Namecheap Gave My Account to an Unverified Third Party Just Because They Asked
摘要
作者称在 Namecheap 注册 13 年的个人账户,因旧大学社团域名问题,第三方领导致电客服声称域名归属社团,客服未做任何验证即更改密码和关联邮箱。作者此前已通过支持工单验证身份并接到 Namecheap 电话确认,但客服未对来电方进行类似核实。作者本愿转让域名,但指出此举暴露重大漏洞,已将 dozen 个关键域名迁出。
荐读理由
这个自述显示 Namecheap 支持接电话就被第三方说服直接改密码和邮箱,你因此知道该把关键域名从这类服务商尽快移出,避免账号被轻易接管的风险
原文
I’ve been a NameCheap customer for 13 years. I’ve also helped out an old college club paying for a .com they use (that is registered to me under my name, address, and phone number). During a recent leadership transition, the incoming club lead wanted to make changes to the DNS and didn’t know to contact me. They figured out the domain name was parked at NameCheap, so they initiated a password reset using the domain name. I got a password reset email and immediately filed a NameCheap support ticket saying “I did not initiate this”. They called me to verify I was the one who filed the ticket, and then followed up with a canned email with tips like check your anti-virus.
The incoming club leader was persistent though, and called NameCheap support. He convinced them the domain registered in my name and address really belonged to his club, and with no verification or validation whatsoever, NameCheap changed my password, and changed the email address associated with my account. All because someone simply asked nicely on a phone call.
Meanwhile in the background, someone advised the new club leader who I was and we were able to connect and get things transferred over. Ultimately I was happy to give them access or even ownership if they wanted (student club turnover being what it is, it’s likely a domain doesn’t get renewed and gets gobbled up by a squatter, which is why I was keeping it current for them).
But NameCheap had no way of knowing any of this. As far as NameCheap was aware, this was a personal account of mine. They demonstrated they were perfectly able to pick up a phone and call me (to verify my initial support ticket) but when someone calls them and says “but I really want access to that account” they don’t bother?
I’d hesitate to even call this social engineering. It’s clearly a massive vulnerability. I’ve already moved a dozen of my most critical domains out of NameCheap after seeing just how easy it is for a third party to completely take over a NameCheap account: just ask nicely.
这条对你有帮助吗?