Namecheap 将我的账户交给了一个未经验证的第三方,仅仅因为他们提出了请求。
我已经是NameCheap的客户13年了。我还帮助过一个老大学社团支付他们使用的一个.com域名(该域名以我的名字、地址和电话号码注册)。在最近的一次领导交接中,新任社团负责人想对DNS进行更改,但不知道要联系我。他们发现该域名停放在NameCheap上,于是使用该域名发起了密码重置。我收到了密码重置的邮件,立刻提交了一个NameCheap的支持工单,说明“我并没有发起这个请求”。他们给我打电话确认我是提交工单的人,然后又发了一封模板邮件,里面有一些建议,比如检查你的防病毒软件。
然而,新任社团负责人很执着,拨打了NameCheap的支持电话。他说服他们以我名义和地址注册的域名实际上属于他的社团,而NameCheap在没有任何验证或确认的情况下,竟然更改了我的密码,并更改了与我账户关联的电子邮件地址。这一切仅仅是因为有人在电话中礼貌地请求。
与此同时,后台有人告诉新社团负责人我是谁,我们得以联系并完成了转移。最终,我很乐意给他们访问权限,甚至如果他们想要的话,完全转让所有权(考虑到学生社团的人员更替,域名很可能不会续费而被抢注,这也是我一直为他们保持域名有效的原因)。
但NameCheap对此毫无所知。在NameCheap看来,这只是我的个人账户。他们证明了他们完全能够打电话给我(以验证我最初的支持工单),但当有人打电话告诉他们“我真的想要访问那个账户”时,他们却不愿意采取行动?
我甚至不愿称之为社会工程。这显然是一个巨大的漏洞。在看到第三方如此轻易地完全接管一个NameCheap账户后,我已经将我最重要的十几个域名迁出了NameCheap:只需礼貌地请求即可。
查看原文
I’ve been a NameCheap customer for 13 years. I’ve also helped out an old college club paying for a .com they use (that is registered to me under my name, address, and phone number). During a recent leadership transition, the incoming club lead wanted to make changes to the DNS and didn’t know to contact me. They figured out the domain name was parked at NameCheap, so they initiated a password reset using the domain name. I got a password reset email and immediately filed a NameCheap support ticket saying “I did not initiate this”. They called me to verify I was the one who filed the ticket, and then followed up with a canned email with tips like check your anti-virus.<p>The incoming club leader was persistent though, and called NameCheap support. He convinced them the domain registered in my name and address really belonged to his club, and with no verification or validation whatsoever, NameCheap changed my password, and changed the email address associated with my account. All because someone simply asked nicely on a phone call.<p>Meanwhile in the background, someone advised the new club leader who I was and we were able to connect and get things transferred over. Ultimately I was happy to give them access or even ownership if they wanted (student club turnover being what it is, it’s likely a domain doesn’t get renewed and gets gobbled up by a squatter, which is why I was keeping it current for them).<p>But NameCheap had no way of knowing any of this. As far as NameCheap was aware, this was a personal account of mine. They demonstrated they were perfectly able to pick up a phone and call me (to verify my initial support ticket) but when someone calls them and says “but I really want access to that account” they don’t bother?<p>I’d hesitate to even call this social engineering. It’s clearly a massive vulnerability. I’ve already moved a dozen of my most critical domains out of NameCheap after seeing just how easy it is for a third party to completely take over a NameCheap account: just ask nicely.