The Register® — Biting the hand that feeds IT

Feeds

300 UK domains pilfered, MASSIVE security lapse blamed

123-Reg, Nominet investigate website control-panel bug

Free ESG report : Seamless data management with Avere FXT

Exclusive What appears to be a glaringly obvious security hole has been blamed for the snatching of 300 domains hosted by one web-hosting firm last year, The Reg has discovered.

A source told El Reg that anyone with a hosting package from 123-Reg, and hence an account control panel, simply had to change the final section of the URL manually (to, for example, /someoneelseswebsite.co.uk) to be able to gain access to another site's emails, name servers and billing.

With access to the admin panel, would-be domain thieves just had to change the contact details for UK registry Nominet to a new email address and then do a failed password request to have a new password sent to the new email address, locking the original owner out, our source claimed.

The .uk registry told The Reg it had "worked with registrars to help them tighten security and prevent a repeat of this incident". Both 123-Reg and Nominet informed us that there was "a query from a registrant" last year that led to Nominet "discovering some irregularities in registration and renewal patterns".

"As part of Nominet's standard operating procedures they locked the affected domains from any transfer or adjustment whilst they investigated further, and with our full support," 123-Reg said in an emailed statement.

Nominet said that its investigations into the issue revealed that "a total of 300 domains had been transferred over to a new registrant in the post-expiry period without the permission of the original registrant".

"We [have] terminated our registrar agreement with one registrar," the dot-UK registry said.

Neither firm would comment on how the the breach had come about or whether the matter had been referred to Britain's Information Commissioner.

Nominet said it couldn't elaborate any further because "we understand there is an ongoing police investigation into this issue". ®

Updated to add

Nominet has been in touch after publication to say that 123-Reg was not the only domain company involved: "Four registrars had domain names that were affected," a spokesman told us.

Email delivery: Hate phishing emails? You'll love DMARC

Whitepapers

5 ways to reduce advertising network latency
Implementing the tactics laid out in this whitepaper can help reduce your overall advertising network latency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Email delivery: 4 steps to get more email to the inbox
This whitepaper lists some steps and information that will give you the best opportunity to achieve an amazing sender reputation.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
5 ways to prepare your advertising infrastructure for disaster
Being prepared allows your brand to greatly improve your advertising infrastructure performance and reliability that, in the end, will boost confidence in your brand.

More from The Register

next story
EE still has fastest, fattest 4G pipe in London's M25 ring
RootMetrics unfurls crowd-sourced 4G coverage map
Report says PRISM snooped on India's space, nuclear programs
New Snowden doc details extensive NSA surveillance of 'ally' India
Highways Agency tracks Brits' every move by their mobes: THE TRUTH
We better go back to just scanning everyone's number-plates, then?
Google tentacle slips over YouTube comments: Now YOUR MUM is at the top
Ad giant tries to dab some polish on the cesspit of the internet
Reg readers! You've got 100 MILLION QUID - what would you BLOW it on?
Because Ofcom wants to know what to do with its lolly
Google says it's sorry for Monday's hours-long Gmail delays
Dual networking outage won't happen again, honest
prev story