more e-mail messages over the weekend, Rosen said in an interview.

Permission Not Granted

According to a recently updated policy from the Internet Corporation for Assigned Names and Numbers, requests to transfer domains between two domain registrars require the registrar who will be taking over control of an Internet domain to receive approval for the transfer from an administrator at the "losing" registrar--the organization that will be ceding control of a domain. ICANN also requires an e-mail to be sent to both registrars involved in the transfer and allows five days for the losing registrar to cancel the transfer.

However, an error at Melbourne IT allowed an individual or individuals to use an account at Melbourne IT reseller Fibranet Services, a U.K.-based Internet service provider, to gain control of the Panix.com domain without the permission of Panix staff or Panix.com's domain registrar, Dotster of Vancouver, Washington, Tonkin wrote.

The administrative contact for the Panix domain at Dotster, the company's registrar, was not contacted before the transfer went through, as required by ICANN. Panix also was left in the dark about the transfer and only realized what was going on when it lost control of its domain Saturday, Ravin said.

Furthermore, an investigation by Fibranet revealed that the account to which ownership of the Panix.com domain was transferred was fraudulent and set up with stolen credit cards, Tonkin said.

The loophole that led to the unauthorized transfer has been closed, and Australian authorities are investigating the fraudulent account. Some security features do exist to prevent hijacking, including a domain-registration locking feature that automatically denies transfer requests. However, such a feature was not used for the Panix domain, he wrote.

For Panix customers like Andrew Ross of Brooklyn, New York, the mistake at Melbourne IT meant a weekend without e-mail, as Panix staff struggled to get through to their counterparts at Melbourne IT to reverse the changes.

While the domain hijacking wasn't a big inconvenience for Ross, who only uses Panix for e-mail, the loss of almost two days of e-mail messages does raise concerns about identity theft, if the hijackers mined the misdirected e-mail traffic for personal information, he said.

System Broken?

There is no evidence that misdirected e-mail and Web traffic were being harvested for information. The hijacking is probably an instance of Internet "vandalism" that was intended to make a point, rather than siphon off sensitive information, Ravin said.

However, the success of the ploy points out a serious vulnerability in the Internet's domain management system, said Rosen, Panix's president.

The system is obviously broken," said Rosen, who expects to lose customers and "a bundle of money" as a result of the hijacking.

Rosen said he didn't know the motivation for the hijacking, but speculated that it may have been retaliation for his company's cooperation in identifying spammers, or an attempt to call attention to problems with the domain transfer system, as ICANN is in the midst of a comment period on domain transfer policies.

ICANN is looking into the domain transfer system to see if there are ways to improve the security of domain transfers or provide more protection against erroneous transfers, wrote Steve Crocker, chairman of the group's Security and Stability Advisory Committee.

ICANN will be studying the interactions across organizations regarding domain transfers and considering ways to improve the system. But those recommendations and changes "may take a little while," he said.

(Grant Gross in Washington, D.C., contributed to this report.)

Popular posts from this blog

Contoh Checklist saat beli mobil bekas

Diambil dari Majalah AutoBild Edisi 54 100 Checklist Mobil Bekas Berkualitas Kriteria Penilaian : (A) Problem minor. Biasanya karena habis dipakai dan normal terjadi di mobil yang sudah berumur. Tapi hal ini bisa dijadikan bahan negosiasi harga. Dan jika mobilnya masih relatif baru, problem ini juga bisa berarti biaya mahal. (B) Cacat yang bisa menjadi serius, jika membutuhkan investigasi lebih lanjut. (C) Kemungkinan adalah problem serius yang mahal dan sulit diperbaiki hingga normal. (D) JANGAN beli mobil ini!!!!!!!!!! Kesan Pertama 1. Dimana anda mobil tersebut? Jika diperlukan, dapatkah Anda menemukan penjualnya kembali? (D) 2. Apakah alamat penjualnya jelas? (D) 3. Bicara langsung ke penjual; apakah pertanyaan Anda dijawab dengan sigap? (D) 4. Lihat dan perhatikan sisi kendaraan, apakah terlihat lurus dan simetris? (D) 5. Periksa setiap sisi untuk mengenali kerusakan berat. (C) 6. Periksa celah antar panel, seharusnya rata dan konsisten. Jika tidak, ada kemungkinan...

Daftar Alamat Bank Jabar Banten (BJB) Jakarta

Alamat dan telpon Kantor Cabang , Kantor Cabang Pembantu, dan Kantor Kas Bank Jabar dan Banten yang berlokasi di Jakarta meliputi wilayah Jakarta Pusat, Jakarta Timur , Jakarta Barat, Jakarta Utara, Jakarta Selatan Kantor Cabang - Bank Jabar Banten - Jakarta Nama KC Alamat Telpon Fax JAKARTA Bank DEVISA Jl.Jend.Sudirman Kav.2 Gedung Arthaloka Lt.Dasar & Lt.4 Jakarta Pusat 021-2511448, 2511449 021-2511450, 2514415 HASYIM ASHARI Jl. KH. Hasyim Ashari No. 32-34, Jakarta Pusat 021-6330676 021-6324430 MANGGA DUA Gedung Masterina Jl. Mangga Dua Raya Blok F1 No. 1-3 Jakarta Pusat 021-62204094, 62204095, 62204096 021-62204093 KEBAYORAN BARU Graha Iskandarsyah Lt. 2 JL. Iskandarsyah Raya no. 66 C Kebayoran Baru 12160 - Jakarta Selatan 021-7229777, 7207334 021-7206990, 7209941 RAWAMANGUN Jl. Pemuda No. 97 Kec. Pulogadung - Jakarta Timur 021-47861771, 47868072, 47868073 021-47863209 Kantor Cabang Pembantu - Bank Jabar Banten - Jakarta NAMA KCP ALAMAT TELPON ...

Nomor Telepon Marshanda

Selingan. Buat bacaan ringan :D -ivo ---------- Forwarded message ---------- Date: Jul 24, 2005 7:57 PM Subject: Tanya Contact Person Marshanda & Delon Sejak gue makin keranjingan internet, gue memutuskan untuk masang line telepon sendiri di kamar.  Tadinya gue happy banget punya line sendiri, sampe akhirnya gue mulai diganggu telepon-telepon misterius. [kriiing] "Halo..." "Halo... Caca ada?" "Oh salah sambung." [klik] [kriiing] "Halo..." "Halo... Caca ada?" Nah, gue mulai heran nih. Yang nelepon beda, sama2 nyari Caca. "Salah sambung" (nada tegas) [klik] [kriiing] "Halo..." "Halo, dengan 314-xxxx?" "Iya betul." "Cacanya ada?" Wah ini udah masuk kategori ajaib. Telepon baru dipasang sebulan, kok udah ada yang salah nomer sampe lengkap gitu? Gue jadi was-was; jangan2 telepon gue dikloning. Maka bulan berikutnya gue minta perincian tagihan telepon gue. Terny...