Latest news of the domain name industry

Recent Posts

China connection to Go Daddy WordPress attacks

Go Daddy’s hosting customers are under attack again, and this time it looks like it’s more serious.
Reports are surfacing that WordPress sites hosted at Go Daddy, and possibly also Joomla and plain PHP pages there, are being hacked to add drive-by malware downloads to them.
Go Daddy has acknowledged the attacks, blaming outdated WordPress installations and weak FTP passwords, and has put up a page with instructions for cleaning the infection.
Last week, I was told that the first round of attacks was very limited. Today, the attackers seem to have stepped it up a notch.
As a result, Go Daddy could find itself in a similar situation to Network Solutions, which had a couple of thousand customer sites hacked a few weeks back.
The attacks appear to be linked to a well-known crime gang with a Chinese connection.
According to Sucuri, when a Go Daddy-hosted WordPress page is hacked, JavaScript is injected that attempts to redirect surfers to a drive-by attack from the domain kdjkfjskdfjlskdjf.com (don’t go there).
This domain was registered with BizCN.com, an ICANN-accredited Chinese registrar, but its name servers appear to have been created purely for the attack.
The registrant’s email address is hilarykneber@yahoo.com. This connects the attack to the “Kneber” botnet, a successful criminal enterprise that has been operating since at least December 2009.
A Netwitness study revealed the network comprised at least 74,000 hacked computers, and that the bulk of Kneber’s command and control infrastructure is based in China.
Since Kneber is known to be operated by a financially motivated gang, and it’s by no means certain that they’re Chinese, it’s probably inaccurate to suggest there’s something political going on.
However, I will note that Go Daddy was quite vocal about its withdrawal from the .cn Chinese domain name registration market.
Network Solutions, while it was quieter, also stopped selling .cn domains around the same time as the Chinese government started enforcing strict registrant ID rules last December.

Twenty registrars canned in 2009

Kevin Murphy, April 30, 2010, Domain Registrars

ICANN shut down 20 domain name registrars in 2009, and is on course to do the same this year, according to numbers released today.
That’s up from seven de-accreditations in 2008, and twice as many as the previous record year, 2003.
ICANN can withdraw accreditation from a registrar, stopping its ability to register domains, if the registrar fails to escrow Whois information or pay its ICANN dues.
It looks like 2010 could well see a similar level of de-accreditations.
Five registrars were shuttered in the first quarter, and ICANN has sent warnings to five more this month.

Remember CFIT? Buy its domain for $250

Kevin Murphy, April 29, 2010, Domain Sales

Remember CFIT? The Coalition For ICANN Transparency is an ironically opaque organization created and backed by Momentous.ca, owner of Pool.com.
It emerged in 2005 to sue ICANN and VeriSign on antitrust grounds, around the same time as they were negotiating .com price increases.
I’d almost forgotten CFIT existed, until CEO Mark McLaughlin mentioned it on VeriSign’s Q1 earnings conference call last night.
The antitrust lawsuit is still pending, after CFIT won an appeal last June. Tenacious organization indeed.
Its domain name did not have the same longevity, however.
CFIT.info now belongs to a domainer, who appears to have picked it up last December. I offered him twenty bucks for it today and he countered with a $250 offer, which is a bit rich for me.
Whatever PageRank it accrued from all its press coverage appears to have dried up, and its parking page is not especially inspiring.
Any takers?

Hostway wants non-existent domain patent

Kevin Murphy, April 29, 2010, Domain Tech

Hostway, the large web hosting company, has applied for a US patent on a system of intercepting and redirecting requests for non-existent domains names.
The application describes “A system and method for controlling internet traffic controls internet traffic directed to a non-existing domain in a centralized manner.”
It appears to cover a service that could be offered to local ISPs, enabling them to show their users monetized search pages rather than domain-not-found error messages.
Under the system, ISPs would intercept NXDOMAIN responses to their users’ DNS lookups.
Instead of passing the error on to the browser, the ISP would consult a centralized controller for the IP address of a context-appropriate landing page to redirect the user to.
It’s not at all clear to me whether Hostway is using the technology or has plans to do so. The application was filed in October 2008.
ISPs using NXDOMAIN substitution to monetize error traffic is widespread but controversial.
ICANN president Rod Beckstrom strongly complained about the practice, which also has security implications, during a rant at the Nairobi meeting last month.
VeriSign’s Site Finder, and later Cameroon’s .cm, both controversially did similar things when they “wildcarded” non-existent domains at the TLD registry level.
Other interesting US patent applications published today include:
20100106650 – covering Go Daddy’s auction services.
20100106793 and 20100106794 – covering email forwarding under Go Daddy’s private registration services.
20100106731 – assigned to VeriSign, covering a method of offering alternative domain names for registration when a buyer’s first choice is unavailable.

AusRegistry scores Japanese .brand deal

Kevin Murphy, April 28, 2010, Domain Registries

AusRegistry, the .au registry, has inked a deal with Brights Consulting, a company offering .brand domain services to the Japanese corporate market.
The company said the deal will mean AusRegistry will provide the technical back-end for any successful new gTLD applications that Brights manages to secure.
Other companies competing for new gTLD business include old hands VeriSign, Neustar and Afilias, as well as hungry newcomers such as Minds + Machines.
AusRegistry currently manages Australia’s .au, .qa for Qatar and .ae for the United Arab Emirates.
Brights is a corporate, rather than retail, ICANN registrar. I may be wrong, but it looks like the company counts Sony among its clients.
Could there be a .sony on the horizon?

