Anatomy of a Domain Hijacking, part 2: The Website Who Came In From The Cold
secretGeek .:dot Nuts about dot Net:.
home .: about .: sign up .: sitemap .: secretGeek RSS

Anatomy of a Domain Hijacking, part 2: The Website Who Came In From The Cold

When secretGeek.net was taken I swore a solemn oath to myself:

My relentless campaign of jokes and nonsense will not be stopped.

And now, just a couple of long weeks later, here I am, happy to report I'm back in control of secretGeek.net.

Right when I was ready to migrate over to leonbambrick.com, I got an email from the Russian registrar, Regtime Ltd, saying:

Sorry  for answer delay. Domain was transferred onto you account.

The number one thing, I think, that helped get the site back was when a good friend, Madina, translated a lengthy email into fluent Russian for me to send to the Russian Registrar.

She re-structured the email to put the sob-story up front, all about how much personal meaning this site has for me, and the positive effects it has had on my life. I think that did the trick.

So what did we learn?

I learnt that passwords at google can be brute forced, if pop is enabled. This can be sped up by use of multiple IP addresses, or a botnet.

That's the most likely way they got access to my account. My password was 'good' by gmail standards but is now 'freaking solid' by any standard.

And I've turned on 2-step verification, plus all the other recommendations from part 1.

Thanks for the encouragement and support. It was dark times, but now the nonsense can continue.





'Chip Camden' on Tue, 07 Jun 2011 22:09:53 GMT, sez:

Excellent, Leon! Welcome back.



'David H' on Tue, 07 Jun 2011 22:29:03 GMT, sez:

Благодарим Вас за Ваш визит. Пожалуйста, приходят снова.



'David H' on Tue, 07 Jun 2011 22:34:10 GMT, sez:

Boo to automatic reformatting of Cyrillic into HTML code ; )



'Barry Kelly' on Wed, 08 Jun 2011 01:55:43 GMT, sez:

I use a 10-character alpha-numeric password in turn generated from an even longer alpha-numeric passphrase (a similar mechanism to SuperGenPass and its ilk, so the generated password is different for every site I use it on); this particular source passphrase is only used for Google and a handful of high-security accounts. I estimate that, according to that seclist link you referenced (1200 attempts per account per day), with 10 billion accounts hammering away at POP it would take an average of 96 years to break into my account.

I recommend using something like SuperGenPass even with its limitations[*] all the time, because it's almost trivial and adds substantially to your security.

[*] The limitations are that the default bookmarklet is implemented via dynamic HTML in the page where the password box itself occurs. This means that a malicious page can potentially snoop on your password before it gets generated into the final password that actually gets sent across the wire, thereby getting access to the master key. This attack is mitigated by having different security levels of "master password". Any trivial crack of a password database (e.g. Gawker, Sony etc.) won't reveal your master password, and even if someone attacked the hashing algorithm, they'd still only get a weak security master key, unless they broke into your bank's website etc., in which case you have bigger problems.



'mike' on Wed, 08 Jun 2011 02:05:01 GMT, sez:

Glad it all worked out. Good of you to document this also for the benefit of the rest of us.



'Misty Fowler' on Wed, 08 Jun 2011 17:25:46 GMT, sez:

I'm so happy that your domain got hijacked! If it hadn't, then I might never have known about this site, and my life wouldn't be nearly as complete. Thanks, hackers!

P.S. I'm even more happy that you got it back.



'Jon Schneider' on Thu, 09 Jun 2011 00:00:07 GMT, sez:

That's great, Leon. I'm glad this worked out for you.

And thanks for sharing the story. I went and strengthened all of my passwords after reading Part 1...



'Steve Trefethen' on Thu, 09 Jun 2011 05:16:46 GMT, sez:

Congrats Leon. I've enjoyed your work keep it coming!



'Juan Manuel' on Thu, 09 Jun 2011 13:00:15 GMT, sez:

Nice, I was hoping for a happy ending! ;)



'Claire' on Thu, 09 Jun 2011 15:22:21 GMT, sez:

I use passwordsafe (http://passwordsafe.sourceforge.net/) and so far, so good. I did change my master pw after reading part 1 though. Glad to see you wrested control back from the hackers!



'Gregg' on Fri, 10 Jun 2011 15:55:46 GMT, sez:

Congratulations, Leon!



