Slashdot Mirror


MelbourneIT Lapse Permitted Panix Hijack

McSpew writes "Netcraft reports MelbourneIT's CTO, Bruce Tonkin, has admitted the Panix domain hijacking occurred because of a loophole in MIT's domain transfer process. He doesn't go into detail about what that loophole was, or how it was closed. As a Panix user, I'd like more detail, and I'd like to know what can be done to stop this sort of nonsense happening to other domains."

9 of 200 comments (clear)

  1. Overworked by tuxter · · Score: 5, Insightful

    I'd like to know what can be done to stop this sort of nonsense happening to other domains

    You'll never stop this sort of stuff, there is always someone smarter and more determined to find loopholes than the overworked, caffeine addicted guy paid to write the code.

    1. Re:Overworked by ajd1474 · · Score: 5, Interesting

      I have had my share of problems with Melbourne IT.

      My father registered a domain name with them under the company name " Brothers Inc." But on the form mispelled Brothers as Borthers. On top of that, no such company ever existed.

      When it came time to transfer the domain name to me, Melbourne IT wouldnt have a bar of it. They wanted proof of my association with this "fictional" company before i could take contral of the domain. When i pointed out that no such company existed, they argued and insisted that i produce a permission of transfer on the company letterhead of "******* Borthers" before they would allow me to move the domain.... even though they acknowledged that no such company exists.

      So what did i do? I created a fake letterhead, signed it and faxed it. They then gave me full control of the domain the same day!

      --
      I refuse to have a sig... dammit!
  2. The is simple by crunk · · Score: 5, Funny
    There was an error in the checking process prior to initiating the transfer

    Someone screwed up.

    The loophole that led to this error has been closed.

    And they fired the guy.

    --
    It's the battle of the minds, and everyone's unarmed.
  3. Melbourne IT have a history of fucking with this. by Anonymous Coward · · Score: 5, Informative

    For quite some time, on the NS redelegatiom page of the MelbIT web site, you could enter in either a hostname, or an IP address, or both, to chose your new nameservers. Great for those of us having to move IP ranges or whatnot.

    The problem is, the web form did nothing at all with the IP addresses you put in. It completely ignored them. You had to call up Melbourne IT and speak to somebody to get the mess sorted out. That one caused me a day of pain.

    Other times, the staff members have stated facts that clearly went against all of their procedures on the web page for redelegation and/or key retreival. "Sorry, no, even though thats what the web page says, it REALLY means the opposite"

  4. What Happened by Marlor · · Score: 5, Informative

    Here is a basic explanation of what happened from what I have read.

    ICANN recently changed the rules for domain name transfers so that rather than requiring confirmation for domain name transfers, they are transferred automatically if the owner does not object within a set period of time (a few weeks IIRC). This is meant to "streamline the domain transfer process". In this regard, I believe that ICANN is partially to blame for this hijacking. These policy changes need to be reviewed. You can, of course, lock your domain against this occurring, but it is a simple error to neglect to do this.

    Melbourne IT is also more or less to blame for this hijacking (depending on who you believe). It has been confirmed that one of their resellers allowed someone to create an account with a stolen credit card number, and initiate the domain transfer process. Panix claims that Melbourne IT failed to send the notification of transfer to them or their registrar. They also state that they had asked that their domain be locked against transfers, but this did not occur. If this is the case, then this is a serious issue with Melbourne IT.

    Mebourne IT has also been accused of being unavailable for contact over the weekend, despite promising 24/7 service. The only way that Panix managed to contact them was via the CEO's mobile number.

    If these accusations are true, then this shows serious problems within Melbourne IT.

  5. Clearly, MIT has it's priorities. by Saeed+al-Sahaf · · Score: 5, Funny
    Panix CEO Alex Rosen said. "I didn't find useful 24-hour NOC-type info anywhere. MIT apparently has no weekend support at all; I finally located their CEO's cellphone in an investor-relations web page."

    Clearly, MIT has it's priorities.

    --
    "Who are in control, they are not in control of anything - they don't even control themselves!" - Glen Beck
    1. Re:Clearly, MIT has it's priorities. by SteeldrivingJon · · Score: 5, Funny


      I expect that is the loophole they have fixed. The CEO's contact info is probably completely gone, now.

      --
      September 2011: Looking for Cocoa/iOS work in Boston area Cocoa Programmer Quincy, MA
  6. Re:The weekend rule by Anonymous Coward · · Score: 5, Insightful

    Speaking to an employee at Melbourne IT, I heard that THE CEO of the company was aware of the problem on the WEEKEND, and their response was that the company in question needed to provide sufficient proof that they were in fact the company they claimed to be (also initiated ON THE WEEKEND).

    Melbourne IT were working within the policy of ICANN, whereby it is now acceptable for a domain to be transferred without the explicit approval of the original owner. This policy was recently changed - it originally only allowed domains to be transferred in ownership with an explicit APPROVAL from the original company. The policy is now such that if the original company does not respond to the request within 5 days, the company asking for transfer will by default have rights to the domain. Everyone who owns a domain effectively must monitor their whois e-mail address at least every 5 days in order to ensure they keep their domain.

    This was NOT a case of Australian government being lazy. This idea of a "weekend rule" is stupid, and certainly did not apply here. This is illustrated by the fact that the company's CEO was involved ON THE WEEKEND.

    Melbourne IT are very much a corporate entity now. They have share holders, and have a large emphasis internally on sales (much to the dismay of the employee I know). This so called "weekend rule" could be applied to many many other corporates as well (the one I work for being one of them!), since normal "BUSINESS hours" are Monday to Friday 9 til 5 (or whatever your variation is). You will notice that Melbourne IT's hours of operations are rather extensive for an Australian "government" organisation. The notion that this situation was bred from some type of government "weekend rule" is ridiculous.

    If google was transferred erroneously on a weekend, you can be sure that it would be dealt with very quickly by whoever needs to deal with it, while of course working in the realms of the policies that govern their processes. The policy is at fault here, not the company governed by them.

  7. Re:The weekend rule by philovivero · · Score: 5, Funny
    In a recent terrorism trial the suspect could not contact anyone on a weekend to report a bomb plot - in 2002.

    Those Aussie terrorist suspects are a lot more polite than the Muslim and American ones. If all terrorist suspects would call in bomb plots, the authorities' jobs would be a lot easier.

    "Yes officer, if you cut the red wire directly after the green one, you should have the bomb defused and be home by tea time."