Improve Domain Name Security, Lessons Learned From Domain Name Hijacking

by Aqeel Syed on August 28, 2009

Every bad thing, every hard time I faced in my life, I learned some lesson out of it. These lessons were hard to learn. Infact there is a positive attached with domain name securityevery negative situation. Worst times of your life makes you perfect.

Due to recent domain name hijacking I learned how to safeguard your assets online and to protect your identity. I’m at initial stages of my career as a web entrepreneur so this knowledge that I gained during this bad time will help me in the long run. Off course as a reader you can also benefit from my experiences.

So here we go with some quick security tips.

Domain Name Account Protection

Domain names are the cheapest thing when you build a website, you can buy for a few bucks while you pay lot more (hundreds or thousands of dollars) for hosting every year. Imagine if you are left without your domain name (your domain name is hijacked) what you have got? A hosting account with CMS/template files and a database! These files of your website are of no use for you without a domain name.

Its very important to register your domain name with a registrar that is secure and have a proven security record. I registered my domains with Name.com, they have pretty good security on domain accounts. If my account was hacked it was not the fault of domain registrar, my email account got hacked first and then cracker took control of my domain name account.  However Name.com helped me out and I took my account back.

Hint Name.com offer an added layer of security with their name safe service, $20 yearly fee and you are more protected.

If you are looking for a proven security record. The only domain registrar that has a proven security record is Moniker.com. Moniker offers personalized security questions for each of your domain names. Even if someone cracked your ID & password with Moniker, they cannot move or change your domains without answering these security questions.

Domain registrar support service is also very important, what if your account is hacked and you cannot get to their support department for several days? Please research on their support response time before registering with them.

Your domain registrar should not be a reseller. Yes, if your domain registrar is a reseller, if he is a one man company. What if he closes his business or he get ill or die? Or worst move out of country, what will happen to your domain names? People those are registering domain names in India and Pakistan (or other small countries) with local companies are actually registering with domain resellers, these are individuals (with few exceptions) charging you high prices and putting you at a risk. Always register your domains with ICANN aggregated domain registrar.

Email address that you are using when registering domains is also important. If you (or your company) can afford get a secured email account (paid) for your domain names. Don’t go for free email services.  Every time a domain is hijacked the reason come to know is free email services like Gmail, Yahoo! mail or Hotmail.

Use a separate email address for registering domain names, other then your general/personal email address.

Hint You should use a different email address in billing, contact and administration information in domain who is. Don’t use email address that you used with your account registration (account ID). For example, I registered my domain account with email ID xyz@mail.com while in who is information I used abc@mail.com. This way crackers don’t get know what email address is used to register that domain account.

You can also enable domain privacy to hide your contact details.

Network Integrity Monitoring
One thing that save me from lot of trouble in this domain hijack attempt is ‘Network Integrity Monitoring’. When cracker made changes with my domain names, I got an alert in email instantly and upon investigating I discovered that my domain account is compromised. If wouldn’t had ‘Network Integrity Monitoring’ may be it would have been too late for me to know about that. I got this service from sucuri.net. And another amazing this is, this handy service is free to use.

Your PC security is very important. Always use a good firewall, Anti virus and spyware removal software. Use McAfee Site Adviser when surfing online. Keep your windows updated with latest security releases.

Do you have any other ideas? Please feel free to share using comments.

{ 5 comments }

Trouble Finding A Good Domain Name? Try These Domain Tools

by Aqeel Syed on August 26, 2009

search-domain

Worried about finding a good domain name? All one letter and even good 2 – 3 letter domains have been registered and you’re searching for a good domain for your next project. Don’t worry there are still good domains available, all you have to do is be creative and use a good domain suggestion tool. I still manage to register some good domain names with help of these tools.

Bust A Name is at top of these tools. Bust a Name suggests available domain names based on user-defined keywords.

After you add keywords, the tool suggests different available domains using your keywords and suggests synonyms to increase your possibilities. Bust a Name also has a dynamic search a la previously mentioned Instant Domain Search. If you’ve ever tried snagging a descriptive domain, you probably know that finding an unparked domain is a challenge. Bust a Name provides a nice set of tools for finding a good domain without resorting to gibberish and hyphens.