'OJ' on Sat, 11 Jun 2011 01:03:46 GMT, sez:

Let me guess, your Gmail password was 'meatbag'? :)



'MJ' on Tue, 26 Jul 2011 10:02:56 GMT, sez:

I've had this very annoying problem with GMail where another guy has the same user name, but with a period in between. Google says the two user names are the same, but tell that to the other guy! He signs up on Facebook, etc. using this email address (with a period), and sure enough, I get the Facebook notifications!

I enabled 2-step authentication, and the problem has become far, far less.



'CariD' on Thu, 11 Aug 2011 05:25:38 GMT, sez:

Great to know you've taken back the control of secretGeek.net! I'm happy for you! You're lucky to have Medina who made a big help. And thanks a lot for sharing the good lesson you learned out of this experience. I swear I never knew till I read this article that passwords at Google can be brute forced, if pop is enabled. It made me so disturbed but at least now now I know what to do. Thanks to you!



'vegetable oil press manufacturer' on Wed, 15 Feb 2012 05:08:32 GMT, sez:

The sponsors are definitely needing more with this. I am glad to see the work going into this. Keep up the good work.




name


website (optional)


enter the word:
 

comment (HTML not allowed)


All viewpoints welcome. But the right to delete any post for any reason is reserved. Don't make me do it. Aim for constructiveness. Comments may be republished, emailed to your loved ones or printed and used as toilet paper. Also, I get particularly nasty on comment spam. It's not worth even trying to post comment spam here -- your html is escaped, and your links are given a rel='nofollow'. By attempting to post a comment, you understand that if the comment is considered spam, at my absolute discretion, your IP address may be used as the target of a prolonged distributed denial of service attack. Your electricity might suddenly stop working. Your car tyres will go mysteriously flat. You will suffer permanent hairloss. Your dreams will be filled with terrifying monsters. And in any case I reserve the right to record and publish your IP address.

 

TimeSnapper is a life analysis system that stores and plays-back your computer use. It makes timesheet recording a breeze, helps you recover lost work and shows you how to sharpen your act.

 

NimbleText - FREE text manipulation and data extraction

NimbleText is a Powerful FREE Tool

Use it for:

  • extracting data from text
  • manipulating text
  • generating code

It makes you look awesome. Use it right now! Go on! Hurry! Don't walk, run!

 

