![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Moniker fake suspension notice (phish?)
Received this for a few of my domains. At first glance it actually looks quite legit. Note that it includes the domain name and also the registrar. A fair bit more sophisticated than the usual "your (bank you don't actually use) login is invalid" phish.
The link includes the victim domain in the URL. I haven't clicked through to see what happens. ========== Dear Sir/Madam, The following domain names have been suspended for violation of the Moniker Online Services LLC Abuse Policy: Domain Name: <my domain> Registrar: Moniker Online Services LLC Registrant Name: Moniker Privacy Services Multiple warnings were sent by Moniker Online Services LLC Spam and Abuse Department to give you an opportunity to address the complaints we have received. We did not receive a reply from you to these email warnings so we then attempted to contact you via telephone. We had no choice but to suspend your domain name when you did not respond to our attempts to contact you. Click here and download a copy of complaints we have received. Please contact us for additional information regarding this notification. Sincerely, Moniker Online Services LLC Spam and Abuse Department Abuse Department Hotline: 480-846-1648 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Too lazy to set a custom title
Join Date: Jun 2003
Location: Ottawa
Posts: 19,631
|
its a huge phishing campaign. i've gotten hundreds of them.
__________________
you don't know you're wearing a leash if you sit by the peg all day.. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
By the way, Moniker has pulled this sort of shit before - threats of suspension etc - which is another reason I initially thought it was legit.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Too lazy to set a custom title
Industry Role:
Join Date: Oct 2001
Location: ┌∩┐ ◣_◢ ┌∩┐
Posts: 46,909
|
Where did I set that timeline graphic.....
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
I'd rather be on my boat.
Industry Role:
Join Date: May 2003
Location: Miami, FL
Posts: 9,743
|
There has been a bunch of domain phishing attempts flying around in the last month or so. I have had several, seemly from several different domain companies. Just staying sharp on the URLs and contact info in the emails, compared to the real companies, will keep you safe.
.
__________________
Michael Sperber / Acella Financial LLC/ Online Payment Processing [email protected] / http://Acellafinancial.com/ ICQ 177961090 / Tel +1 909 NET BILL / Skype msperber |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
Confirmed User
Industry Role:
Join Date: May 2002
Location: Malaysia
Posts: 3,376
|
Quote:
However, that's also another reason why you should consider TFA (Two Factor Authentication). The idea of TFA is to incorporate (a) something you know ie a password with (b) something you have ie a mobile phone or token or something else. Therefore someone with your username and password alone is not going to get into your account. It's a standard feature at Namecheap (free of charge) but they also have a lot of other security features that would defeat phishing and other similar kinds of malady. For example, you are able to disable the "Forgot Password" options which means that if someone gains access to your email they also will not be able to send the login details to your email address.
__________________
"In a Time of Universal Deceit, Telling the Truth is a Revolutionary Act." - George Orwell |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Too lazy to set a custom title
Industry Role:
Join Date: Oct 2001
Location: ┌∩┐ ◣_◢ ┌∩┐
Posts: 46,909
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,592
|
__________________
![]() Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
xxx
Industry Role:
Join Date: Jun 2003
Location: UK
Posts: 31,544
|
__________________
The Affiliate Program |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Let's do some business!
Industry Role:
Join Date: Sep 2004
Location: Austin, TX
Posts: 31,288
|
This isn't just Moniker. This scam is making the rounds through all the registrars. I've been getting them from eNom for two weeks now. They don't appear to have hit Go Daddy yet but I'm sure that will be cycling through pretty soon.