Domain hacks lets you find a domain that combines domain labels, especially the top-level domain (TLD), to spell out the full “name” or title of the domain, making a kind of pun, for example del.icio.us

MakeWords.com has advanced query features that allow you to refine your domain query for starting with, ending with, max letters, language rules random names and more and believe me it works like a magic.

Just Dropped is a website where you can search recently deleted domain names. You can find some good domain names from these recently deleted domain names but beware that there is a chance that you are going to register a domain name banned from search engines or black listed in Adsense.

DomainsBot is a domain search engine, give you suggestions and show availability of domain names. I’d personally used DomainsBot to find some really good domain names. It gives you an inline ajax auto complete feature for searching domain names.

What if your creative sense is dried up? Don’t worry use Word Mixer Enter 5 words and get 2-3 syllable results or use Dot-o-mator for mixing letters and to make up your own words and make up a nifty Web 2.0 domain name.

Split It! Before you finally register a domain name try Split It! It visually shows you how your domain name string will be split. Use this to avoid getting an accidentally funny domain name.

{ 3 comments }

Where was I? What was I doing?

by Aqeel Syed on August 24, 2009

Readers of this blog probably would have been wondering where I am? Or now ‘where was I?’ (as you are reading this post). Its not a long story or even a story :P

I was busy with tightening security of my web servers, hosting accounts, billing systems, office network. As these were the most important things to do for me after cracking of my email account and domain names being hijacked.

Then there was few new projects (new websites) that I was planning to create for last 3 months and wasn’t able to find enough time to get started on these.  So I worked on 2 new projects and on marketing at an existing one, our wonderful blog, The Wondrous. I also prepared a future business plan, this was to set a clear direction for my career.

I’m back after 4 weeks and have decided to become proactive at this blog. I was writing 5 +/- posts a month but have decided now to write more often (few times a week). That means this blog will be update more and you will be reading more money making ideas and tips.

Thank you all my readers for your support and visiting this blog. I’d received few questions from readers though comments, that I will be answering soon.

- Aqeel

{ 0 comments }

My Name.com Account with 14 Premium Domains Hijacked

by Aqeel Syed on July 30, 2009

In past I blogged about domain name hijacking at syedaqeel.com and today I myself become a victim of domain hijacking.

I’d three very hard days,  4 days back my gmail account was hacked somehow and then the hacker cracked my Name.com account from there. I’ve 14 premium domains at Name.com which I was about to lose when I got an automatic alert through Sucuri.net that syedaqeel.com is not available. Domain was giving a 500 internal page error, I thought hosting for that domain is down (its placed on a shared hosting account), I waited for syedaqeel.com to become available. SyedAqeel.com become available after 24 hours, I decided to move it to my dedicated server to avoid further down time.

When I tried to login to my name.com account to change DNS settings, and what I found was surprising, after many tries with right password I was not able to login and when I tried to reset my password it showed that an email is sent at your hotmail.com address.

I was shocked! Yes, email was sent to someone else’s email address, as I used a Gmail account with name.com. It was confirmed that my Name.com account is compromised. My first reaction was to check how it happen and to be true, its almost impossible to crack a name.com account with brute force type attacks, as name.com have very good security.

As I checked who is for syedaqeel.com and thewondrous.com I found that contact, billing and administrator information is changed and a person with name of “Abbas Shafiee” and company name “Yamobile”.

I logged back to gmail and started checking my account that why name.com haven’t sent me a password change or wrong password notification, after going through my account I found some filters, when of them was set by hacker to automatically delete all emails coming from name.com

The first thing I did to check my system for viruses and couldn’t found anything suspicious. Next I changed passwords for all my important accounts.

So who is the cracker?

I Googled to find more about names in who is i.e,  ”Abbas Shafiee” and “Yamobile”. When I dugg deep into results, I found some interesting pages. His full name is “Abbas Sufi Shafiee” and he used to run a blog at yamobile.blogpsot.com and also own a domain yamobile.org hosted at a free web host.

This search reveals that he is an Irani guy and a hacktivists, working against government. Has built some proxies to bypass Irani government’s internet filters. A few forum posts displayed that he is interested in Java scripts and his site at yamobile.org is about keyloggers. He is from Iran but using a fake US address in who is information.

July 28, 2009 at 3:19 PM

I sent an email to name.com informing them that my name.com account is compromised and started waiting for their reply.  After few hours, I sent another email explaining their support in detail, what has happened and requesting to freeze my account so that he can’t transfer domains to any other registrar.

