I for one haven't seen very many services that don't allow you to reset your 2fa if you control the attached email. Would anyone here seriously expect that someone in control of their email wouldn't be able to take control of associated accounts?
I think this is a very good point that I also overlooked when I first read the article. If someone hacked my gmail account, I honestly am not sure if there would be any account of mine that would be safe. Anyone using the Internet today has to put utmost care into protecting their email address and most email providers enable you to do that fairly easily. There was an article here a few months ago promoting logging i…
Namecheap live chat social engineering leads to loss of 2 VPS
71–80 of 426 posts
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#72So he is using 2FA for all the important accounts but for the most important one (the email which he used to register an account at all these services) he's using a weak pw and no 2FA? Am i missing something here? Yes they did not follow protocol but why would one not use 2FA for such an important email addy?
> I’m pretty careful to use 2FA for any service that I consider important
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#73the first error was buying server space from namecheap. good domain server but they get hit frequently being a midsize provider of services, they have enough bait and not enough people to protect it.
That doesn't really make sense. We're a great domain and hosting provider.
Just a few weeks ago I was getting a domain set up with Amazon SES, and one Daria P. helped interpret Amazon's docs to get it verified with them, and explained how I was using the dig command incorrectly to inspect the domain's settings. It's rare you see a support person do that at any company.
And, of course, they did ask for a support PIN.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#74Disclaimer: I'm CIO @ Namecheap 1. The credentials were resent to an already compromised email account 2. This is an isolated case 3. Established procedure was not followed 4. With thissaid, we've used this as a learning example and additional training has been provided to the individual involved 5. Anyone with any self-managed server with ANY provider should always keep their own multiple backups
If 3 is possible, how are we to believe 2?
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#75STOP. USING. NAMECHEAP. Its been months since I wanted to write a detailed summary, but the notion that "namecheap is hackers best domain registrar" is not valid anymore! About year ago I noticed DNS changes on many of my there-parked domains. Upon reaching via Chat (no phone support so that angry customers cannot vent off) I was told that they cannot help me cause Im not the owner of the account! Upon full verificat…
Namecheap has had two factor authentication and was the first provider to have it. Knowing public whois would not grant someone access to anyone's account at Namecheap. They'd still need to know your Namecheap username, your password, and your PIN, and if you had 2FA, that would need to be provided as well.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#76I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#77I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
Fun story time. I use to play MTGO, the online Magic the Gathering game. Played it from beta for a few years say 2002-2004. Wanted to check it out in 2014 to see how it changed. Failed password reset online, had to call in to support.
The support guy was like chortle what was your security passcode? I had no idea. He tried giving some hints. I said it has literally been 10 years, I am never going to remember. So he went ahead and rest my password. He told me for the record my security code was "I am the nacho king", but I would be prompted to change it at next login.
So could I have social engineered a 10 year old MTGO account? Yes. But without it, I would have been locked out. I was NOT going to remember some stupid passcode kid me set on a game account.
And apparently I am the nacho King.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#78Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and what is not possible, as well as the security precautions we have in place.
Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. What do you use to tell whether a chat session is a genuine user or someone successfully using a social engineering attack against your chat operatives? If the answer is "nothing" then you can't know if this is an isolated event or how many of your chat sessions go without a glitch.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#79Also let me reiterate this is an isolated event. We handle over 10,000 chat sessions every day without a glitch. I invite people to use our live chat service and see what is and what is not possible, as well as the security precautions we have in place.
First of I can social engineer one of your staff. Regardless of how much you train them. I could also bribe your staff or try to get you to hire a plant. Yea that last one is far fetched but just making a point that as long as someone can manually do these things someone will.
Re: Namecheap live chat social engineering leads to loss of 2 VPS
#80I had my 2FA at Singlehop bypassed by social engineering attack. They helpfully changed the entire account contact info without any notice to me, presumably from a phone call. The attacker didn't even have any information to go off other than the IP address. I only found out when I saw the server rebooting into rescue mode and luckily I still had an active management portal cookie (changing the password doesn't log y…
Even better, have the option to disable tech support and get an alert if a reset is requested with the metadata related to the party making the request.