An Australian company that manages Internet domain name registrations acknowledged that it was partially responsible for a Web domain hijacking that left Public Access Networks (Panix), a New York Internet hosting company, without an Internet address over the weekend.
An error by Melbourne IT Ltd. allowed fraudsters using stolen credit cards to take control of Panix.com, Public Access Networks's Internet domain, early Saturday, Eastern Standard Time, according to Ed Ravin, a Panix system administrator. The hijacking deprived some Panix customers of e-mail access for two days, and shone a light on what some contend are holes in the system for managing Internet domain transfers, according to Ravin and others.
Panix regained control of its Internet domain Monday, after Melbourne IT reversed the registration change that transferred ownership of Panix.com to an unknown party Saturday night . However, some customers were still experiencing problems Tuesday as the transfer changes worked their way through the worldwide network of DNS (Domain Name System) servers that manage requests for Internet addresses, Ravin said.
The hijackers somehow exploited a "loophole" in the process used to verify requests for domain transfers with the party that owns a Web domain, according to an e-mail message sent to Panix's founder and President Alexis Rosen from Bruce Tonkin, chief technology officer at Melbourne IT. About 5,000 customers were affected and some of them may have lost 100 or more e-mail messages over the weekend, Rosen said in an interview.
According to a recently updated policy from the Internet Corporation for Assigned Names and Numbers (ICANN), requests to transfer domains between two domain registrars require the registrar who will be taking over control of an Internet domain to receive approval for the transfer from an administrator at the "losing" registrar-- the organization that will be ceding control of a domain. ICANN also requires an e-mail to be sent to both registrars involved in the transfer and allows five days for the losing registrar to cancel the transfer. (See: http://www.icann.org/transfers/policy-12jul04.htm.)
However, an error at Melbourne IT allowed an individual or individuals to use an account at Melbourne IT reseller Fibranet Services Ltd., a U.K.-based ISP (Internet service provider), to gain control of the Panix.com domain without the permission of Panix staff or Panix.com's domain registrar, Dotster of Vancouver, Washington, Tonkin wrote.
The administrative contact for the Panix domain at Dotster, the company's registrar, was not contacted before the transfer went through, as required by ICANN. Panix also was left in the dark about the transfer and only realized what was going on when it lost control of its domain Saturday, Ravin said.
Furthermore, an investigation by Fibranet revealed that the account to which ownership of the Panix.com domain was transferred was fraudulent and set up with stolen credit cards, Tonkin said.
The loophole that led to the unauthorized transfer has been closed and Australian authorities are investigating the fraudulent account. Some security features do exist to prevent hijacking, including a domain registration locking feature that automatically denies transfer requests. However, such a feature was not used for the Panix domain, he wrote.
For Panix customers like Andrew Ross, the mistake at Melbourne IT meant a weekend without e-mail, as Panix staff struggled to get through to their counterparts at Melbourne IT to reverse the changes.
Get the independent advice and expertise you need to support a virtual workforce.
The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.
Download now »Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.
Download now »A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »