6 ms·
GoDaddy: Hackers stole source code, installed malware in multi-year breach
- youniverse 4y agoAnyone want to recommend their favorite alternative web hosts? I've tried A2 and NameHero and both were very solid along with fast/great support. Anything else I should look into?
- disadvantage 4y agohttps://www.gandi.net/en https://www.gandi.net/en https://www.ovhcloud.com/en/ https://www.ovhcloud.com/en/ https://asmallorange.com/ https://asmallorange.com/ There are many others I can vouch for. There's a good list of them here[0]. Make sure to choose ones that have proper 2FA as it's a good heuristic for how well they consider security. [0] https://2fa.directory/int/#hosting https://2fa.directory/int/#hosting
- Aachen 4y agoOVH is always an exercise in broken UI including terms of service that seem to be copied from a pdf and have random artifacts. It's probably the worst buying experience I've had since the naughties and nothing changed in the years I'm with them now. ...but they're cheaper than other registrars known for being cheap, and I've monitored their nameservers (and a few others') for nearly a year before switching away from my previous registrar and they were consistently fast whereas others had spikes, outages, or constantly round robined across oceans or some such. Quality servers at very low prices makes me put up with some broken UI for a few minutes per renewal.
- blfr 4y agoOVH is cheap and supports U2F. I have a bunch of stuff with them.
- kennydude 4y agoMy stuff is with Krystal who are fantastic. Had a ticket resolved by them on Christmas day within 2 minutes (i have a discount/referral code if you want it - contact form on website)
- deleted 4y ago[deleted]
- chriscjcj 4y agoFor DNS, I have been using Gandi (1) for the last yen years or so and have been very happy with them. I originally went with them because they were one of the few registrars that did the .cat TLD. I liked the experience and eventually transferred all of my domains to them. They are a french company. Their slogan is "No Bullshit," (2) and I think they've done a decent job of living up to that. My only frustration has been a situation where I was transferring an existing domain over to them. I wanted to create the zone file ahead of time so that when the transfer happened, there would be an identical zone file ready to go. But they wouldn't allow me to create a zone file for a domain that hadn't transferred over to them yet. Since I'm not doing anything critical with my domains, it was just an annoyance, but that would be a show-stopper for some. As it pertains to billing problems, they allow you to pre-pay a chunk of money to your account. (They take PayPal.) It deducts from that amount when domains renew. That provides a buffer if you need to cancel your credit card. Also, on the occasions that I have created trouble tickets, they have been responded to in a reasonable amount of time with helpful information. (1) https://www.gandi.net https://www.gandi.net (2) https://www.gandi.net/en/no-bullshit https://www.gandi.net/en/no-bullshit For web hosting, I used Bluehost for many years and because extremely dissatisfied with them. I switched to Siteground.com about five years ago and have very little to complain about.
- mikem170 4y agoI second your Gandi recommendation! Everything is straightforward. Never had any problems with their service or support. When you buy a domain from them they also include a pair of web/smtp/pop/imap mailboxes you can use, with the ability to create aliases, including wildcard aliases. So I don't need to pay separately for fastmail or some other email service.
- robinwassen 4y agoI can also strongly recommend Gandi. Used them to manage 40+ domains for my old company. Professional and good coverage of the TLDs. Nice is also that you can buy credits - that way I could renew a bunch of domains that expired at different times and filing only invoice to bookkeeping.
- jonathantf2 4y agoGandi are great, also recommend nearlyfreespeech.net
- philistine 4y agoI must be making a huge mistake somewhere, but my registrar is AWS. It's no nonsense. I'm sure recommending AWS for hosting is not what you're looking for, but I've been running a static website on S3 fronted by their CDN and it's been nothing but painless.
- winternett 4y ago>it's been nothing but painless. You forgot "expensive"... It's also a lot more expensive.
- philistine 4y agoI’m not using any of the really expensive parts of AWS. S3, Cloudfront, Route 53. I’ve seen cheaper elsewhere for all of these for sure, but nothing catastrophic compared to the crazy cuckoo cloud stuff.
- legrande 4y agoGoDaddy is a very complex thing. And bugs lurk in complexity. No wonder.
- dylan604 4y agoAre you saying that other hosting companies in the same level of complexity are just better, or possibly alluding that other companies might not be upfront about things occurring within their orgs? Either way, it really sounds a lot like you're minimizing the negligence and just poorly run company.
- deleted 4y ago[deleted]
- vxNsr 4y agoWow, multi-year is truly embarrassing. Hosts being compromised is the the worst case scenario because the attacker can decide who to serve the malware to in a spearphishing fashion.
