GoDaddy security system under fire
Posted by: Timothy Weaver on 03/20/2015 08:54 AM
[
Comments
]
Vinny Troia, CEO of security firm Night Lion Security, was able to convince GoDaddy to hand over account control of a domain with only a fake ID (and a little bit of good, old-fashioned chutzpah).
Troia did not know the account's PIN or credit card details or have access to its listed email account, but as a challenge instigated by journalist Steve Ragan, he revealed that despite multiple layers of security GoDaddy remains wide open to social engineering.
Troia claimed he didn't know the account pin nor the last four numbers of the credit card question by explaining that an underling set up the account. And as for the email address, he explained that there was "a lot of office politics at the moment that I didn’t feel like getting into."
In order to lend credibility to the scam, he set up a fake social media account and set up a Gmail address. He also used Photoshop to create a fake Indiana driver's license, creating a fake ID as evidence of his true identity.
Four days, some email exchanges and some old fashioned guts and GoDaddy handed over the access to Ragan's account.
Troia said by exposing the security flaw, GoDaddy will "implement tougher verification procedures".
GoDaddy has nearly 60 million domains under management and 13 million customers.
Source: The Register.UK

Troia claimed he didn't know the account pin nor the last four numbers of the credit card question by explaining that an underling set up the account. And as for the email address, he explained that there was "a lot of office politics at the moment that I didn’t feel like getting into."
In order to lend credibility to the scam, he set up a fake social media account and set up a Gmail address. He also used Photoshop to create a fake Indiana driver's license, creating a fake ID as evidence of his true identity.
Four days, some email exchanges and some old fashioned guts and GoDaddy handed over the access to Ragan's account.
Troia said by exposing the security flaw, GoDaddy will "implement tougher verification procedures".
GoDaddy has nearly 60 million domains under management and 13 million customers.
Source: The Register.UK
Comments