Slashdot Mirror


Network Solutions E-Mail Security Alert

The following story is somewhat alarming. You must read it if you own a domain name. It is not a hoax; I tested the security hole on a domain name I own. It worked. A large number of readers have written us about it. The Network Solutions site was already overloaded and responding slowly in the wee hours and is probably going to be hit hard all day. They have made a monumental mistake here. Click below to read Slashdot reader Ralph Brandi's excellent description of what's going on. Update posted 2:10 p.m. EDT - see bottom of the story (below).

Ralph writes: Network Solutions has starting spamming some of its customers with notices that include, among other things, the news that they've set up a free e-mail account for you, without bothering to ask first, at their new dot com now mail Hotmail clone. They've even taken the liberty of assigning you a password:

3. Lastly, we are pleased to offer you a FREE e-mail account using our new dot com now mail service. Because it's Web-based, you can use it in the office, at home or on the road. You'll need the following information to set up your account:

 >>>>>>>>>>>>Login name:  domainid
 >>>>>>>>>>>>Password:    domainidnsi

Note that nifty password? It's the same pattern for every domain they've registered an e-mail address for.

Big security [bleep]up. If someone beats you to your account and "guesses" your password, now they can masquerade as you, and if they change the password, you can't even get into the account.

I've already gone into my "accounts", verified that they exist, and changed the passwords. I know that they exist because when I entered other domain IDs I control that I wasn't spammed at, I was returned to the login screen rather than being brought to a presumably newly-created mail page.

I called Network Solutions tech support to demand that they remove the accounts, but the moron on the line didn't understand that they were doing something incredibly boneheaded and wouldn't listen to my explanation. The person on the line insisted that they wouldn't create an account without me signing up for it, but I didn't have to sign up; it was already in place.

The mail I received started out "As a customer of Network Solutions or one of our Premier Program members", so I'm not sure if they're doing this for everyone or just for people who bought their domains through some of the big providers like Pair who are part of the "Premier Program". If you get the e-mail from them, I suggest logging on immediately and changing your password, whether you wanted the account or not. Maybe with a little prodding, Network Solutions will realize they screwed up and delete the accounts and change their procedure.

Update posted 2:10 p.m. EDT by RM - doulos writes "If your tired of getting a busy signal at the 703-... phone number, I found that they have a nice staff of people waiting to answer your questions and complaints at the following TOLL FREE phone number: 1-888-642-9675

They did refer me to the toll-line, but I (politely) insisted that because this was a matter of security that they had initiated, that I should be able to at least speak with a supervisor. They nice person on the phone _politely_ complied, and I was able to put in my request to have those e-mail accounts removed with my appropriate domains.

I just thought I would submit this as an article update because I felt maybe if the phone # was posted as an update it might help alieve some of the offense of having to call, by at least removing the toll from being on your nickel..."

176 of 245 comments (clear)

  1. However much you may hate XXXX corp. by anthonyclark · · Score: 3

    OK,

    However much you may hate XXXX corp DO NOT try and masquerade as them!

    It's not big, clever or AFAIK legal.

    What may seem as a good idea right now may land you/us/everyone in the world in a whole heap of trouble.

    --
    ----- Documentation is worth it just to be able to answer all your mail with 'RTFM' - Alan Cox.
    1. Re:However much you may hate XXXX corp. by Navarre · · Score: 1

      So, if NSI is so freakin' useless, and I hear a lot of people say that they are, then why do they hold a monopoly on dealing out domain names?

      They ignore their own spamming and nearly get blacklisted.

      They make a security blunder and 10-year old with a couple of computer classes in school wouldn't make.

      Why can't I go somewhere else for my service? This might be a naive question, but somebody humour me and explain this, please.

      Mike

    2. Re:However much you may hate XXXX corp. by .pentai. · · Score: 1

      They don't hold a monopoly.

      There are other places with which to get domainnames...the place I work at is soon going to become a registrar (hopefully).

    3. Re:However much you may hate XXXX corp. by Ticker · · Score: 1
      better would it be to throw pies than to risk being sued!

      How come you talk like yoda?

    4. Re:However much you may hate XXXX corp. by fwr · · Score: 2

      It's my understanding that they do hold a monopoly. When the "new" companies are able to register new domain names, they pass the information to Network Solutions who will still be in "control" of the root name servers and maintaining them, right? I personally believe that this qualifies as a monopoly.

      Why doesn't our (USA) government take the monopoly away and assign it to another company? Can't be all that hard to transfer control of a bunch of root domain servers over to another company, can it?

  2. Kinda makes you wonder... by LordChaos · · Score: 4

    What kind of programmer can create an entire web based email system, write the code, and bring the whole system to working order, and then ignore one of the basic principles of password choice that has been a major no-no in the un*x (and other) operating system for decades.
    Mind you I guess it's not surprising when we consider the other screw ups we've seen lately - even in other web based email systems like the recent hotmail scare.
    All we can do is hope that they will be a learning experience for us all, and that screw ups in the "early" days of the internet for the masses will prevent (or at least lessen the effect of) major security holes in future systems..

  3. Oh dear by Palin+Majere · · Score: 4

    First they produce copyright restrictions in whois queries that people cannot opt out of. Then they fight tooth and nail with government regulators over divvying up their monopoly. Now this?

    What's next, my bank creating an email account for me and assigning it the password 123456, like everyone else's?

    Just imagine the possibilities of such a monumental foul-up:

    -) Email Masquerading:
    "Hi InterNic Tech Support, this is so-and-so, I'd like my contact information changed to... No, I'm really so-and-so. You can tell because I'm emailing you from so-and-so's account..."

    -) Spam, Spam, Spam, Spamitty-Spam:
    "You've got mail! Oh joy, so-and-so@internic is spamming me. Lets get them blacklisted and ban their server."

    -) Misrepresentation via Email:
    With this, and some of the information available from a standard whois query, you easily order products and have them shipped to someone COD. And of course, it's authentic because it was shipped from your internic account....

    Someone stop the madness before it continues to spread!

    1. Re:Oh dear by Black+Parrot · · Score: 1

      > Spam, Spam, Spam, Spamitty-Spam:

      Just use the account to spam Network Solutions, and maybe they'll revoke your account!

      --
      Sheesh, evil *and* a jerk. -- Jade
    2. Re:Oh dear by Anonymous Coward · · Score: 1

      A bank in Norway actually did the equivalent of this, the only difference was that it was worse. It decided to change all pin codes for all its customers to its netbank system. That by itself is bad. But it got worse. They made the new pin code directly from the customer's date of birth (not social security code, just the birthday). Then they sent (snail) mails to all its customers, informing them about how nice the bank has been to them. Result: Anybody who received a mail like that instantly knew the pin code to any other customer for which the birthdate was known or could be made known. Not particularly hard, that. And of course any customer not at home at the moment (say, on a four week vacation for example) would come home and find that the netbank account had been open for the world the last weeks.

  4. Could not get in by lee · · Score: 1

    Either my company's email boxes have not been created, do not use the stupid password, or someone has logged in and changed them.

    --
    --- If you don't want to know the answer, don't ask the question.
  5. Will this piss off enough people to get NSI sued? by Myself · · Score: 1

    Okay this has way too much potential. How long is it going to take them to clean up the aftermath? I see another mess of legal battles over this one, and maybe because it's so prominent, we might see some penalties for boneheaded admins like this one. (Oh please, oh please, oh please? We need a legal precedent that makes "blatant neglect" a crime.. heh)

  6. Can you say ... by Ummon · · Score: 1

    ... class-action lawsuit?

    Who wants to keep track of how much time is lost due to this?

    Anyone know how I can figure out what other accounts I might have?

  7. Bah! by ninjaz · · Score: 1

    Just when you thought you'd seen it all, NSI sinks to a new low! I just noticed a name I control affected, too. It appears that they may still be in the process of rolling this out, as the oldest domain got this account, but the others haven't (yet, at least).

    Also, I think it's disturbing that something important as control of your domain name is left wide open by only offering cleartext passwords. i.e, even if you *do* log in and change your password, it can be seen in transit and your name can still get hijacked.

    I think this is a demonstration of NSI's utter incompetence/unwillingness to take due dilligence and that their contract should be terminated.

    1. Re:Bah! by ninjaz · · Score: 1
      Lest I become a source of misinformation, I'm correcting myself now:

      As far as I can tell, this doesn't directly compromise control of the domain name, just the cheesy webmail account. Of course, as others have stated, that may be an effective tool to help with social engineering..

      Anyway, I prefer to roll my own webmail service using Imp along with mod_ssl which doesn't require sending cleartext passwords over the net.

  8. Site appears to be down by Paul+Johnson · · Score: 1
    Sorry, I meant to say... I just followed the link given in the article, and I just get an instant blank page. It looks like Network Solutions have just pulled the service until they get it sorted.

    Paul.

    --
    You are lost in a twisty maze of little standards, all different.
  9. Hmmm... by Khan · · Score: 1

    Looks like it's either /.ed or their servers are offline while they fix this little "problem". .....Heh, I just made myself laugh pretty hard writing that last comment ;) This is truly unreal.

    --

    "Klaatu, verada, necktie!" -Ash

    1. Re:Hmmm... by Kintanon · · Score: 1

      Looks like it's either /.ed or their servers are offline while they fix this little "problem". .....Heh, I just made myself laugh pretty hard writing that last comment ;) This is truly unreal.

      Remember, this is NOT a 'problem'! This is the convenient 'Easy Password Recall' memory assistance system whereby you are no longer required to remember some obscure string of letters and numbers but can rely on a password so obvious that even if you forget it you can guess it in only a few tries! For more of our convenient new services contact us at NSI@FUBAR.NET!

      Kintanon

      --
      Check out JoshJitsu.info for Brazilian Ji
    2. Re:Hmmm... by 47Ronin · · Score: 1

      Easy Password Recall? That concept should never have been thought up by these type of companies.. that's why most real computers ship with some sort of highlight-your-newly-created-password and "copy/paste" type of function. Get into your account with the freaky tongue-twister password then change it later to whatever you want.

      -----
      Linux user: if (nt == unstable) { switchTo.linux() }

      --
      Those who laugh at you for you having a Mac.. are the people who constantly call you to fix their PC.
  10. Personally.. by Kitsune+Sushi · · Score: 1

    If we can expect quality service like this because of it, I'm all for monopolies over services, products, whatever you got! Tell Uncle Sam to stick it.. Let those businesses continue to deliver the good stuff until it hurts!

    Warning: The views expressed in this message are not necessarily shared by the poster, Slashdot, or the free-thinking populace at large.

    --

    ~ Kish

    1. Re:Personally.. by Buttercup · · Score: 1

      Eh... perhaps you hadn't noticed, but Uncle Sam created NSI's monopoly in the first place. That's the way it usually happens.

