Web Hosting Talk







View Full Version : Enom account Hacked


FireStormNET
10-21-2005, 06:07 PM
Has anyone here ever had there enom account hacked into.

I logged into my enom account last night, and noticed that, about $75.00 worth of domains had been registered, that I did not register.

I always recieve email notifications on renewels and new registrations from moderngigabyte.com, on these domains no notifications were ever sent.

Also none of these domains were showing up in my domains list, they had just been charged to my balance, the oldest one registered was over 2 weeks old, normaly when I register a domain it shows up in my domains list within about 5 minutes.

Now enom is trying to tell me, that my account was accessed from several different IP's, and the reason that I did not get email notifications was because they must have changed the email address that the notices go to, so I guess they changed it back then, when they were done, becuase that is the first thing I checked when I noticed the bogus registrations, I find that hard to believe, that they would even care to change it back, as they would have used a bogus email account anyway.

For one thing my notices come from moderngigabyte, and not directly from enom, and I dont see anyway that they could have changed moderngigabytes address since it is not visable in my account.

And on the matter of why the domains were not in my domains list that is another story, now enom has pushed them into my domains list, and is refusing to refund the bogus registrations.

Anyone else ever had this kinda crap with enom, I have been looking at ev1's new domain reseller setup, and this looks like a danm good time to make a change.

Jim

gounder
10-21-2005, 07:25 PM
Sad to hear that this happended to you. So you say the eNom has pushed all the registered domain to you account now??

Have you checked the Domain Register Report?

AnyDemo
10-21-2005, 09:19 PM
Hello,

Luckily enough that the guy did not consume all your fund.

FireStormNET
10-21-2005, 09:24 PM
Originally posted by gounder
Sad to hear that this happended to you. So you say the eNom has pushed all the registered domain to you account now??

Have you checked the Domain Register Report?

Yes they have pushed the domains into my domains list, I did check the whois before that , and they came up as registered by enom, not my normal registration, I would guess that now they are showing as being registered to my account.

Jim

dmaven
10-21-2005, 09:43 PM
Are you an ETP or a sub reseller

FireStormNET
10-21-2005, 10:03 PM
Originally posted by dmaven
Are you an ETP or a sub reseller

I have a $7.95 reseller account under modernbill. I have a ticket into them, to see if they recieved anykind of notifications on the registrations, as I always get notifictations from moderngigabyte when anything is done in the account. If what enom says is true, then there, is a flaw in the system, either there should be somekind of set email notifications, that can only be changed by them, or something to prevent this kind of thing from occuring.

Had I received some kind of email notification, then I would have known right off that something was up. My password was I thought secure, a good mixture of random numbers and letters.

So far they have not given me any other information, such as IP's , or email address's that they say were changed, and then changed back.

Jim

Bashar
10-21-2005, 11:09 PM
do you offer sub-accounts?

if a subaccount of urs did chargeback enom usually push the domains into ur account and deduct the fees

dmaven
10-21-2005, 11:41 PM
It seems they are a sub-reseller of modernbill

FireStormNET
10-21-2005, 11:50 PM
Originally posted by Bashar
do you offer sub-accounts?

if a subaccount of urs did chargeback enom usually push the domains into ur account and deduct the fees

No, there are no sub accounts, enom is saying the account was hacked, or rather that someone logged in with the user and pass, changed the notification email address, ordered a domain, changed the email address, back to what it was, and this was done 5 or 6 times in a about 16 days. As I said if this is the case, then there is indeed a flaw in the system, allowing this to happen. There should be some kind of security measure in place, to only allow the email addy's or other important information to be changed only under certain conditions.


Jim

Bashar
10-21-2005, 11:56 PM
yeah maybe email doesn't change unless email notification is sent to the previous email for confirmation.

hamiltonjo
10-22-2005, 09:44 AM
I thought enom was safe?

dmaven
10-22-2005, 12:50 PM
They are safe, they do not seem to have been hacked