[HN Gopher] GoDaddy: Hackers stole source code, installed malwar...
       ___________________________________________________________________
        
       GoDaddy: Hackers stole source code, installed malware in multi-year
       breach
        
       Author : razin
       Score  : 165 points
       Date   : 2023-02-17 18:16 UTC (4 hours ago)
        
 (HTM) web link (www.bleepingcomputer.com)
 (TXT) w3m dump (www.bleepingcomputer.com)
        
       | [deleted]
        
       | miked85 wrote:
       | I honestly can't believe this company is still in business - it's
       | been terrible for decades.
        
         | webdood90 wrote:
         | have you been using it for decades? or do you just read the
         | headlines to form an opinion?
         | 
         | there are a ton of hard working people at GD that care a lot
         | about the products we make. I don't think that's a fair
         | assessment.
        
       | vxNsr wrote:
       | Wow, multi-year is truly embarrassing. Hosts being compromised is
       | the the worst case scenario because the attacker can decide who
       | to serve the malware to in a spearphishing fashion.
        
         | jeroenhd wrote:
         | It happens to more companies than you'd imagine, even big ones.
         | Security monitoring and logging is hard to get right,
         | especially if you try to add it to a previously insecure
         | system.
         | 
         | A smart attacker can hack your company unnoticed and passively
         | watch your company for the right moment to strike. I doubt that
         | the hackers logged into the office VPN every day.
        
       | anonzzzies wrote:
       | Godaddy. One of the most horrible companies. Always was. Bob
       | Parsons is a sad individual with many lovely quotes attesting to
       | that fact. Hope this ends them.
        
       | avsteele wrote:
       | This might solve a big mystery for me.
       | 
       | When I first set up my company's website it was hosted at
       | GoDaddy. Totally static site. It got 'hacked' one day, with new
       | php files and redirecting users to some nonsense. This was August
       | 2016. The ftp server had a very long, random password. I changed
       | it again after this.
       | 
       | It happened *again* March 2017, though different files were
       | added. After this I moved my site to Digital Ocean.
       | 
       | I never found out how this happened.
       | 
       | Does anyone know how long this has been going on? The article
       | didn't give a definitive start date.
        
         | iLoveOncall wrote:
         | You can have the longest password in the universe and change it
         | after every login, if you have a keylogger on your computer it
         | doesn't matter.
        
           | sn_master wrote:
           | or someone sniffing your network. FTP isn't encrypted.
        
       | muttantt wrote:
       | I feel bad for the hackers that now need to read through
       | GoDaddy's code...
        
       | dylan604 wrote:
       | Long long ago, I needed a new website hosted and with no other
       | decision towards the host than I had never tried GoDaddy, I gave
       | it a shot. Within hours, I regretted the decision immensely. In
       | comparison to my previous hosting experiences, it just pissed me
       | off at almost every turn. It was the first time I experienced a
       | company trying to make the interface for non-techy types and made
       | getting to the guts of the tech hidden behind many layers that
       | just frustrated me to no end. I canceled my account and have
       | never looked back.
       | 
       | It is just another one of the examples of a company that
       | advertises that intensely is probably a company I don't really
       | want to be involved.
        
         | chanandler_bong wrote:
         | They did have a couple of years with good commercials, though.
         | 
         | https://www.dailymotion.com/video/x9v5p4
        
         | mixmastamyk wrote:
         | I tried it once as well, maybe ten years ago. The annoying
         | thing not yet mentioned is that it tries to upsell you at every
         | step. You quickly realize that steps have been added for
         | additional upsell opportunities.
         | 
         | Then the "elephant shooter" drama happened and I moved to
         | namecheap and didn't look back. Was a breath of fresh air in
         | comparison.
         | 
         | I didn't see a way to delete my gd account, so think it is
         | still there. Hope my data didn't get out again. :doh:
        
           | favourable wrote:
           | > The annoying thing not yet mentioned is that it tries to
           | upsell you at every step
           | 
           | I turn it into a game. I love the feeling of having cheated
           | their systems and cleverly opting out of all the up-sells. I
           | am forced to use GoDaddy because I have profitable blogs and
           | e-commerce stores which would be a holy war trying to migrate
           | all that to other services. It's do-able, but would be a
           | headache and a half.
        
             | eclipticplane wrote:
             | > I am forced to use GoDaddy because I have profitable
             | blogs and e-commerce stores
             | 
             | Ever _more_ reason to migrate them, imo.
        