      MJP

      --
      Don't try that "protecting the children" shit you people use to keep the tits and bad words off my TV. --Seanbaby
  11. Update by sgs · · Score: 4

    I just got the spam from NS, and it was a bit different than described. The account name was the administrator's last name with a random number added; not the domain name as described. The password was as described; the account name with "nsi" added to the end.

    A bit better; anyone trying to screw up somebody's account would have to know how to use WHOIS and guess a short number.

    Clueless. Utterly clueless. And these are the guys who claim to be running the Net??

    My password is now a random string that I've already forgotten. Why would I need another e-mail account anyway? Don't you have to have an e-mail address (contact point) to set up a domain name?

    1. Re:Update by KFury · · Score: 4
      > A bit better; anyone trying to screw up somebody's account would have to know how to use WHOIS and guess a short number.


      The number appended to the admins last name isn't random. If you do a whois lookup on yourself or your domain, you'll find this is actually your ns 'handle.' The number NS has appended to your last name (usually the entire last name, plus the uid), and is just as easy to obtain as any other piece of info you've registered.

    2. Re:Update by peter+hoffman · · Score: 1

      If this is true, then they have me confused with someone else because that number is not part of my handle!

      Just to make certain they hadn't assigned two handles to me, I did do a whois on the number I received and it returned information about someone else.

    3. Re:Update by drewbie · · Score: 1

      Well, I haven't even gotten the spam yet and the d**n account has been created for me! I logged in with the username "lastnamehandle" & password as described above and there was the mail interface! So go check and immediately change the password. And then never, ever go back again.

      Looks like I'll be checking out those alternative registrars quickly.

    4. Re:Update by fdicostanzo · · Score: 1

      no good- i got spam'd and i DID use an alternate registry. i don't think this would effect my domain however....

      --
      Synergies are basically awesome, and they're even better when you leverage them. -PA
    5. Re:Update by Carl+Nasal · · Score: 1

      The userid isn't random. AFAIK, it is the user's last name and a number (which is just an incremented number based on the number of the same last names).

      For example, mine is "nasal1". (I don't know of *any* of people with a last name of "Nasal", so that's why there is a 1 after it. For common names like "Jones", someone may get "jones50".)
      --
      ZZWeb.net Web Hosting - http://www.zzweb.net

      --
      ZZWeb.net Web Hosting - http://www.zzweb.net
      ZZWeb.com Internet Consulting - http://www.zzweb.com
    6. Re:Update by Emil+Brink · · Score: 1

      Your last name is Nasal? Wow! I don't mean any offense here, but you could probably make the folks over in comp.lang.c (Deja link) laugh themselves silly pretty easily. Just write a program doing something unspecified (letting main() return void is a classic), and see what happens. Oh, the joy of stupid word plays.

      --
      main(O){10<putchar(4^--O?77-(15&5128 >>4*O):10)&&main(2+O);}
    7. Re:Update by agshekeloh · · Score: 1

      A further update (someone might have posted this below my threshold; apologies if so)

      I received another NSI spam at 10:30 AM EDT, and it was also a bit different than described above.

      Specifically, it doesn't include the free email account.

      It does state that blackhelicopters.org has received a free listing in the new dotcom directory. I wonder what services we're supposed to sell? Perhaps people would pay to be able to launch Black Helicopters(tm, pat. pend.) on people of their choice? Sorry, off-topic.

      It also describes various domain registration bonus plans, and the "read our spam or else" threat.

      No password is included in the mail.

    8. Re:Update by vkire · · Score: 1
      The number appended to the admins last name isn't random. If you do a whois lookup on yourself or your domain, you'll find this is actually your ns 'handle.' The number NS has appended to your last name (usually the entire last name, plus the uid), and is just as easy to obtain as any other piece of info you've registered.

      This is clearly not true. I got the mail and it didn't have any numbers appended. My assumption is that they append numbers if they have more than one person with the same last name. Since my last name is pretty unique (only 5 families in the entire world, AFAIK, and I am the only one that owns a domain), I didn't get a number assigned.

      KV

    9. Re:Update by ct · · Score: 1

      Hate to burst your bubble, but there must be at least 1 other 'Nasal' before you - one without the digit after his ID (at least there is as of 20:03 MST)

    10. Re:Update by FModnar · · Score: 1

      Yep...there must be at least one other "nasal"

      My last name was just the last name....no numbers after it at all.

  12. Same story here by kechnng · · Score: 1

    Yep, same story - blank page. Either NSI have really taken it down or it's suffered the slashdot effect(tm) ;-)

  13. Re:Site appears to be down by shri · · Score: 1

    It's /.ed. Very ironic if you ask me. I managed to get through after about 15 reloads.

  14. Mailing out passwords by Tet · · Score: 3

    Am I the only one that thinks emailing out unsolicited passwords in plain text is a bad idea in the first place? Unencrypted email's not exactly the most secure way of transferring information. There may be times when I *request* a password via email, but I do so knowing and accepting the risks, and I wouldn't do it with something I couldn't afford to be compromised. Of course, the choice of password was dumb beyond belief as well, but that's a separate issue...

    --
    "The invisible and the non-existent look very much alike." -- Delos B. McKown
    1. Re:Mailing out passwords by GC · · Score: 1

      When I set up users to access our ftp server, the procedure is usually as follows:

      1. I get a verbal request from operations
      2. I tell operations to put it in writing
      3. The request comes in writing
      4. I generate a user ID & password generated by my random password generator
      5. The user id & password goes out to the user by tracked mail. (Snail Mail)

    2. Re:Mailing out passwords by deusx · · Score: 1

      Am I the only one that thinks emailing out unsolicited passwords in plain text is a bad idea in the first place?

      Man! Is this one of my biggest pet peeves! I can kinda understand it for a service that generates a password for me-- I need to log in real quick and change it. It's basically a one time password.

      But when I sign up, and PROVIDE a password, and STILL the service sends me an insecure e-mail with the password I JUST PICKED, it really pisses me off!

      Even worse, there was a site (I forget which one now) that I hadn't visited in awhile. So, I get spam from them saying, "Hi we haven't seen you around in awhile, in case you forgot, here's your username and password!"

      AAAAUUUGGGHHH!!

  15. New Advertising slogan? by Jonny+Royale · · Score: 4

    Network Solutions...we're the "duh" in dot com!

    1. Re:New Advertising slogan? by adric · · Score: 1
      Network Solutions...we're the "duh" in dot com!
      Nah. More like we're the "duh" in stupenduhs (and yes, I know it's not really spelled that way :-)
      ---
      --
      not plane, nor bird, nor even frog...
    2. Re:New Advertising slogan? by pod · · Score: 1

      uhm, stupendous maybe?

      --
      "Hot lesbian witches! It's fucking genius!"
  16. what am I missing? by eff · · Score: 5

    If someone beats you to your account and "guesses" your password, now they can masquerade as you, and if they change the password, you can't even get into the account

    I'm probably just extremely dense, but isn't dotcommail just yet another free mail service?

    do you really think people are stupid enough to think that a mail from 'slashdot@dotcomnow.com' (or 'slashdot@hotmail.com' which I just grabbed) must necessarily come from someone working for slashdot?

    if that's the case, we're in deep trouble. there are hundreds of free mail services out there...

    1. Re:what am I missing? by akey · · Score: 2

      do you really think people are stupid enough to think that a mail from 'slashdot@dotcomnow.com' (or 'slashdot@hotmail.com' which I just grabbed) must necessarily come from someone working for slashdot?

      You're most likely correct that most people will not believe that mail coming from slashdot@hotmail.com is from the /. staff, but if even 1% of people believe it, it can mean trouble. What if you had a large commercial domain, and someone hijacked your "free" email account, and sent out a few hundrew thousand pieces of insulting, obscene, misleading (or worse) e-mail. You'll spend a large amount of time and money trying to repair the damage. Sure, only a few hundred people truly believed it, but you've got to send emails to all of them, post an apology to your web site, etc.

      For a competitor, this could be a real easy way to generate bad publicity...

      --

      ---
      "Go Metallica. Die RIAA." -- Linus Torvalds
    2. Re:what am I missing? by drix · · Score: 2

      I can send mail to people that's obscene, insulting, misleading - whatever - under the name 'slashdot@hotmail.com' right now and I always will be able to. Sendmail has no authentication to determine if the from address you're telling it is really who you are (duh). Instead of slashdot@hotmail.com, I could send two million e-mails marked "From: clinton@whitehouse.gov". And guess what? Those same one percent who you mentioned will be the people who actually believe it.

      Bottom line, the ability to recieve mail under a domain, in all but a few exceptions, is not the be-all end-all of security breaches. The only people who would be fooled by this aren't going to take the time to reply back; they're going to take it at face value.

      Hotmail was a security breach. This is stupidity, but on a far more minute level.

      --

      I think there is a world market for maybe five personal web logs.
    3. Re:what am I missing? by Anonymous Coward · · Score: 2

      I think the big danger is that 2 weeks from now a few thousand people who don't read Slashdot and who never think about password security will be out there using their spiffy new mail account that NSI was nice enough to sign them up for, and they won't change the password. Someone will notice their address in a newsgroup, on a mailing list or web page, and say "hey I'd like to read all their mail, and they have that handy dotcommail address so I know their password!". So yeah, I think the article stated the real danger wrong, stealing a brand new account isn't so hot, but stealing one in afew weeks when mail is coming in, that's a real problem.

    4. Re:what am I missing? by Reject · · Score: 1

      The problem (as far as I can tell) is that since NSI were "nice" enough to setup the account for you, and set up the password, they'll assume that it's you coming from that account. Because of that, and the fact that it's so easy for someone to steal the account, someone can just steal your free email account, then pose as you in an email to NSI and have whatever they want done to your domain. That makes it incredibly easy to steal a domain in my eye.

      Then, maybe I'm totally wrong. I might not be giving them enough credit. I'm also not a security expert, so there may be some other totally different problem(s). This is just what's wrong as I can see it.

      --
      Reject

      --

      --
      Reject
      reject@metaphorcity dot com
  17. Wait a second... are we reacting too hastily? by shri · · Score: 5

    I took a look at this story and hurried over to the NSI website and the account I use to register some domains to check this out. Nothing.

    I am glad there was nothing, no dotcomnow account that I can think of and no email with my nice little present from Netsol. If there was, I guess I might have joined in the frenzy here.

    This got me thinking about what the "security hole" is.

    a) That account cannot be used to change my domain parameters, since it does not match the e-mail address I registered from.
    b) Anyone can really set up an account on one of thousands of webmail providers and pretend to be me. Heck, this has happened to me before on some discussion groups, and there is simply nothing I can do to prevent someone from misrepresenting me to lusers. People who know me know where my e-mail comes from, and know I use digital signatures.
    c) How is this different from your friendly bank sending you a credit card without your approval? Infact that is something which I consider more dangerous than this act of stupidity by Netsol.

    Having said this, I seriously think we're over reacting.

    Shri -- returning to the scheduled Typhoon York.

