TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

GoDaddy says a multi-year breach hijacked customer websites and accounts

100 点作者 Octokiddie超过 2 年前

8 条评论

dang超过 2 年前
<i>GoDaddy: Hackers stole source code, installed malware in multi-year breach</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34838251" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34838251</a> - Feb 2023 (74 comments)
veqq超过 2 年前
Although we all know GoDaddy&#x27;s subpar, this is massive:<p>&gt; credentials that gave it access to a “small number” of employee accounts and the hosting accounts of roughly 28,000 customers.<p>&gt; obtain login credentials for WordPress admin accounts, FTP accounts, and email addresses for 1.2 million current and inactive Managed WordPress customers<p>I&#x27;m curious what they concretely did:<p>&gt; goal is to infect websites and servers with malware for phishing campaigns, malware distribution<p>&gt; weight loss websites<p>but hm. I guess I don&#x27;t know a lot about malware, phishing and stuff. How would you gain exactly?
评论 #34890614 未加载
iambateman超过 2 年前
The article reads like a press release more than journalism.<p>Multiple uses of the word “sophisticated” as if the only way someone could gain access to Godaddy for _multiple years_ was if they are quite sophisticated, and not as a result of massive negligence on the part of Godaddy itself.<p>No quotes from the company apologizing.<p>Godaddy is wild…what a mess.
评论 #34890796 未加载
someonenice超过 2 年前
&gt;&gt; a misconfigured domain name system service at GoDaddy allowed hackers to hijack dozens of websites owned by Expedia, Yelp, Mozilla, and others..<p>Any idea what was the impact on Mozilla ? Did it impact the Firefox and plugin servers ?
评论 #34891478 未加载
genmud超过 2 年前
Multi year breaches and general incompetence are kind of Godaddy’s MO. I remember doing notifications of suspicious activity to them and they never bothered even <i>trying</i> to fix it.<p>I would be shocked if they weren’t running afoul of GDPR required notifications by intentionally putting their heads in the sand and pretending no PII was stolen.
评论 #34891338 未加载
insane_dreamer超过 2 年前
I find it hard to believe that GoDaddy is still in business. Even 15-20 years ago it felt like it operated barely above scam-level and to be avoided.
评论 #34892363 未加载
评论 #34892079 未加载
评论 #34891968 未加载
MonkeyMalarky超过 2 年前
Customer websites being hijacked and going unnoticed for <i>years</i> is incredible levels of incompetent.
cyanydeez超过 2 年前
Marginally worse than GoDaddy service