[HN Gopher] GoDaddy: Hackers stole source code, installed malwar...
___________________________________________________________________
GoDaddy: Hackers stole source code, installed malware in multi-year
breach
Author : razin
Score : 165 points
Date : 2023-02-17 18:16 UTC (4 hours ago)
(HTM) web link (www.bleepingcomputer.com)
(TXT) w3m dump (www.bleepingcomputer.com)
| [deleted]
| miked85 wrote:
| I honestly can't believe this company is still in business - it's
| been terrible for decades.
| webdood90 wrote:
| have you been using it for decades? or do you just read the
| headlines to form an opinion?
|
| there are a ton of hard working people at GD that care a lot
| about the products we make. I don't think that's a fair
| assessment.
| vxNsr wrote:
| Wow, multi-year is truly embarrassing. Hosts being compromised is
| the the worst case scenario because the attacker can decide who
| to serve the malware to in a spearphishing fashion.
| jeroenhd wrote:
| It happens to more companies than you'd imagine, even big ones.
| Security monitoring and logging is hard to get right,
| especially if you try to add it to a previously insecure
| system.
|
| A smart attacker can hack your company unnoticed and passively
| watch your company for the right moment to strike. I doubt that
| the hackers logged into the office VPN every day.
| anonzzzies wrote:
| Godaddy. One of the most horrible companies. Always was. Bob
| Parsons is a sad individual with many lovely quotes attesting to
| that fact. Hope this ends them.
| avsteele wrote:
| This might solve a big mystery for me.
|
| When I first set up my company's website it was hosted at
| GoDaddy. Totally static site. It got 'hacked' one day, with new
| php files and redirecting users to some nonsense. This was August
| 2016. The ftp server had a very long, random password. I changed
| it again after this.
|
| It happened *again* March 2017, though different files were
| added. After this I moved my site to Digital Ocean.
|
| I never found out how this happened.
|
| Does anyone know how long this has been going on? The article
| didn't give a definitive start date.
| iLoveOncall wrote:
| You can have the longest password in the universe and change it
| after every login, if you have a keylogger on your computer it
| doesn't matter.
| sn_master wrote:
| or someone sniffing your network. FTP isn't encrypted.
| muttantt wrote:
| I feel bad for the hackers that now need to read through
| GoDaddy's code...
| dylan604 wrote:
| Long long ago, I needed a new website hosted and with no other
| decision towards the host than I had never tried GoDaddy, I gave
| it a shot. Within hours, I regretted the decision immensely. In
| comparison to my previous hosting experiences, it just pissed me
| off at almost every turn. It was the first time I experienced a
| company trying to make the interface for non-techy types and made
| getting to the guts of the tech hidden behind many layers that
| just frustrated me to no end. I canceled my account and have
| never looked back.
|
| It is just another one of the examples of a company that
| advertises that intensely is probably a company I don't really
| want to be involved.
| chanandler_bong wrote:
| They did have a couple of years with good commercials, though.
|
| https://www.dailymotion.com/video/x9v5p4
| mixmastamyk wrote:
| I tried it once as well, maybe ten years ago. The annoying
| thing not yet mentioned is that it tries to upsell you at every
| step. You quickly realize that steps have been added for
| additional upsell opportunities.
|
| Then the "elephant shooter" drama happened and I moved to
| namecheap and didn't look back. Was a breath of fresh air in
| comparison.
|
| I didn't see a way to delete my gd account, so think it is
| still there. Hope my data didn't get out again. :doh:
| favourable wrote:
| > The annoying thing not yet mentioned is that it tries to
| upsell you at every step
|
| I turn it into a game. I love the feeling of having cheated
| their systems and cleverly opting out of all the up-sells. I
| am forced to use GoDaddy because I have profitable blogs and
| e-commerce stores which would be a holy war trying to migrate
| all that to other services. It's do-able, but would be a
| headache and a half.
| eclipticplane wrote:
| > I am forced to use GoDaddy because I have profitable
| blogs and e-commerce stores
|
| Ever _more_ reason to migrate them, imo.
| qwertox wrote:
| The only thing that annoys me from Namecheap is that their
| API isn't that good. You can't just update a single record,
| you have to update the entire zone.
