Enom Pwnage!

Tuesday, August 4th, 2009

Earlier today (Aug 4, 09), I went over to enom.com to try to move over a domain for a client.. But, instead of seeing a pretty UI like I normally do, I see a huge server config file in their of their site displaying countless server usernames, passwords, and IPs.

Being a server admin myself, I realized how horrible a situation this was for a large company. So I immediately try to find their support number… But all of their pages on enom.com were cat with this garbage and the rest of the page was essentially empty. So what to do? google cache!

I call them up, and luckily for them, I get answered immediately. However, they quickly blow me off without the question. “We couldn’t be hacked, who are you?”. I’m speachless. They try to get me off the phone the best way they know how, “Hey, why don’t you create a support ticket about this”. I think to myself, “under the category, your server just got hacked bitch?”. Never the less, I didn’t do that.

Small note, eNom.com has countless webservers with round robbin DNS setup, so the hacker only hacked a single one for it to show all their goodies…