What's new

Ziphosting/Netregistry Domain Exploit! - Your domain could be stolen

zhenjie

Top Contributor
This affects anyone who has purchased a domains from Netfleet/Netregistry which said domain was previously with Ziphosting (potentially other registrars).

Long story short.

Previous owner of domain I own (via Netfleet auctions) still has FULL domain management access. This includes hijacking DNS, Registrant/Technical contact details.

What this means

-Previous owners of domain can delegate the nameservers and point your domain to another website
-Worse, they can change registrant details/contacts which could potentially lead to a transfer of domain to another party via Change of Registrant process.

Ziphosting support was notified on 21st of July and to date (two business days later) they have yet to respond to what I feel is a pretty serious breach. Disappointing as I can only imagine this affects quite a few other people who are likely to be unaware that such situation exist.
 

Attachments

  • ziphosting_domainhack.png
    ziphosting_domainhack.png
    5.4 KB · Views: 29

lmb

Member
Hi - we have identified the bug that has caused this - it is very obscure and applies to a very small number of our accounts.

It affects 0.0054% of domains in our systems.

We have started inspecting and remediating all the affected accounts.

Apologies to anyone affected. it will be addressed as soon as our agents can work through the (relatively short) list.

Larry Bloch
CEO
Netregistry Group
 

zhenjie

Top Contributor
Thank you.

The slow response from ZipHosting (and Netgistry as a whole) was disappointing considering it is a security flaw.
 

findtim

Top Contributor
Interesting analysis but it's still 100% for the effected domains.


yes, and well picked up by zhenjie

we only know the time response on DNT, not on zhenjie's email, if it was 3 days ( 23rd- 26th ) as on DNT i think that is to slow also.

its now the 5th august so i think an update from LmB tomorrow would be good.

tim
 

lmb

Member
yes, and well picked up by zhenjie

we only know the time response on DNT, not on zhenjie's email, if it was 3 days ( 23rd- 26th ) as on DNT i think that is to slow also.

its now the 5th august so i think an update from LmB tomorrow would be good.

tim
Underlying bug was fixed in the first platform software release immediately following my last post. The affected domains were all locked down within 24 hours of my previous post.
 

Community sponsors

Domain Parking Manager

AddMe Reputation Management

Digital Marketing Experts

Catch Expired Domains

Web Hosting

Members online

No members online now.

Forum statistics

Threads
11,100
Messages
92,051
Members
2,394
Latest member
Spacemo
Top