Glaring security flaw puts SA Domains at risk

SA_Citizen

Active Member
Joined
Mar 3, 2013
Messages
34
Reaction score
0
Uniforum SA use a domain update method that makes all South African domains vulnerable to hijacking.

An email ticket system is the only thing standing between you and someone else who wants your domain name. A domain we had worked on for many years was hijacked by our ISP. They monitored the incoming mail to our account after submitting an update request to Uniforum. They then intercepted the mail and replied on our behalf essentially making them the new owner of the domain.

Everything we had worked on, the costs we had incurred during this time and the client base we had built, now belongs to another company.

Uniforum's response to this was unexpected. They said: "You should have registered with a reputable ISP". Passing the buck and not taking responsibility for their flawed system they said we are going to have to spend R20 000 in legal fees to attempt to get it back, but the chances are slim as it took too long to make a complaint. (There's a 5 day window).

We trust our domains to be safe. We should not have to check every 5 days to make sure they are still ours. Once registered we should not have to check again, ever. That's how it works elsewhere.
 
Last edited:
Uniforum SA use an antiquated domain update method that makes all South African domains vulnerable to hijacking.

An email ticket system is the only thing standing between you and someone else who wants your domain name. A domain we had worked on for many years was hijacked by our ISP. They monitored the incoming mail to our account after submitting an update request to Uniforum. They then intercepted the mail and replied on our behalf essentially making them the new owner of the domain.

Everything we had worked on, the costs we had incurred during this time and the client base we had built, now belongs to another company.

Uniforum's response to this was unexpected. Arrogantly, they said: "You should have registered with a reputable ISP". Passing the buck and not taking responsibility for their flawed system they said we are going to have to spend R20 000 in legal fees to attempt to get it back, but the chances are slim as it took too long to make a complaint. (There's a 5 day window).

We trust our domains to be safe. We should not have to check every 5 days to make sure they are still ours. Once registered we should not have to check again, ever. That's how it works elsewhere.

Hi

Contact ICANN they are the regulators for all the domains in the world and lay a complaint by them, they will resolve the matter for you. Uniforum needs to follow the guidelines set out by ICANN and if they don't they can and will loose their licence. I had the same issue with Mweb and they were playing hard ball until I contacted ICANN and CC's them in the mail. The domain issue was sorted the next day where they were doing basically the same thing. This is if that is what really happened but they will investigate, they can see exactly what is happening on any Uniforum domain and if they pick up that it was the case you will get it back, don't bother lying to them because they will pick it up as well.

http://www.icann.org/

Hope this helps
 
Last edited:
What makes the current email based domain management in SA such a dismal failure is it is now very difficult for me to prove I did not reply to the ticket myself. The email headers have all the correct delivery addresses, servers, ISP IP addresses etc. I had threatened to name and shame the ISP on the public forums, but a ton of bricks was dumped on my effort by legal jargon and threats of lawsuits by this ISP for libellous actions on my part. We just don't have the funds to follow through with legal battles.

Naming and shaming is one thing, but this should never have happened. Sure, large brands don't run this risk as it would be plain stupid to try this with them, but a non profit site with an extremely high google ranking and a large number of visitors, run by a small group of people is vulnerable to Uniforum's complacency.

I am definitely going to follow the ICANN route. It's time Uniforum make changes before this happens to someone else.

Here's a tip. When registering your domain name, make 100% sure the email address listed under the registrant is NOT on the same domain and not with the same ISP. Even so, hacking email accounts is one of the first things hacker school grads know how to do.
 
Last edited:
It appears that Uniforum are not on the ICANN accredited list. I got redirected straight back to SA at zadna.org.za and they are the ones who quoted me R20 000 to make an attempt at finding a resolution.
 
What makes the current email based domain management in SA such a dismal failure is it is now very difficult for me to prove I did not reply to the ticket myself. The email headers have all the correct delivery addresses, servers, ISP IP addresses etc. I had threatened to name and shame the ISP on the public forums, but a ton of bricks was dumped on my effort by legal jargon and threats of lawsuits by this ISP for libellous actions on my part. We just don't have the funds to follow through with legal battles.

Naming and shaming is one thing, but this should never have happened. Sure, large brands don't run this risk as it would be plain stupid to try this with them, but a non profit site with an extremely high google ranking and a large number of visitors, run by a small group of people is vulnerable to Uniforum's complacency.

I am definitely going to follow the ICANN route. It's time Uniforum own up to their inadequate system and make changes before this happens to someone else.

Here's a tip. When registering your domain name, make 100% sure the email address listed under the registrant is NOT on the same domain and not with the same ISP. Even so, hacking email accounts is one of the first things hacker school grads know how to do.

So did the ISP registered the domain on your behalf?
 
Unless you only want to trade in SA I don't see the point of using .co.za. Much rather use .com.
 
So did the ISP registered the domain on your behalf?

