TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Perl.com Taken over by Domain Squatters

210 pointsby leejoover 4 years ago

20 comments

bhartzerover 4 years ago
Let’s call it what it is. It’s not a domain taken over by squatters. The domain was stolen.<p>I’ve seen other domains get stolen recently, it seems to be about the same time.<p>Patterns dot com Piracy dot com Perl dot com<p>All stolen at around the same time.<p>With patterns, the thief hacked the network solutions account, put the domain under privacy, transferred it to a Chinese registrar, and then put the old whois data back. They then tried to sell it on sedo and afternic for 10 percent of what it’s worth.<p>I have been able to get sedo and afternic to remove the listings. But patterns has not been returned to its owner after about two months. Still working with the owner and registrars on that.<p>My advice is to lock down your domains, register them for at least 5 years, and if there are changes deal with them quickly. Once a domain is transferred it’s much harder to get back. It can be done, but it’s a lot of work to unravel it all.
评论 #25942921 未加载
评论 #25945088 未加载
评论 #25942866 未加载
评论 #25977754 未加载
评论 #25958125 未加载
erikkriover 4 years ago
Looking at whois history sites, it looks like the domain was owned by Tom Christiansen aka tchrist, which wrote Programming Perl, Learning Perl and the Perl Cookbook.<p>The record wasn&#x27;t supposed to expire until 2029, so not sure how the squatters got this domain.
评论 #25940979 未加载
评论 #25943094 未加载
briandfoyover 4 years ago
Thanks to everyone who has given advice and helped us develop a timeline of the incident. I&#x27;m not part of the network and asset management: I&#x27;m a mere editor of the website.<p>The current registrar has contacted me. They&#x27;ve locked the domain and we need to submit some paperwork. It shouldn&#x27;t be that big of a deal even though it&#x27;s annoying. All of this was handled quickly (12 hours) because of the attention to the internet in general.
评论 #25944721 未加载
superasnover 4 years ago
Very strange indeed<p>&gt; @xsc: Looks like this breach also affected <a href="http:&#x2F;&#x2F;piracy.com" rel="nofollow">http:&#x2F;&#x2F;piracy.com</a> <a href="http:&#x2F;&#x2F;chip.com" rel="nofollow">http:&#x2F;&#x2F;chip.com</a> <a href="http:&#x2F;&#x2F;neurologist.com" rel="nofollow">http:&#x2F;&#x2F;neurologist.com</a> along with <a href="http:&#x2F;&#x2F;perl.com" rel="nofollow">http:&#x2F;&#x2F;perl.com</a> (<a href="https:&#x2F;&#x2F;www.afternic.com&#x2F;listings&#x2F;drawmaster" rel="nofollow">https:&#x2F;&#x2F;www.afternic.com&#x2F;listings&#x2F;drawmaster</a>)
评论 #25943001 未加载
classichasclassover 4 years ago
Floodgap was part of this. I just talked to a very helpful person in NetSol&#x27;s security department and she looked through the ticket. It was initiated by a web chat, and they produced official looking but completely fraudulent documents (photo ID, utility bill, business license, etc.) to prove identity, so this was socially engineered and apparently for multiple domains. They&#x27;re supposed to contact me tomorrow for more on the post mortem.
eruciover 4 years ago
To add insult to injury, There are ads on perl.com about &quot;Start programming with Python&quot;
lifeisstillgoodover 4 years ago
So a potential service here:<p><a href="https:&#x2F;&#x2F;www.icann.org&#x2F;news&#x2F;blog&#x2F;documentation-is-key-to-recovering-hijacked-domain-names" rel="nofollow">https:&#x2F;&#x2F;www.icann.org&#x2F;news&#x2F;blog&#x2F;documentation-is-key-to-reco...</a><p>If documentation is key, then perhaps have a service that will, take your documentation, hash it and then you can store the hash on your domain root (much like google analytics). Then if you lose the domain, you have wayback machine style proof that the domain originally had these docs associated with it.<p>(I can see some downsides to this but what do people think?)
grumpleover 4 years ago
Looks like it was an account hack and transfer, not a registration lapse [1].<p>1. <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;perl&#x2F;comments&#x2F;l6d8ws&#x2F;perlcom_unfriendly_domain_take_over&#x2F;gl2tghw&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;perl&#x2F;comments&#x2F;l6d8ws&#x2F;perlcom_unfrie...</a>
asicspover 4 years ago
More details&#x2F;discussion: <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;perl&#x2F;comments&#x2F;l6d8ws&#x2F;perlcom_unfriendly_domain_take_over&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;perl&#x2F;comments&#x2F;l6d8ws&#x2F;perlcom_unfrie...</a>
mzsover 4 years ago
&gt; We&#x27;re still trying to unravel this and I can&#x27;t get into details. However, it looks like there was an account hack. I don&#x27;t know how long that would take to rewind. We&#x27;re looking for people who have actual experience dealing with that situation so we can dispute the transfer. If you&#x27;ve actually gone through thatprocess, please get in touch.<p>&gt; The perl.org and perl.com domains are unrelated and have different rightful registrants, so this doesn&#x27;t affect perl.org.<p>briandfoy 1 hour ago<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;perl&#x2F;comments&#x2F;l6d8ws&#x2F;perlcom_unfriendly_domain_take_over&#x2F;gl2tghw" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;perl&#x2F;comments&#x2F;l6d8ws&#x2F;perlcom_unfrie...</a>
andredzover 4 years ago
I was wondering why none of the links were working. I was trying to read on the beginnings of Perl6 (now Raku) design (such as in <a href="https:&#x2F;&#x2F;www.perl.com&#x2F;pub&#x2F;2000&#x2F;11&#x2F;perl6rfc.html&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.perl.com&#x2F;pub&#x2F;2000&#x2F;11&#x2F;perl6rfc.html&#x2F;</a>) and also check some States of the Onion. At least everything is currently accessible either through the Wayback Machine or here: <a href="https:&#x2F;&#x2F;perldotcom.perl.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;perldotcom.perl.org&#x2F;</a>
chriszhangover 4 years ago
What is the full story behind this? How did it happen? Was it a domain hijack? Did someone forget to pay the bill? Do I need to worry about this for my domains?
hannobover 4 years ago
Honest question: Was this an important host name?<p>From what I can see Perl the programming language has its home at perl.org, which is running fine. The .com does not show up prominently when googling for perl. Based on Google&#x27;s cache it seems it was some kind of programming-related news page. Was it relevant&#x2F;popular in the Perl community?
评论 #25944962 未加载
beermonsterover 4 years ago
<a href="https:&#x2F;&#x2F;nakedsecurity.sophos.com&#x2F;2021&#x2F;02&#x2F;07&#x2F;perl-com-gets-its-domain-back-normal-service-restored&#x2F;" rel="nofollow">https:&#x2F;&#x2F;nakedsecurity.sophos.com&#x2F;2021&#x2F;02&#x2F;07&#x2F;perl-com-gets-it...</a>
st_goliathover 4 years ago
Reminds me of that one time in 2016 when X.org almost expired[1].<p>[1] <a href="https:&#x2F;&#x2F;www.phoronix.com&#x2F;scan.php?page=news_item&amp;px=X.Org-Domain-Woes" rel="nofollow">https:&#x2F;&#x2F;www.phoronix.com&#x2F;scan.php?page=news_item&amp;px=X.Org-Do...</a>
评论 #25940856 未加载
FerretFredover 4 years ago
Looks like it&#x27;s in Chisinau, Moldova right now... where next I wonder?
nameloswover 4 years ago
It sounds like it&#x27;s hacked since it expires at 2029? Is there any way to sue anybody to win it back?
rurbanover 4 years ago
perl11.org was forgotten to be paid last year (not me). So it is gone also.
评论 #25941211 未加载
评论 #25941237 未加载
alfiedotwtfover 4 years ago
Speculation: they’re selling on Afternic, which sounds more like a legitimate forgetting to renew and someone bought it during the grace period rather than a hack.<p>... wasn’t Perl.com an O’Reilly Publishers asset?
hordeallergyover 4 years ago
Not just twitter, whatsapp, facebook, etc - the DNS system needs replacing too.
评论 #25940545 未加载
评论 #25940478 未加载