           | qwertox wrote:
           | The only thing that annoys me from Namecheap is that their
           | API isn't that good. You can't just update a single record,
           | you have to update the entire zone.
           | 
           | Updating the entire zone just to automatically set a
           | verification token (like for Let's Encrypt) is too risky.
        
         | bombcar wrote:
         | It's sad because I used to remember a long LONG time ago they
         | exposed a bunch of things that other registrars required you to
         | email or call support to do. That stuff is still there, but
         | otherwise the whole site just feels slimy.
        
         | mmcgaha wrote:
         | They are the only company that ever hijacked my robots.txt.
        
           | convolvatron wrote:
           | wtf? what does that look like?
        
         | groestl wrote:
         | For me, this company was Network Solutions. Never have I ever
         | dealt with a thing so bizzare. They even uppercased my email
         | address when communicating with me.
        
           | kstrauser wrote:
           | There were a tiny company and couldn't afford the mixed-case
           | terminals.
        
       | sn_master wrote:
       | I'll never use GoDaddy. They've been fronting their customers for
       | literally decades. Few times I searched for a domain, the next
       | day I search for it find it already reserved by them and on sale
       | for hundreds of dollars instead of the regular $10 it was the day
       | before. They've been abusing their power for as long as they've
       | been in business.
        
         | krimpenrik wrote:
         | Share the same experiences. When godaddy comes up I feel
         | obligated to share. Avoid at all costs
        
         | 2pEXgD0fZ5cF wrote:
         | > Few times I searched for a domain, the next day I search for
         | it find it already reserved by them and on sale for hundreds of
         | dollars instead of the regular $10 it was the day before.
         | 
         | I can confirm this experience, on 2 occasions when I looked up
         | a very specific (and definitely not common) domain, they were
         | suddenly reserved by GoDaddy and sold for a premium price. Not
         | hundreds, but like 50-150 instead of 12.
         | 
         | I can't prove it, of course, but after hearing about those
         | problems with GoDaddy multiple times it just seems too
         | convenient for them to be a coincidence.
        
         | tehlike wrote:
         | One other explanation (though i am fairly certain godaddy was
         | fronting you), is if they include any third party ping/script
         | etc, and that script/ping gets referrer or the url of the page,
         | someone malicious 3p could also do this...
        
         | codetrotter wrote:
         | > Few times I searched for a domain, the next day I search for
         | it find it already reserved by them and on sale for hundreds of
         | dollars instead of the regular $10 it was the day before.
         | 
         | I don't understand how that could possibly be profitable.
         | Imagine how many searches there must be for new domains every
         | day. There is no way they could afford to buy all of the
         | domains that people searched for.
         | 
         | And if they had any means of measuring how "good" a domain name
         | is, in order to filter the searches that people make, and front
         | run only the ones looking for good domain names - I don't think
         | that would make sense either. If you were able to reliably
         | measure how good a domain name was you could just buy the
         | domain name right away without waiting for any customers to
         | search for the domain.
         | 
         | Anyway, for anyone that is looking for a registrar to use I
         | recommend that you stay away from GoDaddy. Register your
         | domains with Gandi.net, they are nice and good.
         | https://www.gandi.net/en-GB
        
           | sn_master wrote:
           | > I don't understand how that could possibly be profitable.
           | 
           | Because registrars have the power to "reserve" domains they
           | like for some time either for free or for only a pennies.
           | 
           | https://en.wikipedia.org/wiki/Domain_tasting
        
             | NationalPark wrote:
             | Godaddy is a crappy company for many reasons, but this
             | seems like something that's trivially testable. If they
             | were really front running domains, anyone could spend an
             | hour typing domains in and see a bunch of them mysteriously
             | registered by godaddy the next day. Has nobody done that?
             | Why can't I find any blogs where this was attempted?
        
               | mirzap wrote:
               | They must have some algo that rates domain quality. It
               | happened to me recently, so it's not bullshit. They do
               | front running, but they have some sofisticated scheme
               | behind it.
        
               | jerf wrote:
               | It is trivially testable. I've tested it myself a few
               | times, against a few different companies, just for fun.
               | I've never seen it happen.
               | 
               | If you imagine ordering all the domains in order of
               | desirability, where the most desirable are long gone, and
               | nobody wants "nsejrx8oesrjasrjb.com" (and even if they
               | want an obfuscated domain, they don't want _that_
               | obfuscated domain), there is a middle ground where it 's
               | not worth pre-registering but if you see an indication of
               | interest it may push you over, especially if you have a
               | cheap back door for registration as registrars do. In
               | that case, the only ones sensible to front-run are the
               | ones in that middle ground. It is possible that I never
               | chose a domain that triggered such an algorithm. That
               | said, as I was aware of this possibility at the time, I
               | did deliberately try to come up with a combination of
               | tasty & tempting words in a new format that looked like
               | maybe someone would really want it, and I never could get
               | the hypothetical algorithms to bite.
               | 
               | Take a crack at it if you're interested; it really isn't
               | that hard or a big investment in time.
        