    1. Re:Wait a second... are we reacting too hastily? by EJB · · Score: 1

      Well because it is NSI's e-mail service and the account is your nic-handle, it looks more official than just another e-mail service.

      And second, (I don't know how it is in the states these days) but a bank sending unwanted credit cards causes quite an outrage here in the Netherlands.

      A big organization tried this with its members, trying to force the terms of the credit card company (with regards to abuse, etc.) on their members, and because of the outrage they had to change it such that those terms would only go into effect after the first authorized use of the credit card.

      So yes, I agree with your c), it's just as bad as sending an unwanted credit card, and I think that's pretty bad.

      EjB

  18. You can change your password by MikeA · · Score: 1

    Go to http://mail.dotcomnow.com and click on preferences. You can change your password from there.

  19. Re:Site appears to be down by sorphin · · Score: 1

    it's moments like this that i decided to drop NSI and register my current domain with one of the other registrars.. i.e. register.com and the like.. they atleast appear to have more than a clue than NSI does, unfortunately, people still use 'whois' to look up a domain, and since that only looks at NSI by default, well, makes life harder... but i'm not surprised that NSI would do something this dumb... i tried 6 times to get them just to change my CONTACT INFO, and oops.. sorry, we lost your pgp key, (and since i can't mail from the email in my contact info anymore.. too bad), thank god i don't hold any domains with them now..

  20. NSI/Slashdot Conspiracy Theory by kaiti · · Score: 1

    Hrm, has the thought occured to anyone that by alarming all of us slashdotters to this not-so-important security hole that the hype and alarm of this story rushes each and every one of us to _GIVE NSI A PASSWORD_. Most folks dont believe in smart passwords. Most folks use the same password everywhere.

    You may have just given NSI more power then they deserve.

    Wouldn't you just love to be a corrupted employee working for dot com mail?

    Just think... if you were, you'd have passwords to hundreds of thousands of root accounts, etc.

    God, what the hell were you guys thinking doing this. Big whoop. Spank NSI.

    But realize that this is a double edged sword.

    -krs

    --
    :: :: krs. ::
    1. Re:NSI/Slashdot Conspiracy Theory by ptomblin · · Score: 2

      Since I don't *want* another damn free email account, but I don't want anybody else to have it either, I intend to change the password to some random string of characters and then promptly forget it.

      --
      The next Cmdr Taco duplicate will be ready soon, but subscribers can beat the rush and see it early!
    2. Re:NSI/Slashdot Conspiracy Theory by kaiti · · Score: 1

      Yes, but in my opinion, the hype caused by the "security threat" announcement psychologically will trigger people to want to "claim ownership" of those domains. Think about it.

      -krs

      --
      :: :: krs. ::
    3. Re:NSI/Slashdot Conspiracy Theory by Psiren · · Score: 1

      Anyone using a root password on the web is a moron in the fisrt place. Not likely to happen is it.

    4. Re:NSI/Slashdot Conspiracy Theory by hucke · · Score: 1
      Most folks use the same password everywhere. Just think... if you were, you'd have passwords to hundreds of thousands of root accounts, etc.

      I would hope no slashdotters would be foolish enough to do that.

      I've changed the password for "my" account and for those of the Fortune 100 company I work for to such things as "idiots.nsi", "nsi-criminals", etc.

      (I also got into "amazon", "bn", and "msn", but don't want to be seen as trying to "take" those accounts... they're available right now if anyone wants them!)

    5. Re:NSI/Slashdot Conspiracy Theory by Greg+W. · · Score: 1

      Anyone using a root password on the web is a moron in the fisrt place. Not likely to happen is it.

      Oh, no. Of course not. There are no morons on the web. No, everyone using the web is a long-time Unix hacker, with a background in practical security administration and cryptology. So this won't cause any problems at all.

      </sarcasm>

    6. Re:NSI/Slashdot Conspiracy Theory by Amphigory · · Score: 1

      Yeap... fsckyounsi is my password :)

      --
      -- Slashdot sucks.
    7. Re:NSI/Slashdot Conspiracy Theory by Amphigory · · Score: 1

      Yeap... fsckyounsi is my password :) Of course I'll now have to change it again

      --
      -- Slashdot sucks.
    8. Re:NSI/Slashdot Conspiracy Theory by thekla · · Score: 1
      Are you suggesting there are people who'd use their root passwd for a free web-based mail service login? They ought to be found and shot if they exist.


      Nick Moraitakis

      --
      -- say with me: i'm a monkey child
    9. Re:NSI/Slashdot Conspiracy Theory by thekla · · Score: 1
      I would hope no slashdotters would be foolish enough to do that.

      I've changed the password for "my" account and for those of the Fortune 100 company I work for to such things as "idiots.nsi", "nsi-criminals", etc.

      You spent the time to change the passwords and now you tell everybody in /. some general directions (illustrated with examples) on how to guess the new ones? Cool!

      Nick Moraitakis

      --
      -- say with me: i'm a monkey child
  21. Re:Weird... by barbaBob · · Score: 1

    If it works like that; what's the domain id for 'etrade.net' or 'etrade.org'?

    More likely is indeed the last name of the administrative contact. I've already found several that work that way :(

    Good luck...

    barbaBob

    --

    --
    *sig*

  22. BTW: it's not for everyone by cjsteele · · Score: 2

    I tried this particular little 'trick' with a random domain, and there was no 'account'. SO, they must be being selective ass holes. -C

    --
    "This above all, to thine own self be true" :x!
    1. Re:BTW: it's not for everyone by Christopher+Cashell · · Score: 1

      I'd have to guess they just hadn't gotten to the one that you checked.

      I happen to be a certifiable 'nobody' and I got this e-mail to. However, as yet, I've been unable to get to Network Solution's site, the connection is timing out.

      Looks like they're prolly getting nailed with a less than pleasant response. Well deserved, however. When I signed up for a domain name, I *never* opted in to recieve any spam, advertisements, or security hole ridden web based e-mail crap.

      I used to like InterNIC and Network Solutions, of course, that was a few years ago now. Back before they were losing their monopoly and acting like spoiled children about it.

      What a shame.

      --
      Topher
  23. We probably are, but... by barbaBob · · Score: 3

    We probably are reacting a bit over the top, but the scary part is that at least three of the 'lastname' and 'lastnamensi' get me into someone elses e-mail account.

    You're right about there not being a real security at the moment. Only people who used their Dot Com Mail address as their contact's e-mail address will be at risk of losing control of their domain, since most of them use 'MAIL-FROM' as their authentication method for authorizing changes to their domain registration.

    It does make me think about advertising ourselves as a 'Network Solutions Partner' though. But then again, I doubt that you'd be really better off with any of the other TLD registrars.

    Cya
    barbaBob

    --

    --
    *sig*

    1. Re:We probably are, but... by shri · · Score: 1

      I agree. The least they could have done would have been to add some sort of verified activation.

      Go to this URL and activate your account. On activation the password would be sent to the e-mail in your contact info.

      BAD security. But not a major concern for now. Unless they have updated your NSI contact info to your new e-mail addr ;-)

  24. Password mailing. by malkavian · · Score: 1

    Wow...
    I'm impressed... It's been a while since I saw a monumental cockup like that (well, since the hotmail affair anyway).
    I'm sure that a couple of minutes adding a check with cracklib wouldn't have gone amiss, or just adding in a random password generator..
    I wonder.. Do these people have a QC department, to make sure that the code they release is robust?
    Or is a building of PHBs with a lone coder stuck in a cabinet somewhere and let out to be fed and watered every now and then..
    For a large company with huge resources at their disposal, there's no excuse for not checking their functionality a hundred times before release... Especially as this is supposed to be their core business!!!
    I'd love to see their PR dept. right now.. :)

  25. Re:Is USA.Net effected by this? by blue · · Score: 1

    No. NetAddress has nothing to do with Network Solutions, and that fiasco is something else in itself. Mine works.

  26. Even more annoying to me was... by scenic · · Score: 1
    this little gem at the bottom:

    If you do not wish to receive e-mail from Network Solutions, click on this e-mail address and type "remove" in the subject line. PLEASE NOTE: by opting to be removed from this list we will not be able to communicate to you, in real-time, on issues regarding your account.

    So basically, if I don't want stupid emails like this, I have to give up "real-time" communication from NSI about my account? That sounds kind of stupid, don't you think?

    Sujal

    --

    politics, food, music, life: FatMixx

    1. Re:Even more annoying to me was... by earlytime · · Score: 1

      this is exctly why I registered my domain with register.com, NSI is a fscking horrible company. I never get mail from register.com, nevermind spam. Also, I've found that register.com's web interface to domain administration is *far* bettter than the e-mail crap that NSI has set up for their domain admin process. Not to say that register.com is perfect, I've had my problems, but NSI is orders of magnitude worse.
      -earl

      --

  27. PARC Lemmings at Network Solutions by Effugas · · Score: 5

    OK, gotta get the music to that strangely addictive game out of my head now.

    Check out this piece of wholesome goodness, delivered in the same message as my (cleartext) domain hijacking password:

    If you do not wish to receive e-mail from Network Solutions, click on this
    +e-mail address and type "remove" in the
    +subject line.
    PLEASE NOTE: by opting to be removed from this list we will not be able to
    +communicate to you, in real-time, on issues regarding your account.


    The mind boggles. One of the primary aspects of the net's formative power is its ability to quickly report the consensus of a company's customer base. Emails such as the one recently sent to all domain owners--containing both an unprecedented security breach and a jaw-dropping amount of arrogance(read our spam or we lose your bill)--only serve to increase internal communication within NSI's customer base, and to erode and eliminate the trust that the company has built up over the years.

    I am positive there are alot of others out there like myself who hold a great deal of technical respect for their extremely high-uptime management of the closest thing we have to a single point of failure. They've done much right, and honestly, they've scaled better than one might have expected considering their ever increasing workload and the sheer number of years they've been doing their job.

    I almost see a parallel to Microsoft here. People complain that the Windows 9x kernel is buggy, but considering that it runs everything from ancient DOS games to 32 bit applications, it's a miracle it runs at all. There's some truly respectable hackery involved in that! However, nobody, not even Microsoft's staunchest allies will say that their businesspeople are the most ethical in the industry, and most of the industry will claim that the Microsoft businessdroids have even less faith in their coders than the Linux bigots.

    Why else fudge the numbers and force the shipments? Nobody's going to run Internet Explorer unless they're forced to...so lets force 'em. That seems to be the mindset.

    Similarly, the Network Solutions folks have pulled off some significant technical miracles, but their business side is obsessed with the concept that nobody cares about anything technical. Since nobody would use NSI if they had an alternative registrar, the quality and quantity of alternatives must be fought tooth and nail. Since NSI is nothing but its collection of names and addresses retrieved under contract from the federal government, they'll claim de facto ownership of the WHOIS database until the Commerce Department's gun is pointed at their head with the hammer cocked.

