Namecheap 因他人索要便将我的账户信息泄露给了未经核实的第三方
94 分•作者: Thrashed•2 个月前
我已经是 NameCheap 的客户 13 年了。我还曾帮助一个大学社团支付 .com 域名的费用(该域名以我的名义、地址和电话号码注册)。在最近一次领导层交接期间,新任社团负责人想更改 DNS 设置,但他不知道应该联系我。他发现该域名托管在 NameCheap,于是便使用域名发起了密码重置。我收到一封密码重置邮件,并立即提交了一个 NameCheap 支持工单,写道“我并未发起此操作”。他们打电话给我核实是我提交的工单,然后又发了一封套话邮件,里面包含一些建议,比如检查杀毒软件。
然而,新任社团负责人很执着,他打电话给 NameCheap 支持。他成功说服他们,这个以我的名义和地址注册的域名实际上属于他的社团,并且在没有任何验证或确认的情况下,NameCheap 就更改了我的密码,并更改了与我账户关联的电子邮件地址。这一切仅仅是因为有人在电话里“客气地”请求了一下。
与此同时,有人向新任社团负责人透露了我的身份,我们得以联系并完成了域名转移。最终,我乐意将访问权限甚至所有权交给他们(考虑到学生社团的换届情况,域名很可能不会被续费,然后被抢注者盯上,这就是我一直为他们保持续费的原因)。
但 NameCheap 根本不知道这些。在 NameCheap 看来,这是一个我的个人账户。他们证明了自己能够打电话给我(以核实我最初的工单),但当有人打电话给他们说“但我真的想访问那个账户”时,他们却不 bother 了?
我甚至不愿意称之为社交工程。这显然是一个巨大的安全漏洞。在看到第三方可以如此轻易地完全接管一个 NameCheap 账户后,我已经将我十几个最关键的域名从 NameCheap 迁移出去:只需要客气地请求一下就行了。
查看原文
I’ve been a NameCheap customer for 13 years. I’ve also helped out an old college club paying for a .com they use (that is registered to me under my name, address, and phone number). During a recent leadership transition, the incoming club lead wanted to make changes to the DNS and didn’t know to contact me. They figured out the domain name was parked at NameCheap, so they initiated a password reset using the domain name. I got a password reset email and immediately filed a NameCheap support ticket saying “I did not initiate this”. They called me to verify I was the one who filed the ticket, and then followed up with a canned email with tips like check your anti-virus.<p>The incoming club leader was persistent though, and called NameCheap support. He convinced them the domain registered in my name and address really belonged to his club, and with no verification or validation whatsoever, NameCheap changed my password, and changed the email address associated with my account. All because someone simply asked nicely on a phone call.<p>Meanwhile in the background, someone advised the new club leader who I was and we were able to connect and get things transferred over. Ultimately I was happy to give them access or even ownership if they wanted (student club turnover being what it is, it’s likely a domain doesn’t get renewed and gets gobbled up by a squatter, which is why I was keeping it current for them).<p>But NameCheap had no way of knowing any of this. As far as NameCheap was aware, this was a personal account of mine. They demonstrated they were perfectly able to pick up a phone and call me (to verify my initial support ticket) but when someone calls them and says “but I really want access to that account” they don’t bother?<p>I’d hesitate to even call this social engineering. It’s clearly a massive vulnerability. I’ve already moved a dozen of my most critical domains out of NameCheap after seeing just how easy it is for a third party to completely take over a NameCheap account: just ask nicely.