<div dir="ltr"><div>If the evildoers got the content lock stock and barrel, they broke in somehow. If someone hijacked the domain, and setup emails to reverse acquire accounts bound to it, then sure, they could do almost whatever via password resets. Who actually uses 2fa?</div><div><br></div><div>The alternative is someone cloned the site, which if basic is theoretically possible, but if something like wordpress with a db backend, he got gaffled somehow. Reverse engineer how they broke into all the accounts, but see above. It's enough to spook someone into paying up probably, when all they did was clone the content, which is probably doable via various archival crawling methods ala google spiders and wayback machine.<br></div><div><br></div><div>-mb<br></div><div><div><div><div dir="ltr"><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Sat, Jul 23, 2022 at 7:12 AM <<a href="mailto:techlists@phpcoderusa.com">techlists@phpcoderusa.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><br>
<br>
On 2022-07-22 19:01, Michael Butash via PLUG-discuss wrote:<br>
> In my experience, when a domain goes up for grabs, the registrar<br>
> basically usurps it and auctions it off with first right of refusal<br>
> having it under their stewardship in the first place as registrar. I<br>
> saw this with <a href="http://butash.com" rel="noreferrer" target="_blank">butash.com</a> [1], of which I own .net and .org, but the<br>
> dude that owned .com was old, and I think died finally. I had a<br>
> godaddy domain update and saw it go up for sale as an auction on<br>
> verisign, where he had it registered all these years (guess he never<br>
> heard he could get a much better deal elsewhere). Some dude outbid me<br>
> for like 700 bucks, said screw it, not that much worth it. Some year<br>
> or so later had a buddy hit him up (so as not from <a href="http://butash.net" rel="noreferrer" target="_blank">butash.net</a> [2] for<br>
> obvious value), but the scab came back "we'll start bidding at $35K".<br>
> He's been sitting on it since as I didn't put his kids through college<br>
> and apparently no one else in my lineage has either.<br>
> <br>
<br>
There is a couple domains I'd like to get that are being held w/o being <br>
used. A domain is only what someone is willing to pay for it.<br>
<br>
<br>
> So yes, verisign, godaddy, etc will all grab your shiz and sell it out<br>
> from under you if they can, then the domain hoarder scabs soak them up<br>
> hoping someone wants it back bad enough. Vermin, the whole lot, like<br>
> zombies roaming the streets for brains. I was working at godaddy when<br>
> Parsons figured out it'd be a huge market to do domain auctions and<br>
> started that back in the day. I thought it was scummy having worked<br>
> for him then, and didn't work for him much longer after.<br>
<br>
I worked for GD in the very early days. Learned a lot and got a bunch <br>
of experience talking tech to non-technical people. Helped me <br>
tremendously when I started freelancing. The GD experience was hell <br>
though. Back then they fired people for little cause and the call center <br>
manager was a bully.<br>
<br>
The thing I am really wondering about is how this dude was able to <br>
transfer my friends website and content from my friend's hosting to his <br>
hosting. This has to be a copyright violation. What say you?<br>
<br>
> <br>
> -mb<br>
> <br>
> On Fri, Jul 22, 2022 at 6:45 PM Keith Smith via PLUG-discuss<br>
> <<a href="mailto:plug-discuss@lists.phxlinux.org" target="_blank">plug-discuss@lists.phxlinux.org</a>> wrote:<br>
> <br>
>> Hi,<br>
>> <br>
>> I have a friend who owned <a href="http://www.nationwidedr.com/" rel="noreferrer" target="_blank">http://www.nationwidedr.com/</a> . It expired<br>
>> <br>
>> along with his hosting while he was in the hospital.<br>
>> <br>
>> I get the domain was available to be registered.<br>
>> <br>
>> Here is the interesting part. Somehow the new domain owner also was<br>
>> <br>
>> able to get his WordPress website complete with all of his business<br>
>> content. It appears not to have been changed.<br>
>> <br>
>> The other part is the domain shows it was registered in 2002, the<br>
>> original date it was registered. I thought when a domain expires<br>
>> and is<br>
>> re-registered by another it will show it was original registered on<br>
>> that<br>
>> second date. Am I wrong?<br>
>> <br>
>> Thoughts on how the new registrant got a hold of my friends<br>
>> WordPress<br>
>> website?<br>
>> <br>
>> The domain and hosting were at GoDaddy.<br>
>> <br>
>> Something seems fishy - am I wrong?<br>
>> <br>
>> Thanks!!<br>
>> ---------------------------------------------------<br>
>> PLUG-discuss mailing list - <a href="mailto:PLUG-discuss@lists.phxlinux.org" target="_blank">PLUG-discuss@lists.phxlinux.org</a><br>
>> To subscribe, unsubscribe, or to change your mail settings:<br>
>> <a href="https://lists.phxlinux.org/mailman/listinfo/plug-discuss" rel="noreferrer" target="_blank">https://lists.phxlinux.org/mailman/listinfo/plug-discuss</a><br>
> <br>
> <br>
> Links:<br>
> ------<br>
> [1] <a href="http://butash.com" rel="noreferrer" target="_blank">http://butash.com</a><br>
> [2] <a href="http://butash.net" rel="noreferrer" target="_blank">http://butash.net</a><br>
> ---------------------------------------------------<br>
> PLUG-discuss mailing list - <a href="mailto:PLUG-discuss@lists.phxlinux.org" target="_blank">PLUG-discuss@lists.phxlinux.org</a><br>
> To subscribe, unsubscribe, or to change your mail settings:<br>
> <a href="https://lists.phxlinux.org/mailman/listinfo/plug-discuss" rel="noreferrer" target="_blank">https://lists.phxlinux.org/mailman/listinfo/plug-discuss</a><br>
</blockquote></div></div></div></div></div>