Skip to main content

CSRF Flaw Allowed Attackers to Hijack GoDaddy Domains

Internet domain registrar GoDaddy has rushed to fix a cross-site request forgery (CSRF) vulnerability that could have been leveraged by malicious actors to take over domains.

The flaw was identified on January 17 by New York-based security engineer Dylan Saccomanni while managing a domain. The expert realized that the company had not implemented any CSRF protections for many DNS management actions.

According to the researcher, an attacker could have exploited the vulnerability to edit nameservers, edit the zone file, and modify automatic renewal settings. 

Saccomanni has published proof-of-concept code for editing nameservers, disabling the auto-renew feature, and editing DNS records.

Continue reading at http://www.securityweek.com/csrf-flaw-allowed-attackers-hijack-godaddy-domains

More at KING.NET

Comments

Popular posts from this blog

Office365 - This resource doesn't accept meetings longer than 1440 minutes

When you create a meeting schedule for number of days, you will see an error  "This resource doesn't accept meetings longer than 1440 minutes". By default the mailbox or room was set for a maximum limit of 1440 minutes.

Here's how you can disable this limit.
Login to the Office 365 Administration ConsoleIn Microsoft Office 365 Exchange, click on Manage.In Manage My Orgnization, click the drop down arrow, and click on Select on Another User. This will prompt you to select the mailbox or room to manage.Select a Mailbox or Room, click OK.In Option, click on Settings.In Scheduling Options, un-check the "Limit meeting duration", then click on Save. That's all. You can now schedule a meeting or reserve a room for number of days.

Hope this help you.

If this helped you, please take the time to share this post by sharing using Google+, Facebook, Twitter, or LinkedIn

Out of Office Reply for Termed Employee

This is a sample Out of Office message that I used for termed employees, unless HR staff specified a different message.

=== Example for KING.NET Employee ===
John Doe (employee or consultant) is no longer with KING.NET effective June 1, 2013 (termination date). For matters relating to "Project Name here" please direct your concerns to John Smith at johnsmith@king.net (Manager or Supervisor). For all other matters, please direct your email to Mary Smith HR at marysmith@king.net.

Please call our main office 703-345-6789 if you have other concerns.
Thank you.

=== End of message ===

I posted this article year 2008 from my old blog.
http://whaddya.blogspot.com/2008/11/example-of-out-of-office-reply-for.html


If this helped you, please take the time to share this post by sharing using Google+, Facebook, Twitter, or LinkedIn

Facebook Business Valuation

Interesting post from Techcrunch.com about the Facebook valuation and I would like to share this to you folks. The picture graph provide a thousand words to fully explain their growth. Please click the image to see in full screen.