.co enters pricey global sunrise

Kevin Murphy, April 26, 2010, Domain Registries

Trademark holders can from today apply for their brands as .co domain names, even if they do not do business in Colombia.
The second stage of .CO Internet’s sunrise period allows owners of non-Colombian trademarks to apply for their domains through one of 10 chosen launch registrars.
Prices vary from $225 with OpenSRS to $335 through Dotster, with most deals comprising non-refundable application fees plus first-year registration. Go Daddy is charging $299.99 and Network Solutions is charging $279.99.
With the possible exception of .xxx, I’ve got a suspicion that this could be one of the last “generic” TLD launches with such expensive sunrise periods.
It’s quite possible there could be pricing pressure if ICANN quickly approves a few hundred new gTLDs next year. If each charges ~$300 for a pre-launch, it could cause some some registrants to rethink their defensive registration strategies.
The .co sunrise ends June 10. General availability begins July 20.

Kurds seek new cultural gTLD

Kevin Murphy, April 26, 2010, Domain Registries

A Kurdish company will apply to ICANN for a .kurd or .kur top-level domain to represent cultural Kurds.
The application will join the likes of .cat, and expected gTLD applications including .scot, .cym, .bzh, and .gal, which promise representation to “cultural”, but non-geographic, user bases.
The potential community for .kurd is around 35 million people, according to Wikipedia, over three times the size of the international Catalan community represented by .cat.
While many Kurds live in middle-eastern nations such as Iran and Iraq, there are almost 14 million living in Turkey, likely soon to be part of the European Union, according to the CIA World Factbook.
I’ve been told that a non-profit cultural gTLD needs only about 10,000 registrations to stay afloat; this seems easily achievable.
The dotKurd application has a web site and a Twitter feed.
The brains behind the TLD is a German-resident software developer called Aras Noori. He recently wrote to ICANN chief Rod Beckstrom, outlining his plan.

Two-letter .info auctions get go-ahead

Kevin Murphy, April 25, 2010, Domain Registries

ICANN has approved Afilias’ request to auction off its reserve of one and two-letter .info domain names.
The company seems to be planning to allocate the names both at auction and through a request-for-proposals process that would see registrants promise to develop and market their .info sites.
Any big partnerships could provide a welcome profile boost to .info, which has been around for a decade but still only grows about as much in a year as .com does in a month.
While auctions could also bring a nice windfall to the company, Afilias can expect to come under pressure from certain trademark holders to keep their brands off the market.
Volkswagen’s lawyers apparently “threatened every action in the book” to keep vw.biz out of Neustar’s allocation process for two-letter .biz names last year.

ICM launches .xxx letter-writing campaign

Kevin Murphy, April 24, 2010, Domain Registries

ICM Registry looks like it has taken a leaf from its opponents’ playbook, and is encouraging supporters of the proposed .xxx top-level domain to send form letters to ICANN.
The company has revamped its web site this week, to make it look a little less 2005, and part of the revamp is this page, which allows users to quickly send emails supporting the TLD to ICANN’s public comment forum, which ends May 10.
The letter addresses the substantial concerns of the comment period — namely, how ICANN should process the .xxx application in the light of February’s IRP decision, which says ICANN was wrong to reject .xxx in 2007.
In recent weeks, Christian groups and the pro-porn Free Speech Coalition have organized campaigns aimed at protesting .xxx. Both campaigns have resulted in large numbers of emails flooding ICANN.
The Christian letters are way off-topic, basically just anti-porn rants.
While the FSC letters do address ICANN’s question, they largely challenge the idea that .xxx has community support. This may end up not being a consideration for the Board.
By contrast, ICM’s letters go directly to ICANN’s core mantras of accountability and equality.
Its letter says: “Picking and choosing elements of the Panel’s declaration, or adding unnecessary procedural steps in adopting the review’s findings, would be a clear sign to the global Internet community that the organization cannot be relied upon to do its job fairly and objectively.”
The new ICM web site does, however, bear the new slogan “It’s time for adult websites to self label”.
It seems to me that this could be quite easily interpreted as a call for all adult web sites to use .xxx, which I’m pretty sure is not ICM’s intention.

ICANN picks Colombia for December meeting

Kevin Murphy, April 22, 2010, Domain Policy

ICANN chief Rod Beckstrom has just confirmed via Twitter that Cartagena, Colombia has been picked for the organization’s December meeting.
Judging from US State Department reports, the country is nowadays not nearly as scary as it was when Joan Wilder made a flying visit to rescue her sister in 1984.
Still, I’m guessing we’ll still see a little bit of that nervousness and paranoia that usually rears its head when ICANN heads for cities with a reputation for violent crime.
Terrorism concerns in Kenya caused many US stakeholders to stay at home and brave unreasonably early mornings participating remotely.
Even the choice of Mexico City caused a bit of a stir last year.
Personally, I’d love to see ICANN hold a meeting in Oakland or Baltimore, just to see what the security advisory looks like.