|
| Updating the entire zone just to automatically set a
| verification token (like for Let's Encrypt) is too risky.
| bombcar wrote:
| It's sad because I used to remember a long LONG time ago they
| exposed a bunch of things that other registrars required you to
| email or call support to do. That stuff is still there, but
| otherwise the whole site just feels slimy.
| mmcgaha wrote:
| They are the only company that ever hijacked my robots.txt.
| convolvatron wrote:
| wtf? what does that look like?
| groestl wrote:
| For me, this company was Network Solutions. Never have I ever
| dealt with a thing so bizzare. They even uppercased my email
| address when communicating with me.
| kstrauser wrote:
| There were a tiny company and couldn't afford the mixed-case
| terminals.
| sn_master wrote:
| I'll never use GoDaddy. They've been fronting their customers for
| literally decades. Few times I searched for a domain, the next
| day I search for it find it already reserved by them and on sale
| for hundreds of dollars instead of the regular $10 it was the day
| before. They've been abusing their power for as long as they've
| been in business.
| krimpenrik wrote:
| Share the same experiences. When godaddy comes up I feel
| obligated to share. Avoid at all costs
| 2pEXgD0fZ5cF wrote:
| > Few times I searched for a domain, the next day I search for
| it find it already reserved by them and on sale for hundreds of
| dollars instead of the regular $10 it was the day before.
|
| I can confirm this experience, on 2 occasions when I looked up
| a very specific (and definitely not common) domain, they were
| suddenly reserved by GoDaddy and sold for a premium price. Not
| hundreds, but like 50-150 instead of 12.
|
| I can't prove it, of course, but after hearing about those
| problems with GoDaddy multiple times it just seems too
| convenient for them to be a coincidence.
| tehlike wrote:
| One other explanation (though i am fairly certain godaddy was
| fronting you), is if they include any third party ping/script
| etc, and that script/ping gets referrer or the url of the page,
| someone malicious 3p could also do this...
| codetrotter wrote:
| > Few times I searched for a domain, the next day I search for
| it find it already reserved by them and on sale for hundreds of
| dollars instead of the regular $10 it was the day before.
|
| I don't understand how that could possibly be profitable.
| Imagine how many searches there must be for new domains every
| day. There is no way they could afford to buy all of the
| domains that people searched for.
|
| And if they had any means of measuring how "good" a domain name
| is, in order to filter the searches that people make, and front
| run only the ones looking for good domain names - I don't think
| that would make sense either. If you were able to reliably
| measure how good a domain name was you could just buy the
| domain name right away without waiting for any customers to
| search for the domain.
|
| Anyway, for anyone that is looking for a registrar to use I
| recommend that you stay away from GoDaddy. Register your
| domains with Gandi.net, they are nice and good.
| https://www.gandi.net/en-GB
| sn_master wrote:
| > I don't understand how that could possibly be profitable.
|
| Because registrars have the power to "reserve" domains they
| like for some time either for free or for only a pennies.
|
| https://en.wikipedia.org/wiki/Domain_tasting
| NationalPark wrote:
| Godaddy is a crappy company for many reasons, but this
| seems like something that's trivially testable. If they
| were really front running domains, anyone could spend an
| hour typing domains in and see a bunch of them mysteriously
| registered by godaddy the next day. Has nobody done that?
| Why can't I find any blogs where this was attempted?
| mirzap wrote:
| They must have some algo that rates domain quality. It
| happened to me recently, so it's not bullshit. They do
| front running, but they have some sofisticated scheme
| behind it.
| jerf wrote:
| It is trivially testable. I've tested it myself a few
| times, against a few different companies, just for fun.
| I've never seen it happen.
|
| If you imagine ordering all the domains in order of
| desirability, where the most desirable are long gone, and
| nobody wants "nsejrx8oesrjasrjb.com" (and even if they
| want an obfuscated domain, they don't want _that_
| obfuscated domain), there is a middle ground where it 's
| not worth pre-registering but if you see an indication of
| interest it may push you over, especially if you have a
| cheap back door for registration as registrars do. In
| that case, the only ones sensible to front-run are the
| ones in that middle ground. It is possible that I never
| chose a domain that triggered such an algorithm. That
| said, as I was aware of this possibility at the time, I
| did deliberately try to come up with a combination of
| tasty & tempting words in a new format that looked like
| maybe someone would really want it, and I never could get
| the hypothetical algorithms to bite.
