How the Domain Names are Hijacked?

How the Domain Names are Hijacked?

No! This is not an article to help or encourage anyone trying to hijack a domain. Rather, this is like an eye-opener and a wake-up call for all those ignorant web-masters to secure their website domains.

From Wiki: Domain hijacking or domain theft is the process by which registration of a currently registered domain name is transferred without the permission of its original registrant, generally by exploiting a vulnerability in the domain name registration system.

Any website consists of 2 parts – a Domain Name System (or DNS) and a web-hosting server (where files reside). What this means is, in reality domain name and web server are 2 completely different entities and are integrated together before the website goes live.

When someone registers a domain name (say example.com) with a domain name registrar (like GoDaddy or Namecheap), he gets to use a control panel provided by the registrar. Using this control panel, he would have to point his domain to his web servers which might be hosted elsewhere. Now whenever an Internet user types “example.com”, the domain name “example.com” is resolved to the target web server and the web page is displayed.

How the Domain names are Hijacked?

A domain can be hijacked only when the domain’s control panel is compromised. In order to gain access to the control panel, you would need these 2 details about the domain

1. The domain registrar name and
2. The administrative email address associated with the domain.

Getting these 2 details is not too tough. Just use a WHOIS service (like DomainTools or whois.net) to lookup the details related to that domain. Under WHOIS Record, you will get to see both the registrar name and the administrative contact email address.

This administrative contact email address is the key to hijack a domain. Once the hacker hacks into this email’s inbox, he will be able to change and control the domain as he likes. Now, hacking an email is a completely different topic. Usually a hacker sends a phishing email containing a fake login page, fooling the user to reveal his email id and password. More sophisticated ways include using keyloggers embedded within an email.

Once the hacker takes full control of this email account, he visits the domain registrar’s website and click on forgot password in the login page. There he will be asked to enter either the domain name or the administrative email address to initiate the password reset process. Once this is done all the details to reset the password will be sent to the administrative email address. Since the hacker has the access to this email account he can easily reset the password of domain control panel. After resetting the password, he logs into the control panel with the new password and from there he can hijack the domain within minutes.

How to Protect your Website Domain from Hijacking?

If you have read the above part carefully, you would already know the answer for the current question. Yes! keeping your administrative email address associated with your domain secure and safe is the key. I would suggest you to go for private domain registration or WHOIS guard privacy. This would cost you around $3 per year or sometimes, you might get it for free as well.

When you register a domain name using the private registration option, all your personal details such as your name, address, phone and administrative email address are hidden from the public. So when a hacker performs a WHOIS lookup for you domain name, he will not be able to find your name, phone and administrative email address. So the private registration provides an extra security and protects your privacy.

Even with WHOISGuard ON, people can still contact you via a routing email Id provided by WHOISGuard. Some hackers might try to make use of this routing email id to contact you for link exchange or buying text links, so that they get to know your administrative email address if you choose to reply to their requests. Make sure you don’t entertain such requests coming via WHOIS.

Courtesy techpp.com

要查看或添加评论,请登录

Jai Lakshwani的更多文章

  • Steps to Make for a Professional Website Design

    Steps to Make for a Professional Website Design

    Professional website design is imperative for any type of business if they are looking to use the Internet to exhibit…

  • Good Design Is Good Business

    Good Design Is Good Business

    What a good attractive branding can play a vital role to enhance your business? Creating a brand perception requires…

  • Importance Of Logo in business

    Importance Of Logo in business

    Logo is just as important as your name at the time of branding of your business. The logo is the first visceral…

  • What to do When you Need a Website Redesign

    What to do When you Need a Website Redesign

    As a seasoned small business owner, you’ve probably tracked your sales since the inception of your business until…

  • How to Choose a Web Design Company

    How to Choose a Web Design Company

    Web design companies offer a wide variety of options and styles. There are three general options when it comes to a…

  • Things To Hate About Web Design And How To Fix Them

    Things To Hate About Web Design And How To Fix Them

    If you browse websites as much as we do, then there is a lot of mistakes which make them to hate. There are so many…

  • How to Create Good Web Design

    How to Create Good Web Design

    There are many different types of web design, from those built using website templates and ‘build your own’ site…

  • How to write best title of website

    How to write best title of website

    The title of website is an obvious and easy way of improving your SEO and lets Google know where the site should be…

  • Difference between Shared Web Hosting, Dedicated Web Hosting and VPS

    Difference between Shared Web Hosting, Dedicated Web Hosting and VPS

    Shared Web Hosting Shared Web Hosting also called Budget Web Hosting. If your website won’t require higher resources of…

    1 条评论
  • Mistakes People Do When Searching A Web Design Agency

    Mistakes People Do When Searching A Web Design Agency

    When you are looking to develop a website, it is tempting to look for the cheapest possible solution. It is possible to…

社区洞察

其他会员也浏览了