    Nobody cares about name resolution, you see. The real fad is WEB BASED EMAIL; create accounts for people without even following basic security procedures!

    Nobody would actually want any of the services offered by NSI through email, so issue a vague threat to cut off all email--even that which is critical to the operation of one's domain--unless the domain owner agrees to sift through the latest thing being hawked by NSI.

    The more NSI does in this style, the more they disenchant, disenfranchise, and disconnect themselves from their customer base.

    There's no logical reason for this to occur.

    I call all of this the PARC Lemming Syndrome. Every hi-tech businessperson secretly(or not-so-secretly) laments that he or she wasn't there at Xerox PARC to bring all of those amazingly profitable inventions to market. The agony of imagining so many lost dollars causes them to try to milk whatever or wherever they're at without due concern for what this will actually do to the businesses Core Competency.

    To the businessperson...maybe he's breaking loose, pulling ahead of the pack, about to lift off, ascend to new hights...or maybe she's in the middle of a herd, trailblazing, secure in the knowledge that together new possibilities are being forged.

    The the customers, and the rest of us...just looks like a bunch of lemmings racing headlong towards a cliff.

    I implore you, Network Solutions. Buy a clue. Get a twelve pack if needed. Your customers trust you because your uptime is unbeatable, your security is generally reasonably tight, and because you've been doing it right longer than anyone else in the business. I'm one of your customers. Before you tell me anything, offer me anything, or do anything, think of why I do business with you, and about what could make me stop.

    Don't be a lemming!

    Yours Truly,

    Dan Kaminsky
    DoxPara Research
    http://www.doxpara.com


    Once you pull the pin, Mr. Grenade is no longer your friend.

  28. Incredible. Even for NSI. by Bob+Ince · · Score: 2

    This is frankly amazing. Not only that such a large, allegedly net-savvy company could make an elementary security blunder(*), but that they even thought to was a viable business plan.

    After all, all existing domain holders already have valid contact addresses(**) and don't need another poxy webmail account. They're also likely to be the kind of net users who'd not use webmail for importantish stuff. Maybe they just wanted to be able to claim X current users to advertisers, whilst not telling them none of the actually use the service.

    Just glad they don't seem to have included any domains I'm involved in...

    (*) Hey! Has anyone tried to get root at NSI using the password 'nsinsi' or something?

    (**) Except for the spammers, obv. Maybe NSI were aiming the service at spammers. That would certainly fit their modus operandi.


    --
    1. Re:Incredible. Even for NSI. by Blrfl · · Score: 1

      Where ever did you get the silly idea that NSI was a large company?

  29. Still works.. by seeken · · Score: 1

    So i went and changed the PW for the doms I manage- and I made a mistake... I got the email, it said xxxxx4 for user, and I jusr type xxxxx, so I accidentally changed the wrong password! D'oh!

    friggan turds.



    Surfing the net and other cliches...

    --

    Surfing the net and other cliches...
    (Who Meta-Meta-Moderates the Meta-Moderators?)
  30. works by Overkill · · Score: 1

    Bahahahaha
    I just sucessfully picked 3 random names
    and added nsi to the end for the password and it actually let me log in=P

    The stupidity of some people...

    1. Re:works by Zedzded · · Score: 1

      Still works, I picked random 3 bigbig websites, haven't changed a thing though, it's too easy. Zed

  31. Re:Is USA.Net effected by this? by Zedzded · · Score: 1

    I had the problem, now it is fixed. It's some other glitch, apparently. Zed

  32. Imagine what that poor webmaster thought... by Brento · · Score: 2

    I can just see that moron sitting in his office now.

    "Hey, look! My new e-mail service is getting tons of hits! Wow, it's only been available for a few hours, and everyone is logging in with their new accounts! Unbelievable! I'm going to be a huge success! I'll be on the cover of Fortune. Hotmail, move over, baby." (sound of smacking lips)

    So let's all contribute to his trumped-up feeling of greatness. I'm logging in with every name I can find (someone else's, of course) and sending congratulatory e-mails to webmaster@dotcomnow.com about what a wonderful service this is, blah blah blah.

    FYI, http://mail.dotcomnow.com still works, even though the original URL sent out in the e-mail is /.ed.

    And before you try it, I've already snatched clinton, lewinsky, and elvis. Heh heh heh....

    --
    What's your damage, Heather?
    1. Re:Imagine what that poor webmaster thought... by mwalker · · Score: 1

      Woop! I just got "slashdot@nsimail.com"!
      Also, hats off to whoever got "root@nsimail.com",
      you beat me to it.

      I must be the "damn" in dot com.

      Whoever got root@nsimail could have some real fun...

      to: webmaster@www.microsoft.com
      from: root@nsimail.com
      Subject: Domain termination
      -------
      Your domain name, registered with us on August 15,
      1985, "microsoft.com", is being terminated
      immediately by NSI. Please call our technical
      support line with any questions you may have.

      -Bob Johnson, NSI tech support.

      -----
      seriously, don't do anything like this.
      at least, unless you're sure no one can trace you.
      (;

  33. No SSL either by Anonymous Coward · · Score: 1

    Also, the login screen is completely insecure! No SSL or anything. Atleast hotmail passwords don't go over the net as plaintext!

  34. Only customers inside the US of A? by barbaBob · · Score: 1

    Can't make it work with contacts outside the US of A. All the last names that work are from people that live inside the US. Guess I am lucky after all ;)

    barbaBob

    --

    --
    *sig*

    1. Re:Only customers inside the US of A? by Paul+Johnson · · Score: 1
      My UK-based employer has now grabbed its free mailbox, so non USAians had better look out too.

      Thanks, Slashdot. This has given me the chance to look good in front of some pretty senior people here.

      Paul.

      --
      You are lost in a twisty maze of little standards, all different.
  35. Not at all surprised.... by yorkie · · Score: 5

    What has happened to the IT industry? Quite simply too many clueless people are being employed, usually hired by equally if not more clueless management.

    I've seen networks brought to their knees entiely due to management making decisions on the network topology. I have seen distributed networks fail due to a management descision to consolidate all logins to one single server! (Doh!) I have spent hours trying to bring dead systems back to life because no one bothered to maintain or monitor the system for 7 years, hoping the system would look after itself, and once I got it working the machine suffered a catastrophic hardware failure, and no more spares were avaialble world wide. And it goes on...

    The most ironic thing is that earlier this year I spent 4 months out of work. For every single interview, the decision rested on someone with no technical experience. I've found a position now, but it is 200 miles from home, and half the team I have to work don't deserve their position.

    There are too many fools in this industry making decisions. No wonder NT is so bloody popular.

    The moron who thought of this, and the bozo who hired him should never be allowed to touch a keyboard again.

  36. NSI - Best security of all by MobyDisk · · Score: 3

    NSI has subscribed to the bes possible security flaw of all - The Slashdot effect. Now that they are hosed, noone can get to their accounts! (At least I cannot seem to get in - timeouts on the site galore)

  37. Prepay for a domain name??? by whirlycott · · Score: 1

    Well, in all the fuss, did anybody miss the part in the famed NetSol email saying that as of Sept. 18th, we have to start paying for domain names in full at the time of registration??? How much does that suck?

    1. Re:Prepay for a domain name??? by MR_URC · · Score: 2

      But it is completely understandable, since they can't seem to get around to mailing their bills. I asked to be billed by mail and had to pay on the website the day before the bill was due. I never got a bill by mail. I got a receipt for my payment within a week, though. With 30 days to get a bill to me, you think someone might have actually sent a bill before the due date. Several domains that were registered with my last place of employment were cancelled due to lack of payment. The bills were never received.

      Forcing online billing is their way of saying that they can't do their own accounting.

  38. Another Potential problem with security.... by Lantheaume · · Score: 1

    So, I checked out the the dotcom directory and it looks like you can change anyone's information. If you go to "Update Your Listing" search for a domain. They give you all the fields to update and say that they will call you to verify. BUT then they give you a box to enter in alternate contact information.

    My guess is all you would have to do is change things put in a fake name, verify it when they call you and your all set.

    Okay, so it's not critical information. But some people might be depending on this engine to find information about companies. Network Solutions is supposed to be a reputable company.

    I'm still waiting for my phone call to see what they use to verify I have permission to change a companies information.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~

    --
    How many surrealists does it take to screw in a lightbulb?
    Fish.
  39. heads up by jsm2 · · Score: 2

    very good post, and people should read the essay linked to. Just one point to save you some trouble later:

    The phrase "Core Competency" is a [tm] trademark of Gary Hamel, a management science professor at the London Business School. He's a cool enough guy (I know him), and doesn't usually get heavy over the fact. But he makes his living out of going round talking to companies as "the Core Competency[tm] guy". So he's a bit touchy if anyone else tries to pass themselves off. And sometimes he feels obliged to defend his trademark in order to stop it passing into the public domain ("use it or lose it")

    I'm not sure what your firm DoxPara Research does, but if you're planning on using the phrase "Core Competency" in a consulting context, you might want to send ghamelATlbsDOTacDOTuk a message, just to keep everything above board.

    Me, I'd say screw it, trademark law's a crock and the thing's probably gone public domain anyway by now. But the information can't make you poorer.

    this free business advice brought to you by

    jsm

    1. Re:heads up by sphealey · · Score: 1

      "The phrase "Core Competency" is a [tm] trademark of Gary Hamel, a management science professor at the London Business School. He's a cool enough guy (I know him), and doesn't usually get heavy over the fact"

      Good luck. I have seen that phrase used at least 10,000 times over the last six years [yes, I was on the dark side in an MBA program], in widely distributed business journals and mass market publications, without attribution or a trademark reference. IANAL, but I think he would have a hard time bringing a case against anyone based on the widespread public use of the phrase.

      sPh

    2. Re:heads up by Effugas · · Score: 2

      The phrase "Core Competency" is a [tm] trademark of Gary Hamel, a management science professor at the London Business School.

      Did he come up with the concept that I named my paper after? Hurm, after I clean it up a bit(some significant alterations are in order after that rather interesting session I had at LWCE), I may toss the paper over to him for evaluation.

      The term is reasonably public domain(hell, I've heard of it), but if he's the inventor of the field of thinking, it would behoove me to understand a bit more of what his theories are.

      (For those who are wondering WTF all this is about--Core Competencies is an essay regarding the economics of Open Source. I brought it up when discussing the diseconomic meanderings of everybody's favorite registrar.)

      Yours Truly,

      Dan Kaminsky
      DoxPara Research
      http://www.doxpara.com


      Once you pull the pin, Mr. Grenade is no longer your friend.

    3. Re:heads up by jsm2 · · Score: 1

      yup, he did. The ref is

      Prahalad, C.K.; and Hamel, Gary. "The Core Competence of the Corporation." Harvard Business Review, May-June 1990, pp. 79-91.. He's got a book out with a similar title (in an airport bookshop near you), but I doubt it adds much to the article.