|
| Take a crack at it if you're interested; it really isn't
| that hard or a big investment in time.
| bmelton wrote:
| This happens a lot. Godaddy comes up in the news, someone
| accuses them of front-running, someone else investigates
| the accusation and finds that the allegation in question
| was definitely not the result of front-running.
|
| https://domaininvesting.com/godaddy-still-not-
| frontrunning-d...
|
| I have no information on whether they are or aren't
| front-running, but every time I've seen a _specific_
| allegation, it 's been disproven. That doesn't make it
| factual either way, but I like Godaddy for enough other
| reasons to not use them, so I don't particularly care if
| they are or aren't, but I've yet to see a specific
| allegation be found credible.
| [deleted]
| legrande wrote:
| GoDaddy is a very complex thing. And bugs lurk in complexity. No
| wonder.
| dylan604 wrote:
| Are you saying that other hosting companies in the same level
| of complexity are just better, or possibly alluding that other
| companies might not be upfront about things occurring within
| their orgs? Either way, it really sounds a lot like you're
| minimizing the negligence and just poorly run company.
| goodfight wrote:
| I feel like this may be the same case at PayPal too. Identity
| theft and random emails were not even intended for me was my
| experience.
| jasonlotito wrote:
| I hate blaming the victim, but so much bad press had come out
| against GoDaddy it's like complaining that the bear hurt you when
| you went into it's den and disturbed it.
|
| Friends don't let friends use GoDaddy.
| rdiddly wrote:
| So was this a breach of cPanel that therefore could affect other
| providers that use cPanel?
| youniverse wrote:
| Anyone want to recommend their favorite alternative web hosts?
|
| I've tried A2 and NameHero and both were very solid along with
| fast/great support.
|
| Anything else I should look into?
| chriscjcj wrote:
| For DNS, I have been using Gandi (1) for the last yen years or
| so and have been very happy with them. I originally went with
| them because they were one of the few registrars that did the
| .cat TLD. I liked the experience and eventually transferred all
| of my domains to them.
|
| They are a french company. Their slogan is "No Bullshit," (2)
| and I think they've done a decent job of living up to that.
|
| My only frustration has been a situation where I was
| transferring an existing domain over to them. I wanted to
| create the zone file ahead of time so that when the transfer
| happened, there would be an identical zone file ready to go.
| But they wouldn't allow me to create a zone file for a domain
| that hadn't transferred over to them yet. Since I'm not doing
| anything critical with my domains, it was just an annoyance,
| but that would be a show-stopper for some.
|
| As it pertains to billing problems, they allow you to pre-pay a
| chunk of money to your account. (They take PayPal.) It deducts
| from that amount when domains renew. That provides a buffer if
| you need to cancel your credit card.
|
| Also, on the occasions that I have created trouble tickets,
| they have been responded to in a reasonable amount of time with
| helpful information.
|
| (1) https://www.gandi.net (2) https://www.gandi.net/en/no-
| bullshit
|
| For web hosting, I used Bluehost for many years and because
| extremely dissatisfied with them. I switched to Siteground.com
| about five years ago and have very little to complain about.
| disadvantage wrote:
| https://www.gandi.net/en
|
| https://www.ovhcloud.com/en/
|
| https://asmallorange.com/
|
| There are many others I can vouch for. There's a good list of
| them here[0]. Make sure to choose ones that have proper 2FA as
| it's a good heuristic for how well they consider security.
|
| [0] https://2fa.directory/int/#hosting
| Aachen wrote:
| OVH is always an exercise in broken UI including terms of
| service that seem to be copied from a pdf and have random
| artifacts. It's probably the worst buying experience I've had
| since the naughties and nothing changed in the years I'm with
| them now.
|
| ...but they're cheaper than other registrars known for being
| cheap, and I've monitored their nameservers (and a few
| others') for nearly a year before switching away from my
| previous registrar and they were consistently fast whereas
| others had spikes, outages, or constantly round robined
| across oceans or some such.