               | bmelton wrote:
               | This happens a lot. Godaddy comes up in the news, someone
               | accuses them of front-running, someone else investigates
               | the accusation and finds that the allegation in question
               | was definitely not the result of front-running.
               | 
               | https://domaininvesting.com/godaddy-still-not-
               | frontrunning-d...
               | 
               | I have no information on whether they are or aren't
               | front-running, but every time I've seen a _specific_
               | allegation, it 's been disproven. That doesn't make it
               | factual either way, but I like Godaddy for enough other
               | reasons to not use them, so I don't particularly care if
               | they are or aren't, but I've yet to see a specific
               | allegation be found credible.
        
             | [deleted]
        
       | legrande wrote:
       | GoDaddy is a very complex thing. And bugs lurk in complexity. No
       | wonder.
        
         | dylan604 wrote:
         | Are you saying that other hosting companies in the same level
         | of complexity are just better, or possibly alluding that other
         | companies might not be upfront about things occurring within
         | their orgs? Either way, it really sounds a lot like you're
         | minimizing the negligence and just poorly run company.
        
       | goodfight wrote:
       | I feel like this may be the same case at PayPal too. Identity
       | theft and random emails were not even intended for me was my
       | experience.
        
       | jasonlotito wrote:
       | I hate blaming the victim, but so much bad press had come out
       | against GoDaddy it's like complaining that the bear hurt you when
       | you went into it's den and disturbed it.
       | 
       | Friends don't let friends use GoDaddy.
        
       | rdiddly wrote:
       | So was this a breach of cPanel that therefore could affect other
       | providers that use cPanel?
        
       | youniverse wrote:
       | Anyone want to recommend their favorite alternative web hosts?
       | 
       | I've tried A2 and NameHero and both were very solid along with
       | fast/great support.
       | 
       | Anything else I should look into?
        
         | chriscjcj wrote:
         | For DNS, I have been using Gandi (1) for the last yen years or
         | so and have been very happy with them. I originally went with
         | them because they were one of the few registrars that did the
         | .cat TLD. I liked the experience and eventually transferred all
         | of my domains to them.
         | 
         | They are a french company. Their slogan is "No Bullshit," (2)
         | and I think they've done a decent job of living up to that.
         | 
         | My only frustration has been a situation where I was
         | transferring an existing domain over to them. I wanted to
         | create the zone file ahead of time so that when the transfer
         | happened, there would be an identical zone file ready to go.
         | But they wouldn't allow me to create a zone file for a domain
         | that hadn't transferred over to them yet. Since I'm not doing
         | anything critical with my domains, it was just an annoyance,
         | but that would be a show-stopper for some.
         | 
         | As it pertains to billing problems, they allow you to pre-pay a
         | chunk of money to your account. (They take PayPal.) It deducts
         | from that amount when domains renew. That provides a buffer if
         | you need to cancel your credit card.
         | 
         | Also, on the occasions that I have created trouble tickets,
         | they have been responded to in a reasonable amount of time with
         | helpful information.
         | 
         | (1) https://www.gandi.net (2) https://www.gandi.net/en/no-
         | bullshit
         | 
         | For web hosting, I used Bluehost for many years and because
         | extremely dissatisfied with them. I switched to Siteground.com
         | about five years ago and have very little to complain about.
        
         | disadvantage wrote:
         | https://www.gandi.net/en
         | 
         | https://www.ovhcloud.com/en/
         | 
         | https://asmallorange.com/
         | 
         | There are many others I can vouch for. There's a good list of
         | them here[0]. Make sure to choose ones that have proper 2FA as
         | it's a good heuristic for how well they consider security.
         | 
         | [0] https://2fa.directory/int/#hosting
        
           | Aachen wrote:
           | OVH is always an exercise in broken UI including terms of
           | service that seem to be copied from a pdf and have random
           | artifacts. It's probably the worst buying experience I've had
           | since the naughties and nothing changed in the years I'm with
           | them now.
           | 
           | ...but they're cheaper than other registrars known for being
           | cheap, and I've monitored their nameservers (and a few
           | others') for nearly a year before switching away from my
           | previous registrar and they were consistently fast whereas
           | others had spikes, outages, or constantly round robined
           | across oceans or some such.
           | 
           | Quality servers at very low prices makes me put up with some
           | broken UI for a few minutes per renewal.
        