Articles

Mind-boggling Demo of New Gaming Genre, aka Folder-Based Hangman, aka Fun with Recursion Mind-boggling Demo of New Gaming Genre, aka Folder-Based Hangman, aka Fun with Recursion
Got CSV in your javascript? Use agnes. Got CSV in your javascript? Use agnes.
I went to write down a book name and founded an internet empire instead. I went to write down a book name and founded an internet empire instead.
NimbleText: Origins NimbleText: Origins
The Windows 8 Mullet The Windows 8 Mullet
Cosby: spontaneous striped background generator Cosby: spontaneous striped background generator
Slides from WDCNZ: Live Coding Asp.net MVC3 Slides from WDCNZ: Live Coding Asp.net MVC3
MVC 3, MVC 3, "Third Times a Charm" references
Custom Errors in ASP.Net MVC: It couldn't be simpler, right? Custom Errors in ASP.Net MVC: It couldn't be simpler, right?
Anatomy of a Domain Hijacking, part 2: The Website Who Came In From The Cold Anatomy of a Domain Hijacking, part 2: The Website Who Came In From The Cold
Anatomy of a Domain Hijacking, part 1 Anatomy of a Domain Hijacking, part 1
secretGeek.net domain has been stolen. The site may go down. secretGeek.net domain has been stolen. The site may go down.
Boring article: 'untrusted domain' issue with SQL Server. Boring article: 'untrusted domain' issue with SQL Server.
Coding While You Commute Coding While You Commute
Test Driven Dentistry Is A Good Thing Test Driven Dentistry Is A Good Thing
The 'less crashy' release of NimbleText The 'less crashy' release of NimbleText
Rethinking Toolbars in Visual Studio (or any IDE) Rethinking Toolbars in Visual Studio (or any IDE)
Where shall we have lunch? Where shall we have lunch?
Setting up email for your microIsv Setting up email for your microIsv
The NO Visual Studio movement: Compiling .net projects in Notepad++ The NO Visual Studio movement: Compiling .net projects in Notepad++
ZeroOne: the editor for programmers who think in binary ZeroOne: the editor for programmers who think in binary
Mercurial workflow for personal projects (with a .net bias) Mercurial workflow for personal projects (with a .net bias)
I see you're using vim. Let me fix that for you. I see you're using vim. Let me fix that for you.
The worst recruitment spam I've ever read The worst recruitment spam I've ever read
A thank you I forgot to say A thank you I forgot to say
My new product, NimbleText, is live My new product, NimbleText, is live
Grabbing the free songs of Jonathan Coulton (with Powershell) Grabbing the free songs of Jonathan Coulton (with Powershell)
Using NimbleSet to compare lists Using NimbleSet to compare lists
Wanted: Wiki Lists (dot org) Wanted: Wiki Lists (dot org)
DOS on Dope: The last MVC web framework you'll ever need DOS on Dope: The last MVC web framework you'll ever need
JSON Query Languages: 5 special purpose editors JSON Query Languages: 5 special purpose editors
What then, is b? What then, is b?
SQLike: A simple editor SQLike: A simple editor
Yet Another BizPlan Generator. Yet Another BizPlan Generator.
HOT GUIDS: A hot or not site for guids HOT GUIDS: A hot or not site for guids
How does life get better? One tiny hack at a time. How does life get better? One tiny hack at a time.
24 things to do, and 100 things *not* to do (yet) for building a MicroISV 24 things to do, and 100 things *not* to do (yet) for building a MicroISV
Venture capital won't kill Jeff Atwood, it will only make him Jeffer. Venture capital won't kill Jeff Atwood, it will only make him Jeffer.
A handy workflow image for newbie mercurial users A handy workflow image for newbie mercurial users
Fractal Feedback, a diversion into recreational programming Fractal Feedback, a diversion into recreational programming
Hump-Jumping: How the Education of Computer Science can be Saved, err, maybe. Hump-Jumping: How the Education of Computer Science can be Saved, err, maybe.
Suggested User Experience Improvements for DiffMerge Suggested User Experience Improvements for DiffMerge
SQL Style Extensions for C# SQL Style Extensions for C#
The Movie Hollywood (And My Wife) Doesn't Want You To See: Weekend at Jacko's The Movie Hollywood (And My Wife) Doesn't Want You To See: Weekend at Jacko's
Sysi: the ultimate administrators toolkit Sysi: the ultimate administrators toolkit

Archives .: secretGeek :: Complete Archives
TimeSnapper -- Automated Screenshot Journal TimeSnapper.com    
Version 3.3: true productivity boost

Next Action NextAction
Managing the top of your mind

NimbleText -- World's Simplest Code GeneratorNimbleText -- World's Simplest Code Generator, Text Manipulator, Data Extractor

25 steps for building a Micro-ISV 25 steps for building a Micro-ISV
3 minute guides -- babysteps in new technologies: powershell, JSON, watir, F# 3 Minute Guide Series
Universal Troubleshooting checklist Universal Troubleshooting Checklist
Top 10 SecretGeek articles Top 10 SecretGeek articles
ShinyPower (help with Powershell) ShinyPower
Now at CodePlex

Realtime CSS Editor, in a browser RealTime Online CSS Editor
Gradient Maker -- a tool for making background images that blend from one colour to another. Forget photoshop, this is the bomb. Gradient Maker


[powered by Google] 


How to be depressed How to be depressed
You are not inadequate.



Recommended Reading


the little schemer


The Best Software Writing I
The Business Of Software (Eric Sink)

Recommended blogs

Jeff Atwood
Joseph Cooney
Phil Haack
Scott Hanselman
Julia Lerman
Rhys Parry
Joel Pobar
Thomas White
OJ Reeves
Eric Sink

Aggregated Links

proggit
dzone
hacker news
dot net kicks

Human Link Machines

interesting finds
a continuous learner's weblog
arjan's world
weekly link post

LinkedIn profile
LogEnvy - event logs made sexy
Computer, Unlocked. A rapid computer customization resource
PC Smart Buys - Computer Hardware in Australia
 
home .: about .: sign up .: sitemap .: secretGeek RSS .: © Leon Bambrick 2006 .: privacy

home .: about .: sign up .: sitemap .: RSS .: © Leon Bambrick 2006 .: privacy