Feeds

Gmail exploit aids domain hijack

Web designer holds out against extortion

Internet Security Threat Report 2014

Web designer David Airey has succeeded in recovering his domain after hackers exploited flaws in Gmail to trick his hosts into authorising a fraudulent transfer.

Airey's woes began when he took his girlfriend for a month-long holiday to India on 21 November, a trip he mentioned in his blog. The holiday was a break from work and he only occasionally checked his emails.

All seemed well until shortly before his return when Airey received an email from a friend informing him that his website, Davidairey.com, had "disappeared".

At first Airey thought he'd made a mistake and allowed his domain name to expire and a domain poacher had snapped it up before he got the chance to renew it. Subsequent digging revealed a darker truth: hackers had posted a bogus transfer request on his web host support panel the day Airey left for India.

This, alongside an attack on a Gmail account run by Airey, allowed them to seize his domain and hold it for ransom. Initially crooks demanded $650 before dropping their offer down to $250.

Airey's host, ICDSoft, were unable to reverse the transfer. The transfer request was initially sent to Airey's Gmail account but forwarded to crooks after they used an exploit to forward the email to a third-party account. Gmail has since fixed the flaw but Airey says that users would still be wise to check their account settings to verify that they too haven't been hit by the hack.

Recovering the domain through legal action would eat up far more in lawyer's fees, perhaps a minimum of $1,500, and might take months. During that time Airey would also lose passing trade that the domain brought in. In the meantime Airey has established an alternative Davidairey.co.uk website.

While it might be a pragmatic decision to give in to fraudsters Airey vowed to fight on, rallying considerable support in the process.

Three days after reporting how a Gmail security flaw resulting (in part) in the theft of his domain name Airey was able to recover the address. GoDaddy.com staff, the registrar with who his domain had been parked, helped him undo the transfer request.

Airey's account of the web hijack and its aftermath can be found here. ®

Security for virtualized datacentres

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
BlackEnergy crimeware coursing through US control systems
US CERT says three flavours of control kit are under attack
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.