             | blfr wrote:
             | OVH is cheap and supports U2F. I have a bunch of stuff with
             | them.
        
         | kennydude wrote:
         | My stuff is with Krystal who are fantastic. Had a ticket
         | resolved by them on Christmas day within 2 minutes
         | 
         | (i have a discount/referral code if you want it - contact form
         | on website)
        
         | [deleted]
        
       | greatgib wrote:
       | "We have evidence, and law enforcement has confirmed, that this
       | incident was carried out by a sophisticated and organized group"
       | 
       | I like how they try to hide their incompetence with bullshit
        
         | sophacles wrote:
         | Law enforcement (to GoDaddy): "well it went on for years from
         | what we can tell. Whoever did this is more sophisticated than a
         | bunch of impulsive teenagers 'joyriding'".
         | 
         | GoDaddy PR (to world): The attackers were sophisticated, the
         | cops said so!
        
       | skilled wrote:
       | What a disgrace of a platform. I'd understand dropping a c99 on a
       | cPanel back in early 2000s but these days? What are the engineers
       | doing at the company, collecting a paycheck and pretending to do
       | work?
       | 
       | Speaks volumes for the culture being cultivated at GoDaddy.
        
         | Tostino wrote:
         | I feel like a lot of these older platforms are being shown to
         | be as rickety as they actually are, as malware and hacking
         | toolkits improve and proliferate. Bad practices are going to
         | show through, bigtime with this next cold war the US is
         | entering.
        
           | dylan604 wrote:
           | i would not be surprised if their back end is still a bunch
           | of old skool perl scripts in the cgi folder that were l33t
           | coded back in the day, but nobody now can even start to parse
           | the perl itself.
           | 
           | switching from impossible to read perl scripts to flavor-of-
           | the-day language would be a use case i can actually get
           | behind and support for replacing.
        
         | localghost3000 wrote:
         | I agree that this is bad but I'd encourage you to rethink your
         | comment. The "clown engineers" you are calling out maintain a
         | level of uptime and scale thats hard to for most people to
         | imagine. You don't do that by being an idiot.
         | 
         | Instead of calling them names and assuming bad intent, maybe
         | take a second to think about how much it must suck for them
         | right now. I'm sure it's all hands on deck nights/weekends to
         | fix. No one sets out to do a bad job in my experience.
        
           | jayess wrote:
           | Godaddy has the most user-hostile platform of any domain
           | registration company I've ever encountered in the 25+ years
           | I've been registering domains. It's utter garbage in every
           | way.
        
             | localghost3000 wrote:
             | I agree that there are a lot of dark patterns. Thats
             | probably more the product and marketing team though
             | wouldn't you agree?
        
           | skilled wrote:
           | You're right. I have removed the "clown" part, because after
           | submitting my comment it left an itch in me, too. I think I
           | have seen too much bad press about GoDaddy that "simple"
           | things like this just bring out the worst in me. Thanks for
           | pointing that out.
        
             | localghost3000 wrote:
             | We all do it. I say stuff in the heat of the moment too. I
             | appreciate your willingness to change the wording. Very "un
             | HN like" lolol! :)
        
       | bilekas wrote:
       | > A GoDaddy spokesperson was not immediately available for
       | comment when contacted by BleepingComputer earlier today
       | 
       | This is just a sign of GoDaddy's complacency. I use Godaddy for
       | domain registrations only. Yet I had my account taken over with a
       | sim card attack/swap and they spent so long to fix the issue that
       | domains where transfered without locking.
       | 
       | Web Hosting, particularly 'shared' hosting is extremely prone to
       | regular banal attacks and requires extreme constant attention,
       | customers less tech savvy would choose it for the very reason
       | they know the Godaddy name, they're expecting them to look after
       | the tech work.
       | 
       | A Multi-Year breach is an incredible display of incompetence and
       | neglect. I have no idea what the security/monitor team are doing
       | there but someone definitely dropped the ball, especially given
       | the fact they admit that the 2020 break was related. It should
       | have been and open and shut case from there.
        
         | reaperducer wrote:
         | _A GoDaddy spokesperson was not immediately available for
         | comment when contacted by BleepingComputer earlier today_
         | 
         | As someone who has waited on hold with GoDaddy support for over
         | six hours on multiple occasions, this does not surprise me.
        
       ___________________________________________________________________
       (page generated 2023-02-17 23:01 UTC)