TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

GoDaddy says a multi-year breach hijacked customer websites and accounts

100 pointsby Octokiddieabout 2 years ago

8 comments

dangabout 2 years ago
<i>GoDaddy: Hackers stole source code, installed malware in multi-year breach</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34838251" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34838251</a> - Feb 2023 (74 comments)
veqqabout 2 years ago
Although we all know GoDaddy&#x27;s subpar, this is massive:<p>&gt; credentials that gave it access to a “small number” of employee accounts and the hosting accounts of roughly 28,000 customers.<p>&gt; obtain login credentials for WordPress admin accounts, FTP accounts, and email addresses for 1.2 million current and inactive Managed WordPress customers<p>I&#x27;m curious what they concretely did:<p>&gt; goal is to infect websites and servers with malware for phishing campaigns, malware distribution<p>&gt; weight loss websites<p>but hm. I guess I don&#x27;t know a lot about malware, phishing and stuff. How would you gain exactly?
评论 #34890614 未加载
iambatemanabout 2 years ago
The article reads like a press release more than journalism.<p>Multiple uses of the word “sophisticated” as if the only way someone could gain access to Godaddy for _multiple years_ was if they are quite sophisticated, and not as a result of massive negligence on the part of Godaddy itself.<p>No quotes from the company apologizing.<p>Godaddy is wild…what a mess.
评论 #34890796 未加载
someoneniceabout 2 years ago
&gt;&gt; a misconfigured domain name system service at GoDaddy allowed hackers to hijack dozens of websites owned by Expedia, Yelp, Mozilla, and others..<p>Any idea what was the impact on Mozilla ? Did it impact the Firefox and plugin servers ?
评论 #34891478 未加载
genmudabout 2 years ago
Multi year breaches and general incompetence are kind of Godaddy’s MO. I remember doing notifications of suspicious activity to them and they never bothered even <i>trying</i> to fix it.<p>I would be shocked if they weren’t running afoul of GDPR required notifications by intentionally putting their heads in the sand and pretending no PII was stolen.
评论 #34891338 未加载
insane_dreamerabout 2 years ago
I find it hard to believe that GoDaddy is still in business. Even 15-20 years ago it felt like it operated barely above scam-level and to be avoided.
评论 #34892363 未加载
评论 #34892079 未加载
评论 #34891968 未加载
MonkeyMalarkyabout 2 years ago
Customer websites being hijacked and going unnoticed for <i>years</i> is incredible levels of incompetent.
cyanydeezabout 2 years ago
Marginally worse than GoDaddy service