      I agree that the [tm] is probably fscked through common usage, although I'll mention that an MBA-dude would have been more likely to hear it without the [tm], as he has given blanket license for its use in academic contexts.

      But he's a good guy, and I bet he'd be very receptive to your paper (particularly if the Open Source/Core Competency nexus might add new fields to his consulting empire).

      Have fun.

      jsm

      (good old google shows I'm not just making this up)

    4. Re:heads up by Effugas · · Score: 2

      (Sorry all for the public post. I don't have JSM2's private email.)

      I attempted to email Gary, but the message was returned. Could you verify his address and contact me? I'd like to contact him, per your suggestion.

      I checked google--yeah, this guy very likely would be interested in the software impacts of much of his economic theories. Particularly with the business model evolution I need to work on involving the future of software development--his input would definitely be appreciated.

      Thanks!

      Yours Truly,

      Dan Kaminsky
      DoxPara Research
      http://www.doxpara.com



      Once you pull the pin, Mr. Grenade is no longer your friend.

  40. Now I'm really scared... by Cort_Tompkins · · Score: 1

    I just changed the password for my own personal domain, but that got me thinking and I tried to guess the login/password for the domains of my customers.

    Nearly every single one of them has ended in the digits 57. Within a few minutes of picking common names and numbers around 57, I was able to log in to dozens of accounts. It was hard to resist the temptation to commandeer account gates57 =)

  41. No, this reflects on NSI's security as a (w)hole by Brento · · Score: 2

    I don't think we're overreacting. I think it's disturbing when someone so big does something so stupid. Think about how much we rely on this company for our day-to-day services, and how tough their security should be. They should have extremely stringent standards.

    Someone assigned every single account the same password, in essence. This violates so many common sense rules that it's amazing: easy-to-guess user names, standard passwords, passwords sent out in regular e-mail, no authentication process, yadda yadda yadda. I mean, I just logged on and snagged three major commercial sites, just to see if I could do it. I'm batting .666 so far .

    If I did something that stupid and assigned all my local office users with easy-to-guess passwords, it would be no big deal, because I'm small potatoes. But when a giant like NSI does it, it's insulting to all of us. None of us would make that mistake, and it's fair to say that most of us probably aren't getting paid whatever the NSI schmuck was.

    --
    What's your damage, Heather?
  42. This is 'webmaster@dotcomnow.com' talking! by barbaBob · · Score: 2

    Can't believe this. 'webmaster' is wide open as well. There's e-mail from 'clinton', 'elvis' and a few others.

    I changed the password. I'll mail it to postmaster@netsol.com later on. Jeez....

    --

    --
    *sig*

  43. Accept our SPAM or else! by quonsar · · Score: 1
    I also received the spam thismorning, and the part that really hacked me off (I was unaware until now of the security implication of the email account) is the end of it:

    If you do not wish to receive e-mail from Network Solutions, click on this e-mail address and type "remove" in the subject line. PLEASE NOTE: by opting to be removed from this list we will not be able to communicate to you, in real-time, on issues regarding your account.

    So by opting out of their spam, you are opting out of ANY communication from them at all regarding your domain(s).

    To paraphrase The Who, "Who the fuck are they????????

    Bite My Ziff, Davis!

    ======
    "Cyberspace scared me so bad I downloaded in my pants." --- Buddy Jellison

  44. Alternative registrars -- who are they? by Zigg · · Score: 4

    This is absolutely crazy, and I want it to be the last straw. I have been screwed over by NSI both personally and professionally now:

    1. I wanted to change the registrant name on zigg.com, which I registered years ago with a short-lived business of mine, to my own personal name, so I could dissolve the business. However, despite the fact that I sent them proof from the county that the business and myself were identical legal entities, they insisted that the change was a "domain transfer" and I'd have to reregister.
    2. For two weeks now I have spoken and e-mailed at least ten different people on another issue. I recently came in to work at a startup ISP. The domains were registered through their "Registration Plus" or "WorldNIC" or whatever the hell they wanted to call it -- and the host record handles have periods in them! None of the NSI forms will accept these bogus host handles, and nobody who I can get access to -- not even after the front-line drones got so confused by what I was patiently trying to explain to them that they gave me the supposed "priority" e-mail address (priority@networksolutions.com, for those who are interested; but it still takes days to answer) -- understands the problem. I think I'm going to have to settle for registering the hosts under new IPs.

    All in all, NSI has screwed me over again and again, and their callous disregard for professionals that need to get their jobs done by not even allowing me access to engineers (after repeated requests) to repair the aforementioned host handle problem is a load of bullshit.

    Now, to the thrust of this posting -- where can I find these so-called alternative registrars? Are they yet capable of freeing me from the shackles of NSI -- to the point of never having to email anyone at networksolutions.com again -- and still keep my .com, .org, and .net's?

    I sincerely hope that if they are not here now, that they arrive very soon. I have a lot of new business for them.

    1. Re:Alternative registrars -- who are they? by joost · · Score: 2

      where can I find these so-called alternative registrars?


      http://www.joker.com/
      (not a joke)

    2. Re:Alternative registrars -- who are they? by jamiemccarthy · · Score: 3
      The official list is at http://www.icann.org/registrar s/accredited-list.html.

      Register.com was the first. Joker.com is currently the cheapest (it's based in Germany but its English webpages are passable).

      Jamie McCarthy

      --

      Jamie McCarthy
      jamie.mccarthy.vg

    3. Re:Alternative registrars -- who are they? by Anonymous Coward · · Score: 1

      I have had excellent luck with register.com for two of my domain names. When my NSI domain name comes up for renewal I'll be moving it over to register.com. Not only is it easier to deal with register.com, but they offer free DNS and domain aliasing (unlike NSI). The only downside (if you can call it that) is that my domains do not show up in the Internic whois database.

  45. Way to deal with this... by sterno · · Score: 1
    By accident I have managed to find a way to prevent this webmail problem. If you set up your DNS so that that you have a server named like mail.domainname.tld the webmail thing does not work.

    When I tried to access my dot.com webmail (what a dorky name), I was told to go to mail.domainname.tld, which redirected me to my mailserver since I already register that machine name in my DNS settings.

    ---

    --
    This sig has been temporarily disconnected or is no longer in service
  46. Re:Update - Various ways by Anonymous Coward · · Score: 1

    So far, I've only been able to get into 2 domains using the admin's last name and admin's last name & nsi. I haven't found any domains or any of my domains where I could use admin last name & handle number.

  47. OH, and it gets worse... by irrelevant · · Score: 1

    Passwords are extremely guessable as they are limited in length as well with extra characters being ignored.

  48. Idiots by eyeball · · Score: 1

    This reminds me of when the New York-based phone company Nynex (now Bell Atlantic) sent out a mass mailing to /all/ their subscribers containing a phone card and the matching pin #. Needless to say, many cards fell into the wrong hands, and all hell broke loose...

    And people worry about electronic privacy. They should be more worried about gross ineptitude.

    --

    _______
    2B1ASK1
  49. Put your dotcomnow mail account to good use! :) by CoreDump · · Score: 1

    Okay,

    The link in the email is either /.'ed, they took it down, or it's another example of NSI icompetency. ( I suspect a combo of the first and last. :P )

    My username/password was not related to any of my NIC handles in any way. The password was the combo of 'username+nsi' which is truly awful as already noted here.

    You can go to http://mail.dotcomnow.com to access your account, so they definitely *haven't* taken the site down.

    I logged in, changed my password, set up the vacation message, and sent mail to NSI expressing my displeasure at this rather silly attempt to gain yet more business from me ( it ain't gonna happen. )

    So now, when they reply to my emails, they'll get my autoreply vacation message.

    Hrm... wonder if there are any autoresponders at NSI that I could mail from my wonderful new account... ( heh )

    --

    ---
    Segmentation Fault ( core dumped )

  50. Huh? (was Re:Way to deal with this...) by Zigg · · Score: 1

    Okay, I'm confused. I wasn't offered a new webmail address in my own domain. I was offered some idiotic "whatever@dotcomnow.com" address.

    If they had tried to pull something on redirecting mail on my domain at all, you can bet I would be down to Herndon (they are in Herndon, aren't they?) as fast as I could with an aluminum bat demanding to see the person who made that decision.

  51. You know what makes me MAD? by Amphigory · · Score: 1
    Take a look at this little tidbit at the bottom of their email:

    If you do not wish to receive e-mail from Network Solutions, click on this e-mail address and type "remove" in the subject line.
    PLEASE NOTE: by opting to be removed from this list we will not be able to communicate to you, in real-time, on issues regarding your account.


    As I read this, it means that if I choose not to get their spam, then they will not email me anything at all! Like "Your domain is being shut down". Now maybe that isn't really what they mean -- but if not they are deliberately making it sound like that's what they mean.

    I really, really, really resent this. Guys -- it is clear that Network Solutions and the domain name system in general is completely, totally out of control. I have been waiting 5 years for some reasonable new TLD's. Waiting, with no luck. All because of network solutions. I want these jerks out of business, and I think I know how.

    I think it's time to start our own DNS, a la alternic. If we could get participation from slashdot participants, we would probably cover 50% of the net. If we really agressively pushed it, we could probably get 90% coverage.

    *sigh* It would probably never work, but internic makes me mad.



    --
    -- Slashdot sucks.
    1. Re:You know what makes me MAD? by Zigg · · Score: 1

      You've got my vote and support -- I'll be your first customer, or employee if you need me. (-:

    2. Re:You know what makes me MAD? by .@. · · Score: 5
      I have been waiting 5 years for some reasonable new TLD's. Waiting, with no luck. All because of network solutions.

      Err...not true. The main reason no new gTLDs have been rolled out is that the Intellectual Property (IP) and Trademark (TM) interests are scared of cybersquatting, and refuse to pay what it would cost to police these new gTLDs for possible infringement. This is troublesome, because IP and TM law require the famous mark holder to bear the cost of protecting their marks. They want to shift that cost to the registry and/or registrar, who will of course pass it on to the domain name owner.

      They keep asking for things like unilateral, full, standardized, searchable access to all registrant data, enforced verifiable contact info, heavily restrictive and punitive Dispute Resolution Policies, etc.

      NetSol may suck, but in this instance, it's not NetSol that's creating the vacuum. It's the people who own famous names and marks, who keep pushing for more than anyone is willing to give. Net result: No new gTLDs.

      If you're concerned, stop whining and get involved. The ICANN Domain Name Service Organization is acting on these very issues right now.

      The Individual Domain Name Owners' Association is fighting to ensure things like equity in dispute resolution and protection of your personal information are present in the future worldwide DNS system.

      --
      .@.
  52. Server offline? by jps3 · · Score: 1

    Re: the NSI web-base email password fiasco

    Now, I can't even get online! The server must be down or just bogged by people trying to break in to the server. What a load of crud...