__________________
Vacares - Web Hosting, Domains, O365, Security & More - Paxum and BTC Accepted Wanted: CCBill pay sites for sale |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
So Fucking Banned
Industry Role:
Join Date: Feb 2001
Location: Taipei
Posts: 25,198
|
Mine were from ENOM etc
Hover over the link in the email and it links to some shady looking url, you can see from that, how shady this is. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
So Fucking Banned
Industry Role:
Join Date: Nov 2015
Posts: 1,418
|
I've got these in the mail before
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
FUBAR the ORIGINATOR
Industry Role:
Join Date: Jan 2002
Location: FUBARLAND
Posts: 67,382
|
__________________
![]() FUBAR Webmasters - The FUBAR Times - FUBAR Webmasters Mobile - FUBARTV.XXX For promo opps contact jfk at fubarwebmasters dot com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
VIP
Industry Role:
Join Date: Jul 2013
Posts: 22,112
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | ||
Confirmed User
Industry Role:
Join Date: May 2002
Location: Malaysia
Posts: 3,376
|
Quote:
Quote:
__________________
"In a Time of Universal Deceit, Telling the Truth is a Revolutionary Act." - George Orwell |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Icq: 14420613
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
|
this has been going on for a week or more
![]() ![]() ![]()
__________________
Need WebHosting ? Email me for some great deals [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed Chicago Pimp
Industry Role:
Join Date: Aug 2004
Location: Chicago
Posts: 7,100
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | ||
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
Quote:
Then again.... I guess people who fall for phishing aren't going to know or care about IP based security. Or 2FA, for that matter. |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |||
Confirmed User
Industry Role:
Join Date: May 2002
Location: Malaysia
Posts: 3,376
|
Quote:
So if I know with a high degree of certainty that I will never access from say China or Pakistan, I should be able to exclude access from any IP originating from CN, PK or any given set of countries. Of course, hackers can hide it but I guess it all helps. Quote:
Quote:
![]()
__________________
"In a Time of Universal Deceit, Telling the Truth is a Revolutionary Act." - George Orwell |
|||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 | |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
So it goes like this... 1) First 2FA value is captured by phish site, and passed through. At this point if login was to succeed they would have control of your account. 2) Registrar sees unknown & geographically disparate IP (the phish site) logging into that account, sends SMS to client with further instructions to further verify the login. 3) SMS warns of possible breach and advises client to load registrar site directly in order to complete login, which may then require them to change password, or confirm that the new IP on the other side of the world is actually legit. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Confirmed User
Industry Role:
Join Date: May 2009
Location: Onboard an airplane around the globe
Posts: 3,733
|
I have my domains at Fabulous and I have been getting those too.
One way to catch those are that they are sent to the domainprivacy email. Fabulous always communicate with me on my real email, via a forwarding email address, which is of course unique and only used for just Fabulous. It contains letters and numbers in a certain order, only Fabulous knows about this email to even exist and it would be highly unlikely for anyone else to guess the email. Thereby, once I receive an email addressed to that forwarding address, then I can quite safely assume it is real and everything else gets ignored. But I found the same emails in my Gmail spam box, with the domain http:// shakilkumar . com/abuse_report . php?domain.com You can remove the ?domain.com and see, it will try to download a .pdf.scr file. Pretending to be the complaint in PDF format but in reality an executable .scr file. Of course I didn't download the file nor did I enter my own domain after the question mark.
__________________
---------------------------------------------------------------------------------- The truth is not affected by the beliefs, or doubts, of the majority. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 | |
Confirmed User
Industry Role:
Join Date: May 2002
Location: Malaysia
Posts: 3,376
|
Quote:
Since I am using it as soon as I am receiving it, the 2FA is of no use to the phisher who has no way to obtain a new one because he doesn't own my phone. I think technically its possible but difficult for a phish site to use a 2FA.
__________________
"In a Time of Universal Deceit, Telling the Truth is a Revolutionary Act." - George Orwell |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 | |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
![]() If you're logging in via the phish site, which then relays your username, password and a valid 2FA token to the registrar, they control your session. There is only the 2FA challenge once, at login; every subsequent load will present some sort of session identifier, in the URL, or a cookie. Since you're going via the phish site, they can capture that session identifier, and now they own your session. Then it's as simple as printing a "we were wrong, apologies for the inconvenience," with a fake logout button, to make the user go away (remember they're responding to a notice about their domain, not just routinely logging in to do something else.) Phish site still owns the active session and can do anything with your account that does not require another 2FA challenge. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 | |
Confirmed User
Industry Role:
Join Date: May 2002
Location: Malaysia
Posts: 3,376
|
Quote:
So if the domain site detects login from unusual IP location, that gets flagged and prompts domain site to force a second 2FA request and require a second verification via logging in through browser rather than email link. Is this what you are saying? I do think it addresses something which people should be strongly advised against doing anyway which is logging into their account via email link. It needs work but its a good idea - I will also suggest this one.
__________________
"In a Time of Universal Deceit, Telling the Truth is a Revolutionary Act." - George Orwell |
|
![]() |
![]() ![]() ![]() ![]() ![]() |