My site was hacked, used for phishing, registry disable my domain

Discussion in 'Security' started by bizbugs, Dec 8, 2008.

  1. #1
    My site was hacked, used for phishing, registry disable my domain.

    I received an email from the registry:

    We have recently receive the complaint below that the domain name .COM has been used as an ebay/paypal phishing site. This domain name has been disabled till we have a chance to research this issue further. Please send us an email providing further details as to this issue, and what steps will be taken to prevent this issue in the future. Your assistance is greatly appreciated.

    I cant contact our hosting provider since their site and IP was not accessible.
    Please let me know what to do?
     
    bizbugs, Dec 8, 2008 IP
  2. Jakee246

    Jakee246 Banned

    Messages:
    88
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #2
    First off what is the ip address? Second who is the register? Third domain name?
     
    Jakee246, Dec 8, 2008 IP
  3. bizbugs

    bizbugs Member

    Messages:
    45
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    41
    #3
    IP: 118.127.10.57
    the registry already enable the domain.
    the hosting provider is: http://auzziehosting.com.au/
    as of now I cant access their site and their tech, as well as the ticket.
    I moved our domain to other server.

    What to do w/ our account w/ http://auzziehosting.com.au/
     
    bizbugs, Dec 8, 2008 IP
  4. Oranges

    Oranges Active Member

    Messages:
    2,610
    Likes Received:
    92
    Best Answers:
    0
    Trophy Points:
    90
    #4
    I think, that hosting you were using might have some security loop holes,
    thats the only reason its hacked.They look like scam for sure. IMO.
     
    Oranges, Dec 8, 2008 IP
  5. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Yeah, they are a scam - They have just changed there name to Burst Networks ( which is already taken in a number of countries ) and they have a fake ABN number.

    Also, there old box was either internally " hacked " or used for phishing stuff, or it was externally hacked and used for phishing content.
     
    SSANZ, Dec 14, 2008 IP