  53. Take a look at the headers, folks. by tracey · · Score: 1

    I just noticed that the email I got came from netsol1@INTEGRAM.ORG, which whois's to:

    INTEGRAM (INTEGRAM4-DOM)
    2730 Prosperity Ave.
    FAIRFAX, VA 22031
    US

    They don't seem to have much in common with NSI. their web address seems to be an empty directory (has the apache feel to it though).

    So, what gives with this?

    1. Re:Take a look at the headers, folks. by Ranger+Bob · · Score: 1

      Yep. You're right. Of course, this is a prime example of potential Internet-based masquerading...

      One more thing: didn't anybody consider that it's just as easy to go to any free-mail site and creat a bogus account for masq-ing as anyone (or any organization???)

      --
      "Widget choice makes me horny." -
    2. Re:Take a look at the headers, folks. by Wholeflaffer · · Score: 1

      Yeah, I looked them up, too. Interesting thing is the e-mail address listed for the main contact:
      [snip]
      Domain Name: INTEGRAM.ORG

      Administrative Contact:
      INTEGRAM (IN601-ORG) no.valid.email@WORLDNIC.NET
      703 849 1700
      Technical Contact, Zone Contact:
      Markle, Chad (CM3763) cmarkle@INTEGRAM1.COM
      703-849-1700 (FAX) 703-849-0056
      Billing Contact:
      INTEGRAM (IN601-ORG) no.valid.email@WORLDNIC.NET
      703 849 1700

      Record last updated on 03-Sep-99.
      Record created on 29-Mar-99.
      Database last updated on 15-Sep-99 05:06:04 EDT.
      [snip]
      (FYI - WorldNIC = Network Solutions)
      I wonder if I can get a "no.valid.email@" address on my registration?

      --
      Certified Microsoft Notworking Specialist
  54. reminds me of that 70's SNL skit... by Croaker · · Score: 1

    ...with Lily Tomlin as a spokeswoman for the phone company:

    "We'll sell your personal information if we feel like it. We'll privitize public information. We'll set up an e-mail account for you, without even asking, and make the password obvious. If you complain, we won't care. We don't have to. We're NSI."

    Scary thing is, back then it was comedy. Now, it's the truth.

    1. Re:reminds me of that 70's SNL skit... by poink · · Score: 1

      "Whoops, we just lost Peoria!"

  55. They seem to have shut it off now by Get+Behind+the+Mule · · Score: 1

    I just got the mail from NSI. There is no mention of a free Email account, and in fact there is no section 3.

  56. SIGH by Bud^- · · Score: 1

    Man, that would really suck for the person that admins > 100 domains, oh wait that is me ... sigh.

    Oh well, it's not like I have nothing to do anyways, I'm glad internic created me this account, it is a true service on there part.

    Now I can access my email from home, work and on the road ... oh wait I already do that via telnet->elm.

    What ever happened to the key concept in CS 101?
    KISS - Keep It Simple Stupid.

  57. These morons are in cahoots with MS by Oscarfish · · Score: 1
    Perhaps NSI and MS are working together on this one, and the "dot com mail" or whatever the hell it's called is based on the (cough) ultra-secure Hotmail code.

    This really sucks and I'm not renewing my domains with NSI ever again - when they expire I'll register with someone else and I'll lobby to have them put on the MAPS RBL if they spam me again.

    These f*ckers have screwed up before but this really takes the cake. I swear to God they've got to be working with MS on this!

    --

    --------

    Oscarfish.com: tropical fish with attitude. Way t

  58. Mail IDs are not by Handle... by Neurowiz · · Score: 1

    The Mail IDs are built via how many of last names there are, and then incrementing a number like so: If there were 3 Maldas, then there are 3 accounts:
    malda@...
    malda1@...
    malda2@...

    The password is that MailID & nsi.


    --

    --
    Neurowiz
  59. Another Jim Rutt $#^%#^ up by ConceptJunkie · · Score: 1

    You know I worked for a company (TEIR) that Jim Rutt pounded into the ground by hiring incompetent managers, making incredibly stupid business decisions and thinking the only thing a programmer or engineer wants to be happy is free beer.

    Three years ago TEIR developed a Client/Server architecture that required 5 _megabyes_ of DLL's to run on a client machine. This took a year and a half to and about 80 people to develop.

    After being given tens of millions of dollars and running the company into the toilet, it's amusing to see he was given another company that continually does incredibly stupid things. I wish I was an executive because there is obviously no accountability.

    The worst about this thing was that as soon as I saw the e-mail, I immediately windered how many people would try to abuse this blatant security hole. It's obvious no one with two neurons to rub together was involved in this promotion at any level.

    I can't wait until I can change to another company for my domain registration.

    Rick



    --
    You are in a maze of twisty little passages, all alike.
  60. Re:...also username=last_name, pw=last_name+nsi... by bmetzler · · Score: 3
    Yeah, I managed to log in using my last name as well and changed the password. I clicked on profiles (or whatever it's called, I forgot already) and found out that it wasn't me, but someone else with the same last name.

    Note, for last names that are consecutively numbering them. So the first the accounts are set up like this:

    user: smith
    pass: smithnsi
    user: smith1
    pass: smith1nsi
    user: smith2
    pass: smith2nsi
    user: smith3
    pass: smith3nsi
    user: smith4
    pass: smith4nsi

    Needless to say I don't consider that a good security measure either. And no, I'm not telling you what mine is numbered...


    --
  61. Anyone managed... by bertboerland · · Score: 1

    ... to get into the networksolutions.com account ;o)

    --
    -- for undocumented cisco commands, take a peek @ dotu
  62. It's bullshit like this why I'm glad all my domains are Christmas Island. Not only do I get better and cheaper service than NSI domain holders, but they have very strict privacy policies, you can even opt out of being visible in the whois database, and in the case of trademark contention they'll only act based on a court order, end of story. And they're hosted by a British company, too, so I don't think even an American court order would suffice - it'd have to be tried in the British courts. Maybe that's not as good a thing though. :)

    .cx domains rule. They're relatively uncommon and not even close to saturated, you get an insanely long "free" period to play with a domain (and technically it'd be possible to never have to pay for a domain, though that's quite dishonest), and if you want uniqueness, no better way than that. "Dot cx? That's weird man... must be some cool thing!"

    Oh, and they only have authenticated web-based access for modification. I don't think they use https, though, but then again, email-based NSI updates aren't exactly secure either.

    This just settles it for me. I'm never going to trust NSI with any domainnames.
    ---
    "'Is not a quine' is not a quine" is a quine.

    --
    "'Is not a quine' is not a quine" is a quine.
    Quine "quine?
  63. Need directions to change to alternate registrar by Hollins · · Score: 2

    Could someone post directions on how to change to a different name registrar for the domains I am already using? I know how to register new domains with the alternatives, but I want to switch my accounts over.

    Thanks.

  64. Re:Weird... by mke2fs · · Score: 1

    It works like this :

    * Domain1 could be domain.com
    * Domain2 could be domain.net

    And so on...

    This may not be it, but I used domain3 as my username... and got in.

    When you do a whois you'll see what to use.
    Regards,
    Stig

  65. nsi.com networksolutions.com by JeremyH · · Score: 1

    Am I missing something here?

    www.nsi.com/dotcomnowmail turns up a 404 for me. Same with www.networksolutions.com/dotcomnowmail. (nsi.com is just a redirector to networksolutions.com)I also looked at networksolutions.com and I cant see anthing on there about this program.

    I have a domain registered with nsi (I registered when they were still at internic.net) and I have not recieved any spam from them about free web mail.

    Whats the deal? Or did they fix this thing already?

    --
    -JeremyH
  66. The risks of email spoofing by remande · · Score: 2
    On the one hand, anybody with a domain can set up bogus email accounts: "microsoft@foo.com", "bill_clinton@foo.com". If we worry about people using our personal and organizational names for email addresses, we have a lot to worry about. Too much, in fact.

    OTOH, this is a problem because "dotcomnow" is NSI, and NSI has a reputation for trust. Thus, there's a world of difference between "microsoft@foo.com" and "microsoft@dotcomnow.com".

    Just some thoughts for figuring out how nasty this security breach is.

    --

    --The basis of all love is respect

  67. Re:Try: http://mail.dotcomnow.com by JeremyH · · Score: 1

    Damn I just tried that. It does work.

    And I never even got the email from nsi.

    If it wasnt for /. I never would have heard about this. WTF?????

    --
    -JeremyH
  68. Forward all NSI SPAM to the MAPS RBL. by strredwolf · · Score: 3

    NSI is screwed up big time with this deal, and the Internet community, especially those who deal with net-abuse of this type and magnitude, does not like such a bad neighbor. Forward with full headers and apropriate password removed to MAPS RBL (http://www.mail-abuse.org) and post it to news:news.admin.net-abuse.email with the subject of NSI SPAM. Also document every phone call you've made to remove the free e-mail account and pass that along too. It's time we nip NSI in the bud about this.

    ---
    Spammed? Click here for free slack on how to fight it!

    --

    --
    # Canmephians for a better Linux Kernel
    $Stalag99{"URL"}="http://stalag99.net";
  69. It's worse (better?) than you think.... by imac.usr · · Score: 1
    Nobody else seems to have brought this up: once you've logged in as someone else, you can set up the service to allow you to send messages using a different address (to "create the appearance of sending mail from your other accounts" - taken directly from their Preferences page). So, apparently all you have to do is add the address listed as the contact address in the WHOIS table, make it the default, and bingo! You've just become that person. You're not user@dotcommail.com, you're user@microsoft.com or user@yahoo.com or user@earthlink.net or user@whitehouse.gov or whatever. If you somehow got ahold of that person's POP settings, you can even have their mail forwarded to the dotcommail account.

    Wheee! I haven't been this tempted to screw my former employer since I heard about the NT/IIS4.0 bug!

    --
    I use Macs for work, Linux for education, and Windows for cardplaying.
  70. Will this affect WHOIS? by Jonny+Royale · · Score: 1
    I hate to ask this but...

    Since Network Solutions is handing these out based on registrars and domains, and they run the whois database, can/will they modify the whois database? Can someone with an account check this? (I don't have one, or its foo-bar).

    I don't think they're allowed to, but it's their playground, so you never know.

  71. will spam bring dotcomnow.com to its knees? by klund · · Score: 1

    I just guessed two usernames and passwords, (sorry, Mr. Smith numbers 83 and 84, whoever you are), put them both on vacation mode, and sent a message from one to the other. No loop.

    But, I already received some spam at both accounts. Some spammer has already written a script to generate lastname### address and flood their server. I hate spam, but this is kind of funny.

    I wonder how much disk space they have?

    --
    My word processor was written by Stanford Professor Donald Knuth. Who wrote yours?
  72. "THE DOT COM PEOPLE." by $nyper · · Score: 1

    I thought they were supposed to be "THE DOT COM PEOPLE." I mean my God I have just tested this and let me just say that this has to be one of the most stupid policy based security screw-ups I have ever seen.

