cancel
Showing results for 
Search instead for 
Did you mean: 
Go to solution

News about DNS weakness at GoDaddy.com

22Jan 19
Bomb Threat, Sextortion Spammers Abused Weakness at GoDaddy.com

 

The Above I just learned about should we be worried?

5 REPLIES 5

Krebs exposed weakness in DNS

What is GoDaddy doing to fix this weakness???

 

Brian Krebs article: https://krebsonsecurity.com/2019/01/bomb-threat-sextortion-spammers-abused-weakness-at-godaddy-com/

Highlighted
Community Manager
Community Manager

Re: News about DNS weakness at GoDaddy.com

Hi @Laisseraller @krafttechgroup. Thanks for reaching out. As the article you're referring to mentions, "We’ve identified a fix and are taking corrective action immediately... While those responsible were able to create DNS entries on dormant domains, at no time did account ownership change nor was customer information exposed". 

 

JesseW - GoDaddy | Community Manager | 24/7 support available at x.co/247support | Remember to choose a solution and give kudos.

Re: News about DNS weakness at GoDaddy.com

Yes I saw that response already.  Domain transfer isn't the issue so I'm not sure why that is part of the response from GoDaddy.  The issue is with the ability to modify a domain's DNS records by people that don't own the domain...through a weakness in GoDaddy's architecture.  When will the "fix" be applied?

Community Manager
Community Manager

Re: News about DNS weakness at GoDaddy.com

@krafttechgroup. My apologies if I'm missing something, but I don't see where GoDaddy mentions domain transfers in the response. Unfortunately, I don't have additional information currently. If I do find more I can share, I'll do it here. 

 

JesseW - GoDaddy | Community Manager | 24/7 support available at x.co/247support | Remember to choose a solution and give kudos.
Solution

Re: News about DNS weakness at GoDaddy.com

My efforts in this post was just to alert others!  Thanks for everyone that participated!   This will need to be an ongoing effort to keep on top of it.   I personally experienced my own domain name for another company stolen then the crooks attempted to sell it back to me for big dollars, I was able to change the name slightly keeping my website working and their effort ended.  This was a Canadian Company not Godaddy.  My website is now on a USA hosting site not Godaddy.  You learn by experience.