Live data from Hacker News

Perl.com Taken over by Domain Squatters

twitter.com

41–50 of 82 posts

Re: Perl.com Taken over by Domain Squatters

#41
post #21
post #8

Looking at whois history sites, it looks like the domain was owned by Tom Christiansen aka tchrist, which wrote Programming Perl, Learning Perl and the Perl Cookbook. The record wasn't supposed to expire until 2029, so not sure how the squatters got this domain.

Perhaps they pwned his e-mail acccount, or social-engineered their way to take control of his phone number. (Just guessing.)

There's always the chance someone social-engineered their way past the registrar's access control, or that they got some kind of access to the registrar's systems. Or the domain owner simply didn't read an email properly and clicked the wrong link.

There's too little information to draw conclusions at this point.

Re: Perl.com Taken over by Domain Squatters

#42

Let’s call it what it is. It’s not a domain taken over by squatters. The domain was stolen. I’ve seen other domains get stolen recently, it seems to be about the same time. Patterns dot com Piracy dot com Perl dot com All stolen at around the same time. With patterns, the thief hacked the network solutions account, put the domain under privacy, transferred it to a Chinese registrar, and then put the old whois data ba…

Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.

Re: Perl.com Taken over by Domain Squatters

#43

Very strange indeed > @xsc: Looks like this breach also affected http://piracy.com http://chip.com http://neurologist.com along with http://perl.com ( https://www.afternic.com/listings/drawmaster )

checking whois for each of those domains, my first thought is I sure hope Key-Systems didn't get owned :|

EDIT: On a sidenote:If this[1] is true, looks like the attacker may have compromised another registrar that perl.com used (Network Solutions), moved domain to another registrar, than KS. Still a big concern though

[1] https://nitter.net/DInvesting/status/1354778895749419013

Re: Perl.com Taken over by Domain Squatters

#44

Very strange indeed > @xsc: Looks like this breach also affected http://piracy.com http://chip.com http://neurologist.com along with http://perl.com ( https://www.afternic.com/listings/drawmaster )

checking whois for each of those domains, my first thought is I sure hope Key-Systems didn't get owned :| EDIT: On a sidenote:If this[1] is true, looks like the attacker may have compromised another registrar that perl.com used (Network Solutions), moved domain to another registrar, than KS. Still a big concern though [1] https://nitter.net/DInvesting/status/1354778895749419013

KS is just the destination registrar. Most of the domains were from NetSol from what I can tell.

Re: Perl.com Taken over by Domain Squatters

#45
post #42

Let’s call it what it is. It’s not a domain taken over by squatters. The domain was stolen. I’ve seen other domains get stolen recently, it seems to be about the same time. Patterns dot com Piracy dot com Perl dot com All stolen at around the same time. With patterns, the thief hacked the network solutions account, put the domain under privacy, transferred it to a Chinese registrar, and then put the old whois data ba…

Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.

Agreed, definitely use 2fa if it’s offered. What many people don’t realize is that there are a lot of registrars still using less secure platforms. So moving to a more secure registrar can help as well.

I mention registering for 5 years in the future because if something like this happens, there will be no question as to whether or not you lost the domain because it expired.

Re: Perl.com Taken over by Domain Squatters

#46
post #8

Looking at whois history sites, it looks like the domain was owned by Tom Christiansen aka tchrist, which wrote Programming Perl, Learning Perl and the Perl Cookbook. The record wasn't supposed to expire until 2029, so not sure how the squatters got this domain.

Likely phishing or some other account takeover tactic. Also not "squatters". This domain was stolen.

Re: Perl.com Taken over by Domain Squatters

#47
post #44

Earlier quoted context omitted.

checking whois for each of those domains, my first thought is I sure hope Key-Systems didn't get owned :| EDIT: On a sidenote:If this[1] is true, looks like the attacker may have compromised another registrar that perl.com used (Network Solutions), moved domain to another registrar, than KS. Still a big concern though [1] https://nitter.net/DInvesting/status/1354778895749419013

KS is just the destination registrar. Most of the domains were from NetSol from what I can tell.

as noted in my edit

Re: Perl.com Taken over by Domain Squatters

#48
Floodgap was part of this. I just talked to a very helpful person in NetSol's security department and she looked through the ticket. It was initiated by a web chat, and they produced official looking but completely fraudulent documents (photo ID, utility bill, business license, etc.) to prove identity, so this was socially engineered and apparently for multiple domains. They're supposed to contact me tomorrow for more on the post mortem.

Re: Perl.com Taken over by Domain Squatters

#49

Earlier quoted context omitted.

How would you prevent a group from trolling or performing a hostile takeover of a small domain? How would someone acquire a domain? How do you determine consensus? In this case, as someone who doesn't follow Perl, how would I make an informed decision on which perl.com domain I really want?

It's not an obvious problem to solve, but nobody would invest much in performing a hostile take over of a small domain. In the case of Perl.com it looks like a hostile takeover, of a popular domain, and it didnt cost them much to take it over I guess.

Here [0] is an example of someone putting inordinate amount of effort to take down a tiny mastodon instance. If it would have been possible to take over a domain in a similar manner - it would have happened too.

[0] https://news.ycombinator.com/item?id=21719793

Post reply on HN