    MORONIC!!!! My 2 year old cousin has a better understanding of security concepts than these people.

    Someone definitely needs a good ass chewing after implementing a policy like this one. If I were to ever write such an idiotic policy like this I would blame it on Old-timers syndrome and retire from the world of Network Security. Damn... I don't know whether to cry or laugh about this incident.

    $nyper

    --
    "Help me Obi-/.-Kenobi,your my only hope!" -$
  73. Another interesting tidbit from the spam... by doce · · Score: 1

    I recieve the email as well. At the bottom, they were nice *cough* enough to allow you to remove yourself from their spam list, as such:

    If you do not wish to receive e-mail from Network Solutions, click on this e-mail address and type "remove" in the subject line.
    PLEASE NOTE: by opting to be removed from this list we will not be able to communicate to you, in real-time, on issues regarding your account.


    but of course, you by doing you, you also lose the ability to correspond with NSI altogether. Complete BS, in my opinion.

    --
    woof!
  74. netsol.com down? by saturated · · Score: 1


    Does anyone know if they took it down, or if it was /.'d?

    --
    ' god damn this is one wacky game show ' ~ jay in mallrats
  75. Try this by tweek · · Score: 1

    I got in via the alternate address and changed my settings. I would suggest doing this. Turn on vacation reply and then use this as the message.


    I do not accept mail here. This account was setup
    without my permission by NSI. If you need to email me
    with important information please email me at the email
    address listed via whois.

    --
    "Fighting the underpants gnomes since 1998!" "Bruce Schneier knows the state of schroedinger's cat"
  76. Re:Amazing it runs at all? Try OS/2! by Kintanon · · Score: 1

    All this, and it's a hundred times more stable than Windows. In other words, you should not be surprised that Windows runs at all. Every OS/2 user knows that it's possible to for an operating system to do all that Windows does (and more) and still be stable

    I knew I should've stuck with Os/2 Warp back in '94.... What kind of support does IBM offer for OS/2 nowadays? OR has someone else taken over the OS? Be nice to know there is another alternative to windows out there.

    Kintanon

    --
    Check out JoshJitsu.info for Brazilian Ji
  77. No item #3 in my email by joost · · Score: 1

    I just got the email from Network Solutions (I'm a non-US customer). There's no item #3. I cannot login using my name, handle or domain name/handle.

    So either they've taken it out or it's for US customers only.

    1. Re:No item #3 in my email by Spatch · · Score: 1

      Well, I checked the whois record of a domain I own (and, frankly, would like to get back from the clutches of the Duh Com people, since all their info is horribly out of date and I have no way of contacting 'em) and I tried logging in under every combination of every piece of information I could find in the whois record.

      No luck.

      Then I tried just my last name. I got in, and thanked the nice people at Network Solutions for giving me such a nice email address. But they seemed to call me "Fred", though.

      Strange.

  78. Criminal incompetence by sammy+baby · · Score: 1

    Actually, it is, in some circumstances. It's called "criminal incompetence," but I don't know if there's any legal precedent in the computing industry. Anyone?

  79. Nice domain name by Chris+Pimlott · · Score: 2

    Hmm, am I the only one who finds the domain name "netSOL.com" oddly appropriate?

  80. Class action lawsuit by Old+Man+Kensey · · Score: 2
    I think this provides enough material for a domain owners' class-action lawsuit. This would fall under criminal negligence, putting literally billions of dollars' worth of assets at risk. Another might be misappropriation of property -- arguably use of an entity's registration info, like use of their phone number, belongs to that entity, and NSI's legal blather at the top of WHOIS queries could be seen as an illegal effort to restrict an entity's use of their own property.

    Anybody want to start a mailing list? If we can get about 1,000 subscribers I think we might have something here.

    --
    -- Old Man Kensey
  81. Re:No, try THIS. by tweek · · Score: 2

    well i guess that would work

    Time to clean the mountain dew of my damn monitor now.

    --
    "Fighting the underpants gnomes since 1998!" "Bruce Schneier knows the state of schroedinger's cat"
  82. It's not in every message by philg · · Score: 1
    I didn't get any NSI communications for my domain name until this morning -- looks like the same message, but only had two bullet points. (i.e., no mention at all of the webmail account).

    Mine is a .org account -- any idea if this offer was restricted/implemented only for the .com's? I doubt it....Whether the account actually exists or not is, of course, an open question, at least until the server comes back up. :)

    phil

    p.s. -- I replied to the message, asking someone to contact me about the disclaimer at the end, and sending administrative and advertising information on the same list. I find this somewhat concerning, as I might skim over important info buried in a sea of "SPECIAL OFFERS". (I also don't want any more spam in my inbox than I can avoid.) I encourage other people with similar concerns to do the same.

  83. Network Solution's Phone Number by Threemoons · · Score: 1

    Hey there...for all of your edification...

    it's 703 742-0400

    All circuits are busy now.

    Luckilly, I'm being let out of my veal-fattening pen at 1 due to the hurricaine...I and my boyfriend will then jointly program our modems to do the dialing for us whilst I kick back with a Jack & water and flip the bird towards VA....

  84. Strangely Relevant by Sebbo · · Score: 1

    I was browsing with multiple windows this morning, and had one window fetching this article while another was fetching the floydcam piece from Tuesday. I came back after they'd finished loading, and my eyes fell on: "And for record, I regret damage done to property and life-but the power of Nature is still amazing."

  85. WTF? by KaosDG · · Score: 1

    Hey, can somebody give me some pointers here...
    (no, not *p)
    I tried the link (netsol.com/blahblah)all i get is a timeout.

    and the mail.dotcomnow.com gives me a login screen, but it says it failed to auth when i try the standard lastname##/lastnamensi combo. after a few tries it gives a "free web mail" page but that's it. I didn't recieve an e-mail from NSI, but I did register with them, so i'm partially worried they might have kicked me off the boat.

    wtf? can't we mount (he said mount) a petition against this sort of crap? Or at least /. them for it?
    I say we lay a corporate smack-down on them and let those roodie-poo, candy-assed NSI people know who brings them the money...

    --
    "Fuzzy Wuzzy was a bear, Fuzzy Wuzzy had no hair... Fuzzy Wuzzy wasn't fuzzy was he?"
  86. Try: http://mail.dotcomnow.com/login/ by Anonymous Coward · · Score: 1

    http://mail.cotcomnow.com/ will route you to an nsi page but http://mail.dotcomnow.com/login/ will take you to the login screen...

    I am a bit paranoid, I have changed passwords of eight accounts already and am considering legal action agains nsi for creating accounts under my name without my permission

    Try domainid+1 and domainid+1+nsi for login and passwords, they seem to work in some instances

  87. telnet is eeeeeeevil! by Nugget94M · · Score: 1

    You should be using ssh 1.2.27, not telnet.

  88. Re: NSI real name by orabidoo · · Score: 2

    maybe with this someoen will finally force-rename Network Solutions to Network Problems.

  89. How people should respond.... by jeff_C · · Score: 1

    One way to make sure NSI feels some pressure to fix this is for whoever managed to get microsoft, IBM, ford, gm, etc. to send an email to the real administrative contact listed in the whois database an email from this free account. Just make sure in the email that you copy the original email, and explain why this was such a bad idea.

  90. Two major things! by Anonymous Coward · · Score: 1
    Well... I got in and changed my password... then I decided to send a note to 'pastmaster@mail.dotcomnow.com' to ask them to delete my account. I sent the note from their site and Cc:ed my self.

    Once the message was sent it showed a link for a "sent" folder so I clicked on the link. Yep, there was the message I had just sent. So... I click the back button on my browser and what happens? It sent my message again (I got another copy).

    Then... after laughing myself silly... I got another message with the subject of "I SUCK BADLY" with text of:

    y0,
    NSI values security soooo much that we didnt even change our postmaster or root passwords... as a result we will never get your message....

    sorry

    Sad... really sad...

  91. Call them TOLL FREE at: (888) 642-9675 by doulos · · Score: 1

    No busy signal either!!! This number was advertized at the following URL on their own site: http://www.networksolutions.com/dotcommail/email_a ccess.html but who knows how long it will be up. I called it and asked to speak to a supervisor, where I was then politely taken care of. I explained the matter of security compromise, and then politely requested the e-mail accounts to be removed for all of my domains in question.

  92. Go ahead. Tell them what you really think... by macdaddy · · Score: 1

    Don't tell /. Tell NSI how stupid this whole ordeal is by filling out their "Customer [Anti-]Satisfaction Survery". I'm sure they'd love to hear from their actual customers that paid *good* monoey for NSI's services exactly what they think of those services and the people supporting them. Go ahead but be honest... :-)

  93. Read their terms of service - VERY BAD! by Tumbleweed · · Score: 1

    If you read their service agreement, you'll notice this little gem as part of section B. REGISTRATION:

    "You hereby grant NSI the right to disclose to
    third parties such Account Information."

    Gah! Okay, so what this means is, if you log into that account, you agree to let them release all your information to be spammed into oblivion.

    Nice.

  94. fake? by jlb · · Score: 3

    am i the only person here who does not necessarily believe this really is from internic? I mean, none of the email addresses are even internic hostnames, none of the recieved headers look like they're from internic. Since this is such publically available information, anyone could really pose as internic and mail you. Maybe I'm being naive but I don't think internic is this stupid. It's hard to believe that someone would be that stupid to try to pose as internic to get users for their free email, but I think it makes more sense that way. Here's the headers from my mail: Received: from maild.inte-net.com ([63.71.102.109]) by bilbo.w-link.net (8.9.0/8.8.5) with ESMTP id CAA05359 for ; Thu, 16 Sep 1999 02:04:59 -0700 (PDT)

  95. I have a few questions by macdaddy · · Score: 1

    Could someone answer these for me?

    1. What contact person did these messages go to? Billing, Technical, or Administrative?

    2. Is this the same DotComNow mail that NSI is wanting to charge $169 for 2 years of service?

    3. What specifically is my domainID? I'm assuming from the /. posts that its my NSI Handle.

    4. Could someone please document the whole procedings for getting in, checking to see if you have an account, and changing the passwd?

    5. Does anyone live in the Baltimore, MD area and have time this afternoon to stop by NSI's headquarters and bitch-slap the first few people you see? If enough /.ers attend this little get together, NSI may get a clue and stop being so "like, whatever..." about everything. :-)

    Thanks for the info!

  96. Re:Oh my. . . . by jkubecki · · Score: 1

    Uh, don't want to say anything, but did you by chance mean to type "Test message from account!" in the SUBJECT line of the message you sent, not the CC line?

  97. how to tell if you are affected by MR_URC · · Score: 1

    Apparently, part of the system has been shut off. I was sent the email and followed their directions; I could not log in. So I looked around a bit and found this page: There is an engine that will search by your domain name. Mine was not found, implying that my account was deactivated.