- jeroenhd 4y agoIt happens to more companies than you'd imagine, even big ones. Security monitoring and logging is hard to get right, especially if you try to add it to a previously insecure system. A smart attacker can hack your company unnoticed and passively watch your company for the right moment to strike. I doubt that the hackers logged into the office VPN every day.
- dylan604 4y agoLong long ago, I needed a new website hosted and with no other decision towards the host than I had never tried GoDaddy, I gave it a shot. Within hours, I regretted the decision immensely. In comparison to my previous hosting experiences, it just pissed me off at almost every turn. It was the first time I experienced a company trying to make the interface for non-techy types and made getting to the guts of the tech hidden behind many layers that just frustrated me to no end. I canceled my account and have never looked back. It is just another one of the examples of a company that advertises that intensely is probably a company I don't really want to be involved.
- mmcgaha 4y agoThey are the only company that ever hijacked my robots.txt.
- convolvatron 4y agowtf? what does that look like?
- bombcar 4y agoIt's sad because I used to remember a long LONG time ago they exposed a bunch of things that other registrars required you to email or call support to do. That stuff is still there, but otherwise the whole site just feels slimy.
- mixmastamyk 4y agoI tried it once as well, maybe ten years ago. The annoying thing not yet mentioned is that it tries to upsell you at every step. You quickly realize that steps have been added for additional upsell opportunities. Then the "elephant shooter" drama happened and I moved to namecheap and didn't look back. Was a breath of fresh air in comparison. I didn't see a way to delete my gd account, so think it is still there. Hope my data didn't get out again. :doh:
- qwertox 4y agoThe only thing that annoys me from Namecheap is that their API isn't that good. You can't just update a single record, you have to update the entire zone. Updating the entire zone just to automatically set a verification token (like for Let's Encrypt) is too risky.
- muttantt 4y agoI feel bad for the hackers that now need to read through GoDaddy's code...
- skilled 4y agoWhat a disgrace of a platform. I'd understand dropping a c99 on a cPanel back in early 2000s but these days? What are the engineers doing at the company, collecting a paycheck and pretending to do work? Speaks volumes for the culture being cultivated at GoDaddy.
- Tostino 4y agoI feel like a lot of these older platforms are being shown to be as rickety as they actually are, as malware and hacking toolkits improve and proliferate. Bad practices are going to show through, bigtime with this next cold war the US is entering.
- dylan604 4y agoi would not be surprised if their back end is still a bunch of old skool perl scripts in the cgi folder that were l33t coded back in the day, but nobody now can even start to parse the perl itself. switching from impossible to read perl scripts to flavor-of-the-day language would be a use case i can actually get behind and support for replacing.
- quags 4y agoWell cpanel is written in perl, and certainly hard to read but overall I would say cpanel is probably one of the more secure control panels. This hacking, sounds like the systems were root compromised and unlikely to be related to cpanel. I would guess it is more likely credential compromise, perhaps phishing related on staff themselves.
- localghost3000 4y agoI agree that this is bad but I'd encourage you to rethink your comment. The "clown engineers" you are calling out maintain a level of uptime and scale thats hard to for most people to imagine. You don't do that by being an idiot. Instead of calling them names and assuming bad intent, maybe take a second to think about how much it must suck for them right now. I'm sure it's all hands on deck nights/weekends to fix. No one sets out to do a bad job in my experience.
- bilekas 4y ago> A GoDaddy spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today This is just a sign of GoDaddy's complacency. I use Godaddy for domain registrations only. Yet I had my account taken over with a sim card attack/swap and they spent so long to fix the issue that domains where transfered without locking. Web Hosting, particularly 'shared' hosting is extremely prone to regular banal attacks and requires extreme constant attention, customers less tech savvy would choose it for the very reason they know the Godaddy name, they're expecting them to look after the tech work. A Multi-Year breach is an incredible display of incompetence and neglect. I have no idea what the security/monitor team are doing there but someone definitely dropped the ball, especially given the fact they admit that the 2020 break was related. It should have been and open and shut case from there.
- reaperducer 4y agoA GoDaddy spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today As someone who has waited on hold with GoDaddy support for over six hours on multiple occasions, this does not surprise me.
- sn_master 4y agoI'll never use GoDaddy. They've been fronting their customers for literally decades. Few times I searched for a domain, the next day I search for it find it already reserved by them and on sale for hundreds of dollars instead of the regular $10 it was the day before. They've been abusing their power for as long as they've been in business.