After waiting for 7 hours, I was so worried, so devastated and haven’t got any reply. I tried to contact them through twitter but didn’t found any reply.

It took me 9 hours, 3 emails from 2 different addresses, Twitter tweets, a phone call, a fax and finally a problem report at their GetSatisfaction to contact name.com support.

They sent me a few question, for those I replied promptly, waited for 5 hours to get their reply and guy at support shocked me by telling that it will take them 15 days to complete investigation.

15 days!!! I told their support that these are not just domain laying around, I have full developed websites on these domains & I don’t want to lose my readership.

Any how name.com locked that account so worries were less.

July 29, 2009

To expedite investigation process I sent name.com documents verified by Notary Public for my identity verification.

I sent an email to Aibek, admin of the top technology blog MakeUseOf.com (MakeUseOf.com was hacked in November 2008). I asked Aibek what to do in this situation, Aibek replied promptly giving some quick tips and asked me to make it public with detail and proofs.

Contacting The Cracker

On July 29 I sent an email to Abbas Shafie’s email address displaying in who is and asked him why did he hacked my account & now what does he want? His response was,

dude i bought these domains with a cheap price, i can show you that 300$ has been gone from my paypal account
dude i bought them….
Theft?

what i had to do now ? 
can i report this to paypal ?

And when in next email I asked who sold you these domains? He said Aqeel Syed! What a joke it is! Apart from all this serious situation I kept laughing.

I sold him all my established domains for $300 as I need money and was in hurry. The fact is I pay $300 in hosting fee every month for these sites, these sites has generated $3000 in affiliate sales and I got business of $2000 from these domains. The other thing is he said I was paid by PayPal! Ah! I wish badly that PayPal should have been available in Pakistan. Shafiee even don’t know that PayPal do not support Pakistan, how false his accusation is!

July 29, 2009 at 11 PM
Name.com support informed me that investigation is almost complete and they will get back to me quickly. I was asked to create a new account where they will move my domains.

July 31, 1 AM

I’m still waiting to be contacted from name.com. They are good at what they do, but I’m not satisfied with their support. Even in a serious matter like that they are not replying, TheWondrous.com is down and I’m helpless. I can’t do anything about that site, frustrated waiting for name.com support to do something.

July 31, 3 AM Domains are back!

Finally I recieved a good email from name.com support, they had returned me my domains. Apart from initial disappointment name.com support helped me out. Its a good news, that theft ruined 4 work days and devastated a lot. Thank you all our readers, friends, twitter contacts, Aibek from Makeusof.com & name.com support for helping us in this bad situation.

{ 3 comments }

Getting High PR Backlinks

by Aqeel Syed on July 25, 2009

Links are very important factor in ranking of a website in SERPs (Search Engine Result Pages). All major search engines consider back links as a major factor in deciding quality of a webpage. Google’s PR algorithm is based on backlinks.

SEO and link building is not what it used to be few years back. Google these days pays more importance on quality of backlinks than quantity. A relevant contextual backlink is far more valuable than a handful of unrelated low quality backlinks.

In this article we are discussing 3 ways to get high quality baklinks for free.

1. Free Backlink from Apple.com

Apple.com is PR 9 and the page itself where you are getting link is PR 7.  Work around to get this juicy, high quality link is to create an Iphone App. And to do it, you just need to create a Web App made for the iPhone and then submit it to their directory. You can even create something basic and simple (but I would suggest useful).

This simple search on Google, give lots of ideas on creating an Iphone App.

2. Grab You Free Backlink for Google Profiles

You can use Google Profiles to grab a free link from Google.com. You just need to fill the information that they ask about yourself, include the URL of your website, add some pictures and description, one more backlink. As long as you add enough information, your profile will be displayed in Google’s search results, and it should count as a normal backlink because Google does not use the nofollow attribute on the website links.

You can also use this service to improve your SERM (Search Engine Reputation Management), as this profile is going to rank with your name in search results. You can see my profile here.

3. Backlink from a PR 10 website, Adobe.com!

Adobe.com is one of the few elite those have PR 10 so you can imagine how much authority that domain have. If you use Adobe products and have done some development you can get a PR from subdomain, forums.adobe.com which has a PR 9 by joining its communities and adding your backlink in your profile.

Their are many other easier ways to get backlinks from high PR domains, do you have used any? Please share your experiences.

{ 6 comments }