๐ Explore this trending post from Hacker News ๐
๐ **Category**:
๐ **What Youโll Learn**:
The incoming club leader was persistent though, and called NameCheap support. He convinced them the domain registered in my name and address really belonged to his club, and with no verification or validation whatsoever, NameCheap changed my password, and changed the email address associated with my account. All because someone simply asked nicely on a phone call.
Meanwhile in the background, someone advised the new club leader who I was and we were able to connect and get things transferred over. Ultimately I was happy to give them access or even ownership if they wanted (student club turnover being what it is, itโs likely a domain doesnโt get renewed and gets gobbled up by a squatter, which is why I was keeping it current for them).
But NameCheap had no way of knowing any of this. As far as NameCheap was aware, this was a personal account of mine. They demonstrated they were perfectly able to pick up a phone and call me (to verify my initial support ticket) but when someone calls them and says โbut I really want access to that accountโ they donโt bother?
Iโd hesitate to even call this social engineering. Itโs clearly a massive vulnerability. Iโve already moved a dozen of my most critical domains out of NameCheap after seeing just how easy it is for a third party to completely take over a NameCheap account: just ask nicely.
โก **Whatโs your take?**
Share your thoughts in the comments below!
#๏ธโฃ **#Namecheap #Gave #Account #Unverified #Party #Asked**
๐ **Posted on**: 1784845206
๐ **Want more?** Click here for more info! ๐