- codetrotter 4y ago> Few times I searched for a domain, the next day I search for it find it already reserved by them and on sale for hundreds of dollars instead of the regular $10 it was the day before. I don't understand how that could possibly be profitable. Imagine how many searches there must be for new domains every day. There is no way they could afford to buy all of the domains that people searched for. And if they had any means of measuring how "good" a domain name is, in order to filter the searches that people make, and front run only the ones looking for good domain names – I don't think that would make sense either. If you were able to reliably measure how good a domain name was you could just buy the domain name right away without waiting for any customers to search for the domain. Anyway, for anyone that is looking for a registrar to use I recommend that you stay away from GoDaddy. Register your domains with Gandi.net, they are nice and good. https://www.gandi.net/en-GB https://www.gandi.net/en-GB
- sn_master 4y ago> I don't understand how that could possibly be profitable. Because registrars have the power to "reserve" domains they like for some time either for free or for only a pennies. https://en.wikipedia.org/wiki/Domain_tasting https://en.wikipedia.org/wiki/Domain_tasting
- deleted 4y ago[deleted]
- NationalPark 4y agoGodaddy is a crappy company for many reasons, but this seems like something that's trivially testable. If they were really front running domains, anyone could spend an hour typing domains in and see a bunch of them mysteriously registered by godaddy the next day. Has nobody done that? Why can't I find any blogs where this was attempted?
- rdiddly 4y agoSo was this a breach of cPanel that therefore could affect other providers that use cPanel?
- miked85 4y agoI honestly can't believe this company is still in business - it's been terrible for decades.
- webdood90 4y agohave you been using it for decades? or do you just read the headlines to form an opinion? there are a ton of hard working people at GD that care a lot about the products we make. I don't think that's a fair assessment.
- krimpenrik 4y agoI am avoiding it for decades, and it is terrible. Better alternatives Namecheap, ovh, digitalocean, gandi, TransIP
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- jasonlotito 4y agoI hate blaming the victim, but so much bad press had come out against GoDaddy it's like complaining that the bear hurt you when you went into it's den and disturbed it. Friends don't let friends use GoDaddy.
- greatgib 4y ago"We have evidence, and law enforcement has confirmed, that this incident was carried out by a sophisticated and organized group" I like how they try to hide their incompetence with bullshit
- sophacles 4y agoLaw enforcement (to GoDaddy): "well it went on for years from what we can tell. Whoever did this is more sophisticated than a bunch of impulsive teenagers 'joyriding'". GoDaddy PR (to world): The attackers were sophisticated, the cops said so!
- avsteele 4y agoThis might solve a big mystery for me. When I first set up my company's website it was hosted at GoDaddy. Totally static site. It got 'hacked' one day, with new php files and redirecting users to some nonsense. This was August 2016. The ftp server had a very long, random password. I changed it again after this. It happened *again* March 2017, though different files were added. After this I moved my site to Digital Ocean. I never found out how this happened. Does anyone know how long this has been going on? The article didn't give a definitive start date.
- iLoveOncall 4y agoYou can have the longest password in the universe and change it after every login, if you have a keylogger on your computer it doesn't matter.
- sn_master 4y agoor someone sniffing your network. FTP isn't encrypted.
- quags 4y agoThere seem to be three incidents and all after 2020. But FTP - unless godaddy enforced TLS connections on that - which back in 2016 probably not because it would have been a support burden this could has easily have been password sniffed.
- justinclift 4y agoOne of my relatives had a similar thing happen a few years ago, though not at GoDaddy. In this particular case, they had "shared hosting" and it turned out the permissions on their particular directory were somehow left writeable by "other". In the *nix filesystem sense. eg any other customer/user/etc on the server was able to overwrite the files. Which someone had done at some point. Was easy to fix at the time (eg fix the permissions), but I have no idea if it occurred again over time.
- goodfight 4y agoI feel like this may be the same case at PayPal too. Identity theft and random emails were not even intended for me was my experience.
- anonzzzies 4y agoGodaddy. One of the most horrible companies. Always was. Bob Parsons is a sad individual with many lovely quotes attesting to that fact. Hope this ends them.
- djcannabiz 4y agoCare to share some of your favorites?
- rograndom 4y agoI am not surprised at all. Maybe 7 years ago I got called in to clean up a website "hack" where the site had a bunch of malicious JS on it. Site was hosted on GoDaddy. Pulled the site down locally and started the regular process of find/remove, but nothing was showing up. Hosting the site locally, the JS wasn't being put on the page. Checked all the server files for stuff like php.ini, user.ini, etc etc. Nothing was showing up. Created a plain info.php file on the account. That had the JS injected into it. Started searching for other sites with the same JS, found a bunch, dozens. Started a search for "neighbor" sites to the one I was investigating, ones that most likely were on the same server. They ALL had the JS injected. Server was owned. I alerted the client and sent a note into GoDaddy, like you need to check this out. Got a response that it was impossible for the server to be compromised and I should buy their Sitelock service for security. Instead we requested a migration to another server and that cleared up the issue.