Earlier quoted context omitted.
https://www.gandi.net/
They're cool until they start holding your domains hostage and demanding that you email them a scan of your passport.
Namecheap live chat social engineering leads to loss of 2 VPS
41–50 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#42Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#43Not trying to be snarky, but the biggest lesson here seems to be "don't operate without off-host backups". Cheap VPS providers don't typically offer that sort of thing as a standard feature. Even when they do, the backups would be on the same infrastructure, and easily wiped from the same (compromised) console. You could have just as easily lost all the data in an accidental way, with no malice or 3rd party involved.…
We offer full backups with all managed servers/services Self-managed a customer is responsible for their own backups. Just like with DO and that full server loss a couple of months back.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#44Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and what is not possible, as well as the security precautions we have in place.
Is it? Does that mean that my ability to reset your users solusvm passwords with or without 2fa constitutes as a 1337 0day?
Hey BTW, remember that time you got hacked through your support site and didn't tell anyone?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#45the first error was buying server space from namecheap. good domain server but they get hit frequently being a midsize provider of services, they have enough bait and not enough people to protect it.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#46Earlier quoted context omitted.
We offer full backups with all managed servers/services Self-managed a customer is responsible for their own backups. Just like with DO and that full server loss a couple of months back.
We who?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#47Earlier quoted context omitted.
That's not good verification. It takes a couple of minutes to produce convincing fake ID scans, and they aren't going to have anything to verify them against. And presumably they wanted you to send those photos to them as an unencrypted email attachment, right?
its better verification than most will require.
Edit: Since I'm getting some downvotes I'd really like to know how one could possibly argue that asking for ID scans is better than email resets. You can't really forge the ability to receive email at an address, but you can very easily replace the name on an ID scan.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#48I for one haven't seen very many services that don't allow you to reset your 2fa if you control the attached email. Would anyone here seriously expect that someone in control of their email wouldn't be able to take control of associated accounts?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#49On another note, there 2FA seems to broken as well. I once received a text about resetting my Instagram account from the same number that they send me to authenticate my login session. I've never had an Instagram account.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#50I wish there was a way to disable the "customer support backdoor" in all these kinds of services. I've started to deploy full disk encryption to all my servers now so if the attacker does manage to get into the management account the server itself is still protected from single user / rescue mode / etc.