|
| Quality servers at very low prices makes me put up with some
| broken UI for a few minutes per renewal.
| blfr wrote:
| OVH is cheap and supports U2F. I have a bunch of stuff with
| them.
| kennydude wrote:
| My stuff is with Krystal who are fantastic. Had a ticket
| resolved by them on Christmas day within 2 minutes
|
| (i have a discount/referral code if you want it - contact form
| on website)
| [deleted]
| greatgib wrote:
| "We have evidence, and law enforcement has confirmed, that this
| incident was carried out by a sophisticated and organized group"
|
| I like how they try to hide their incompetence with bullshit
| sophacles wrote:
| Law enforcement (to GoDaddy): "well it went on for years from
| what we can tell. Whoever did this is more sophisticated than a
| bunch of impulsive teenagers 'joyriding'".
|
| GoDaddy PR (to world): The attackers were sophisticated, the
| cops said so!
| skilled wrote:
| What a disgrace of a platform. I'd understand dropping a c99 on a
| cPanel back in early 2000s but these days? What are the engineers
| doing at the company, collecting a paycheck and pretending to do
| work?
|
| Speaks volumes for the culture being cultivated at GoDaddy.
| Tostino wrote:
| I feel like a lot of these older platforms are being shown to
| be as rickety as they actually are, as malware and hacking
| toolkits improve and proliferate. Bad practices are going to
| show through, bigtime with this next cold war the US is
| entering.
| dylan604 wrote:
| i would not be surprised if their back end is still a bunch
| of old skool perl scripts in the cgi folder that were l33t
| coded back in the day, but nobody now can even start to parse
| the perl itself.
|
| switching from impossible to read perl scripts to flavor-of-
| the-day language would be a use case i can actually get
| behind and support for replacing.
| localghost3000 wrote:
| I agree that this is bad but I'd encourage you to rethink your
| comment. The "clown engineers" you are calling out maintain a
| level of uptime and scale thats hard to for most people to
| imagine. You don't do that by being an idiot.
|
| Instead of calling them names and assuming bad intent, maybe
| take a second to think about how much it must suck for them
| right now. I'm sure it's all hands on deck nights/weekends to
| fix. No one sets out to do a bad job in my experience.
| jayess wrote:
| Godaddy has the most user-hostile platform of any domain
| registration company I've ever encountered in the 25+ years
| I've been registering domains. It's utter garbage in every
| way.
| localghost3000 wrote:
| I agree that there are a lot of dark patterns. Thats
| probably more the product and marketing team though
| wouldn't you agree?
| skilled wrote:
| You're right. I have removed the "clown" part, because after
| submitting my comment it left an itch in me, too. I think I
| have seen too much bad press about GoDaddy that "simple"
| things like this just bring out the worst in me. Thanks for
| pointing that out.
| localghost3000 wrote:
| We all do it. I say stuff in the heat of the moment too. I
| appreciate your willingness to change the wording. Very "un
| HN like" lolol! :)
| bilekas wrote:
| > A GoDaddy spokesperson was not immediately available for
| comment when contacted by BleepingComputer earlier today
|
| This is just a sign of GoDaddy's complacency. I use Godaddy for
| domain registrations only. Yet I had my account taken over with a
| sim card attack/swap and they spent so long to fix the issue that
| domains where transfered without locking.
|
| Web Hosting, particularly 'shared' hosting is extremely prone to
| regular banal attacks and requires extreme constant attention,
| customers less tech savvy would choose it for the very reason
| they know the Godaddy name, they're expecting them to look after
| the tech work.
|
| A Multi-Year breach is an incredible display of incompetence and
| neglect. I have no idea what the security/monitor team are doing
| there but someone definitely dropped the ball, especially given
| the fact they admit that the 2020 break was related. It should
| have been and open and shut case from there.
| reaperducer wrote:
| _A GoDaddy spokesperson was not immediately available for
| comment when contacted by BleepingComputer earlier today_
|
| As someone who has waited on hold with GoDaddy support for over
| six hours on multiple occasions, this does not surprise me.
___________________________________________________________________
(page generated 2023-02-17 23:01 UTC)