Web Hosting Talk







View Full Version : "bug" in ev1servers.net domain control panel(attention newbies!)


e-view
01-24-2005, 07:31 PM
Hello WHT,


I feel like i have to write about it. Because our company almost lost 32 domain names, and adjacent - almost 350!

I call it bug. You call it what ever you like. Main thing, what its very easy to make small fateful mistake and your domains is going for a walk.

Ok, our example.

One our client, refugee from (callit)bestcompany.com asked us to renew
domain name. We asked if bestcompany.com if they could transfer domain name to
us or give full control, so we could renew it. They refused to provide full control, instead created a sub-user.
We logged in at https://manage.opensrs.net and saw, what we can change Admin contacts, Name servers and something else. Ok, i changed Admin contacts to our companies, and went to www.ev1servers.net. Then i entered our costumers domain and asked if system could sent password. Woila! Costumersdomain.com had Admins email info setuped on our email, so it had to sent it. We got password,logged in and BINGO. There is all bestcompany.com domains. They had main account and added domain after domain... just bag it into one account.

I know it stupid and maybe some of you will carefully look at what you are doing... but some of us(especial newbies) want best for costumer and gives full access (enables Billing, Admin, Owner contact info changes). You cannot give access to change Admin info. Otherwise you can lost all you account.

:)
(sorry for my language... wish there could be embed spell checker:) )


Good luck :)

nameslave
01-24-2005, 08:45 PM
First off, this is NOT an EV1Servers.net's thing but that of Tucows/OpenSRS.

Secondly, I wouldn't call it a bug at all, since that stupid hosting company should NOT a) hold all their clients' domains in 1 single account and b) when they relinquish control, they should have created a new account just for that leaving client and render login of that newly created account.

e-view
01-25-2005, 06:33 AM
Thing is what its too easył to make a mistake.
a) then why is "bulk" registration for?
b) there is function "create sub-user". bestcompany.com didnt wanted to relinquish control. They simply thought, what after creating subuser they'll still have root rights but at the same time user will be able to change info by himself.

:/

ajaspers
01-25-2005, 08:19 AM
bestcompany.com should have created a sub-account that can only change nameservers.

Maxo
01-25-2005, 08:28 AM
I agree with nameslave. It is not EV1 problem. It is a problem of the hosting company, not taking enough security measures.

eSology
01-25-2005, 09:19 AM
Best solution is to avoid horrible counter-intuitive control panels.

After 6 months with the openSRS control panel I walked away and never looked back. The good thing is you "almost" lost them but didn't. Be happy you didn't.

SoftWareRevue
01-25-2005, 03:13 PM
Perhaps it has something to do with understanding what a sub-user account is?Create/Manage a Sub-User

You may add an additional username and password associated with this domain in order to allow multiple people to update your records. You can restrict access for this sub-user to allow only certain records to be modified