    "This form will only work if you have already signed up for dot com mail. If your browser informs you that it was unable to locate the server, that means you have not signed up for dot com mail. If you would like to get dot com mail call, 1-888-642-9675."

    Since they activated mine automatically and sent me a notice of this, it appears that they have shut down 1st logins.

  98. Re:Amazing it runs at all? Try OS/2! by LordNimon · · Score: 1
    I know this is off-topic, but to answer the question, IBM doesn't exactly provide stellar support for home users. You're much better off relying on the support of fellow OS/2 users. IBM does still provide updates and bug fixes for OS/2 for free, though, but they tend to be geared towards the needs of their big corporate clients. For instance, USB keyboard support is way more important than USB scanner support, so OS/2 has the former but not the latter.

    However, that won't stop hundreds of us from attending Warpstock '99 next month, right after the Atlanta Linux Showcase.

    There are rumors of Stardock taking over a small-user version of the OS/2 client. We'll know for sure this weekend. You can keep track of the OS/2 world by visiting WarpCast

    --
    And the men who hold high places must be the ones who start
    To mold a new reality... closer to the heart
  99. Transfer registration to register.com! by sben · · Score: 2

    Caveat: I haven't tried this, but I'm initiating proceedings as I type....

    Apparently, register.com lets you transfer the registration of your domain from NSI to them. Check out this page. It seems to require a fax or snail-mail, but at this point, I don't really care how clumsy it is.

  100. They Say it was a crank... by Darksky · · Score: 1

    We just called NSI and they say someone went in and created accounts from the whois list and gave them all the "joe" passwords.... According to NSI you have to go in and actually create your own account, it is not pregenerated. But I don't see how one person would create accounts for everyone on the whois list....

    --
    01101100 01101001 01101110 01110101 01111000 01110010 01110101 01101100 01100101 01110011
    1. Re:They Say it was a crank... by Darksky · · Score: 1

      P.S. I don't think this was NSI's fault.. did any of yo so called geeks even bother to read the headers on the email? Who the HELL is netsol1@integram.org... They are NOT NSI affiliated....

      --
      01101100 01101001 01101110 01110101 01111000 01110010 01110101 01101100 01100101 01110011
    2. Re:They Say it was a crank... by tweek · · Score: 1

      Actually they ARE part of netsol.

      whois on integram.org shows registered to worldnic.net
      worldnic.net shows registered to network solutions


      gee do YOUR fucking homework next time.

      --
      "Fighting the underpants gnomes since 1998!" "Bruce Schneier knows the state of schroedinger's cat"
  101. NetWiz.Net - good service, no spam. by seebs · · Score: 1

    http://domains.netwiz.net/, even has an antispam
    policy on their main page.

    --
    My blog: http://www.seebs.net/log/ --- My iPhone/iPad app: http://www.seebs.net/seebsfrac/
  102. How to (supposedly) get the account removed by tgeller · · Score: 1

    I just called the 888 number and asked to have the account removed. The first person said, "You have to respond to the 'remove' instructions at the bottom." I pointed out that that would only stop mail to my @tgeller.com account, and would not remove the dotcomnow account. "No," she said, "it does both." I asked to speak to her supervisor, and he insisted that was correct. I doubt it, but there it is. --Tom

    --
    Tom Geller
  103. We have choices. by kuro5hin · · Score: 2

    Look here or here for all sorts of other domain registrars. Screw NSI-- enough is enough. There are literally hundreds of other top-level-domains. Find one that's better, and use it.

    ----
    We all take pink lemonade for granted.

    --
    There is no K5 cabal.
    I am not the real rusty.
  104. An open letter to NSI by Bald+Wookie · · Score: 1

    To those with the power to make a difference:

    In an effort to retain customers, you gave them all free web email accounts. Do you even have a clue of who your customers are?

    The average domain owner probably has a computer and an ISP. In many cases they will be a company that provides mail services for its employees. Others will be ISP's running huge mail servers. Many more will be website operators, who often get free email with their hosting package. At the very least they probably have a PC and an ISP that offers POP3. These people know the internet, and most of them dont want or need webmail. Those who do, probably already have it.

    So, to retain customers you automatically sign them up for a service that they don't want? I simply dont understand the logic behind this. Not only that, but you break the most basic rules of security. Now you force some already annoyed sysadmins to fix a security hole that you created. Heads should roll.

    Lets be honest, your company doesn't have the best reputation for customer service. Instead of blowing money on a mail server and admin costs, you could have hired more reps and made a public commitment to service. That would have made a nice little press release, and attracted some quiet praise. At the very least, it would have shown that you understand the problem, and are taking steps to fix it. Instead, you create more trouble for your customers and get bad press for technical ineptness. Go read the Cluetrain Manifesto www.cluetrain.com, clean house, and hire the clued. Otherwise, wither and die. HTH HAND

    -BW

  105. They might have just fixed it. by phil+reed · · Score: 1

    The www.dotcomnow.com site, which when I bookmarked it this morning took me to the login page, now takes me to an introduction & signup page. The original login seems to have vanished. There are now 3 different free mail domains (dotmail.com nsimail.com mymailbag.com) each with the same form, and when I try to use the id and password that worked this morning, they don't work now.


    ...phil

    --

    ...phil
    "For a list of the ways which technology has failed to improve our quality of life, press 3."
  106. Quick Quick!!! by Shaheen · · Score: 1

    Someone, quick! Get over to NSI and take over microsoft.com!!

    This is the chance we've all been waiting for! As soon as one of us Linux zealots owns microsoft.com, we can point it to linux.com!

    Just a thought to make world domination more feasible.

    - Shaheen

    --
    You should never take life too seriously - You'll never get out of it alive.
  107. Re:...also username=last_name, pw=last_name+nsi... by Jonavin · · Score: 1

    Holy ithoughtyouwerealltrolling.com!!

    I tried my domain name but it didn't worked. Then I tried my surname after reading your post and now... well, now I'm paranoid.

    Does that mean somebody has already beaten me to my domain logons, or are these mailboxes 'random'.

    complain! complain!

  108. What About Other Registrars? by Rolan · · Score: 1

    Just out of curiousity, did NSI do this to ALL domains in their database or only to the ones that came from their services? i.e. If I registerd a domain through register.com (which I didn't) would they also add this service to that domain? Just an interesting point to consider....

    --
    - AMW
  109. They didn't program it - Critical Path did. by seebs · · Score: 1

    traceroute to mail.dotcomnow.com or whatever it
    is revealed that it's hosted by cp.net - Critical
    Path, who do kick-ass mailing services - and who
    have an aggressive anti-spam policy.

    --
    My blog: http://www.seebs.net/log/ --- My iPhone/iPad app: http://www.seebs.net/seebsfrac/
  110. It gets worse... by sodergren · · Score: 1

    As if the username password stuff wasn't bad enough...

    They sent me the spam about the free e-mail account, complete with a username/password for a domain that I have nothing to do with!

    The domain was sodergren2-dom; I'm not in any of the contact information for this domain. I have nothing to do with this domain. The only connection is that I share a last name with this domain.

    Don't they know how to utilize their own whois database? Maybe copyright issues prevent them from using it...

  111. Re:No Monopoly/Other Registrar choices by ender- · · Score: 1
    It's my understanding that they do hold a monopoly.

    Actually,no, you're more than welcome to get a Domain name owned by another country, such as mine. [Which is for the lovely little country of Niue "nooway"] or any of a number of other countries... plus your domain info isn't available via whois, so I don't get spam from anyone [not yet anyway]

    ender

    Can't think of a good sig right now...

  112. UGH! Finally go my "free" e-mail canceled by GMontag · · Score: 1

    Saw this on slashdot and immediately got on the phone to NSI.

    I spent 3 hours getting the runaround and being disconected with these idiots today. Was so frustrated that I went to the office in person (Herndon VA is near where I live)and asked at the desk (third floor of a pretty nice building) about the problem.

    The people at the front desk don't know anything about the 'net, but offered to let me sit on hold on their phone for lord knows how long, waiting for CS.

    Went home, checked mail, and yes I had a copy of the dreaded e-mail Spent another hour+ getting bounced aound, then finally got the offending account removed.

    BTW, the nice chick on the phone (only nice one was the one that helped me, the last one) assured me that nobody has used these accounts yet. She was supposed to have mailed a cancellation verification to me, but it has not shown up yet.

  113. A look at the headers by Nethead · · Score: 1
    I sent mail to myself from the dotcomnow.com system and found that it's really handled by cp.net (Critical Path) out of San Francisco.

    The Public and Investor Relationships contact is a Stefanie Elkins (415-344-5503) selkins@cp.net.

    Their "Email Solutions for Proprietary/Groupware Systems" toll free number is 1-800-826-4666. I'll call THEM and ask them to remove any knowledge of my domains from their system... and remind them that I'm a Washington State Resident and we don't like spam. We have a nice anti-spam law here.

    --
    -- I have a private email server in my basement.
  114. What about forced SPAM? by SWiTCH2 · · Score: 1

    here is what the bottom of that email states: "If you do not wish to receive e-mail from Network Solutions, click on this e-mail address and type "remove" in the subject line. PLEASE NOTE: by opting to be removed from this list we will not be able to communicate to you, in real-time, on issues regarding your account." eh? i'm screwed if i did, screwed if i don't!

  115. Re: Unsolicited credit cards by coyote-san · · Score: 2

    Your friendly bank does not send you an unsolicited credit card because the courts (at least in the US) have held the contract is unenforcable. One concern was that credit cards could be stolen from the mail without the person's knowledge, and if the card was unexpected and from an unknown company the consumer/victim would have absolutely no clue there was a problem. A second concern was that many people would not be familiar with credit cards (in the 60's, as I recall) and they could incur substantial liabilities without realizing it.

    They can, and do, send you "preapproval" letters that only require you to confirm some information and sign it. Someone can still steal these letters and forge you signature, but theft and forgery are already crimes.

    It is legal for a company to issue you a replacement card without prior notice, but it runs the risk of pissing off customers. A bank manager quietly told me that a full third of the customers, including myself, closed our accounts after our bank was bought out and the new bank decided to issue "debit cards" (pre loss caps) to replace "atm cards" without prior notice or consent. It was rude, crude, and socially unacceptable, but legal.

    Back to the "generous" NetSol offer, I am outraged. And not just because they keep making me these wonderful offers yet are incapable of changing my contact informaton despite repeated requests.

    The currency on much of the net today is reputation, and NetSol's indifferent disregard to the consequences of its actions is as shocking to our sensibilities as the 60's banks disregard to the consequences of it's far-too-open credit card policy was to their peers. Of course nobody should automatically assume that the NetSol accounts are actually controlled by the person whose name appears on them, but a lot of people will. Unlike most (all?) other free mail sites, NetSol accounts can be tied to real names, real addresses and real phone numbers. So they have *far* more intrinsic credibility than "HotMail" or "GeoCities."

    --
    For every complex problem there is an answer that is clear, simple, and wrong. -- H L Mencken