Live data from Hacker News

Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

twitter.com

61–70 of 99 posts

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#61
post #55

How else is the CEO supposed to respond? He's in the tough position where he can't prove a negative; the burden of proof is on the original tweeter. So the CEO needs the "hacker" to either prove it or admit they were mistaken, and bug bounties are exactly how companies do this. (Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying th…

> you'd be shocked how many people try to claim bug bounties from us because they "hacked" their own account using their own credentials. Wait ...what? Like, seriously?

Yup, but in a roundabout way.

For example, they'll inspect traffic and nab a session cookie. Then they'll use that session cookie on another internal API request to change a setting, and claim they were able to modify a setting by reverse engineering things.

They seem really scary at first, and then you dig into it and you're like "oh...".

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#62
post #43
post #36

Earlier quoted context omitted.

My best guess for the second one is "human trafficking".

Or perhaps a Runescape fan. "buying gf, 100 gp" I wonder if they also have an armour trimming service.

Look at the person's comment history. He seems to be very sincere about wanting to sell women to people.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#63
post #55

How else is the CEO supposed to respond? He's in the tough position where he can't prove a negative; the burden of proof is on the original tweeter. So the CEO needs the "hacker" to either prove it or admit they were mistaken, and bug bounties are exactly how companies do this. (Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying th…

> you'd be shocked how many people try to claim bug bounties from us because they "hacked" their own account using their own credentials. Wait ...what? Like, seriously?

A few weeks ago I saw a vulnerability reported for an FTP server that claimed they could put a file on the remote server. With FTP! What madness! I wish I could find it but I cannot, still makes me chuckle.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#64
post #37
post #34

Earlier quoted context omitted.

> kingofkyiv.com > buyagf.com What the hell am I looking at?

The kingofkyiv account frequently tries to plug their sketchy eastern-european-women-"love"-connection huckster website on HN. Preying on desperate nerds could be profitable.

That's what the first site is. Wtf is the second one??

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#65

Coincidentally I just received an email request to reset my password on Namecheap (not issued by me), anyone else? On top of that, my account has been locked for 24 hours for three consecutive failed password or username entry attempts.

You should watch your domains and look out for any friends who suddenly have a new car or a new nice watch :-).

My strategy for things is to use a unique username and email address (and password..) for critical services, that way any hacks/leaks of other sites don't reveal my entire web presence. It may be that your email was found in another dump, or from a domain whois lookup.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#66
post #55

Earlier quoted context omitted.

> you'd be shocked how many people try to claim bug bounties from us because they "hacked" their own account using their own credentials. Wait ...what? Like, seriously?

A few weeks ago I saw a vulnerability reported for an FTP server that claimed they could put a file on the remote server. With FTP! What madness! I wish I could find it but I cannot, still makes me chuckle.

Yeah, we get those too. We let people write JavaScript to build their sites (we're a site builder), and people will use that feature and add an alert and then claim it's XSS (on their own account).

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#67

Coincidentally I just received an email request to reset my password on Namecheap (not issued by me), anyone else? On top of that, my account has been locked for 24 hours for three consecutive failed password or username entry attempts.

Perhaps someone just got confused with the amount of j's in their username?

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#68

> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mech…

I think that's reasonable. I was thinking in terms of cutting out the gaming aspect when I made that statement. I probably should have been more specific. The premise of the entire conversation was based on someone making an unjustified accusation without even following it through and testing it to begin with.

No post body was provided.

Re: Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk

#69

Really glad I moved my domains to Porkbun recently. This is Namecheaps second blunder this year in terms of being a reliable service provider. First engaging in politically cheap racial discrimination (their ban on Russia seemingly having hit anyone who ever in their history used a Russian IP adress and demanding evidence of a users current location before lifting it), now giving hackers carte blanche to screw with e…

Besides that, Porkbun is also cheaper in most cases.

That's why I moved most of my Domains to Porkbun too.

Post reply on HN