Yes. I went to their premises and had them set it up. I later had them correct it because they originally registered it in their name. They did this without any resistance and it remained that way for quite a few years. Mysteriously it reverted back to them though and when I asked them to fix I was told to phone their lawyers.

They have since sold off hundreds and hundreds of email addresses on this domain, left the website running, but we are unable to move the NS records or do an upgrade to the site which is running on an antiquated cms. We are unable to do anything to the whois records as the ticket is rejected time and time again. We had to can the entire operation as it is futile working on something or attempting to work on something that does not belong to you on paper.
 
Unless you only want to trade in SA I don't see the point of using .co.za. Much rather use .com.

Yeah. Quite true if you can get the domain on a .com that you want. We couldn't. The name is crucial to our search phrase and luckily we were able to get the new .co on the same name. So now it's a matter of 301'ing the entire site somehow. The old domain is doing exceptionally well on Google. Sucks.
 
Yes. I went to their premises and had them set it up. I later had them correct it because they originally registered it in their name. They did this without any resistance and it remained that way for quite a few years. Mysteriously it reverted back to them though and when I asked them to fix I was told to phone their lawyers.

They have since sold off hundreds and hundreds of email addresses on this domain, left the website running, but we are unable to move the NS records or do an upgrade to the site which is running on an antiquated cms. We are unable to do anything to the whois records as the ticket is rejected time and time again. We had to can the entire operation as it is futile working on something or attempting to work on something that does not belong to you on paper.

Then you lodge a dispute with Uniforum. and you name and shame the ISP.
 
Though, I do wonder why you had setup your email in such a way that your ISP could view it?
 
Though, I do wonder why you had setup your email in such a way that your ISP could view it?

The ISP hosts the mail server. They have access to all mails going through their systems. It's not something that we set up specifically for them. If you have an email address hosted by an ISP that ISP can view all your mails if they so wish.
 
Then you lodge a dispute with Uniforum. and you name and shame the ISP.

We went into lengthy discussions with Uniforum. As posted earlier, the best we got from them was "You should have registered with a reputable ISP". Not quite the right answer from a trusted domain name registrar, at the mercy of the ISP. The reason we have not named and shamed the ISP is listed in an earlier post in this thread.
 
Last edited:
Yes. I went to their premises and had them set it up. I later had them correct it because they originally registered it in their name. They did this without any resistance and it remained that way for quite a few years. Mysteriously it reverted back to them though and when I asked them to fix I was told to phone their lawyers.

Could you give us a timeline? When did you first notice that the domain was registered under the wrong name? When did they eventually correct it?

Edit: I just have to mention something else ... I do not see this as a glaring security flaw with Uniform's system. The flaw or security failure was with the email handling itself via a 3rd party ISP.
 
Last edited:
The ISP hosts the mail server. They have access to all mails going through their systems. It's not something that we set up specifically for them. If you have an email address hosted by an ISP that ISP can view all your mails if they so wish.

Must've been a helluva sketchy ISP. The ISPA doesn't allow that.
 
Could you give us a timeline? When did you first notice that the domain was registered under the wrong name? When did they eventually correct it?

They corrected the original registration where they had listed themselves as the registrant. This was during the late 90s. At that time I asked them to fix it which they did, but a few years after, when we became very active in developing a site on this domain they reinstated themselves as the registrant and have become really aggressive towards us when we try reclaim the domain. They blatantly tell us there is no way they will restore rightful ownership and we have to speak to their lawyers if we ever want to bring up the topic again. This has been going on for a few years now, but we remain persistent.
 
Must've been a helluva sketchy ISP. The ISPA doesn't allow that.

Yep. at the time we had no idea. It was still early days when we originally registered with them. There were no Afrihosts or Hetzners, just these smaller start-ups. We were still on dial-up. So you can imagine the amount of time we have put into this domain to date. And as you know, domain age plays a huge role in Google search.

But yes, I do believe they would not pass any ISPA tests if they were to be audited.
 
Last edited:
The ISP hosts the mail server. They have access to all mails going through their systems. It's not something that we set up specifically for them. If you have an email address hosted by an ISP that ISP can view all your mails if they so wish.

Complete bloody hogwash..

NONE of my ISPs can access my email accounts in any way shape or form.
 
Yep. at the time we had no idea. It was still early days when we originally registered with them. There were no Afrihosts or Hetzners, just these smaller start-ups. We were still on dial-up. So you can imagine the amount of time we have put into this domain to date. And as you know, domain age plays a huge role in Google search.

But yes, I do believe they would not pass any ISPA tests if they were to be audited.

Ummm back in the early days, you could have dealt with iAfrica or UUNet etc etc.. there were alot of very reputable large guys out there, not just smaller start ups.

TBH, all I'm hearing now is excuses about your lack of research into your ISP, and I have to admit that I think there is a lot more to this story than you are letting on.
 
Top
Sign up to the MyBroadband newsletter
X