I have a problem with my domain. One of our domains seems to have been hacked.
The domain “dezentralbox.org” points to a torrent page. This is not our Site and we dont know why this happen.
Here is a screenshot of the site: Imgur: The magic of the Internet
Hello, thanks for replying. So that I can explain the whole problem in detail, I wanted to insert more than 2 links. Unfortunately this was not possible.
I have a problem with my domain. One of our domains seems to have been hacked.
The domain “dezentralbox.org” points to a torrent page. This is not our Site and we dont know why this happen.
Here is a screenshot of the site: Imgur: The magic of the Internet
We have 20+ domains. The Domains are located on on Raidboxes.de and are redirected with Claoudflare to our main side “decentralbox.com”.
I do not know unfortunately, how my old agency made that with the forwarding by Cloudflare. But they claim that they have NOTHING to do with it.
Also raidboxes says, that this is a problem on Cloudflare, because the domains point to the nameserver of Cloudflare.
But if I log in on Cloudflare, I do not see forwarding or an entry for the Domain “dezentralbox.org”
These nameserver from Cloudflare are also active on other domains from me, but there was no such mess.
Question 1: What was hacked now? Account of Raidboxes or Cloudflare?
Question 2: Which passwords do I have to change? Email, Hoster, Raidboxes and Cloudflare, or just EVERYTHING?
Question 3: Can our website “decentralbox. com” also be hacked, only we don’t know it yet?
Your domain registrar is the company where you registered the domain name. That may or may not be the same as your hosting company.
This is the offending name server that needs to be removed - decentralbox.com
I don’t know if that will resolve the issue or not, you may have an incorrect IP address in the DNS tab of your Cloudflare dashboard. But, decentralbox.com as a name server is incorrect and needs to be removed.
@user382, it does not appear that you’ve successfully even added the zone to Cloudflare.
dezentralbox.org is pending and has completely incorrect name servers. You need to login to your Cloudflare account for that .org domain, verify what name servers you should use, contact your registrar and have them update them to the ones you should use.
decentralbox.com is active, has the correct name servers and also has one incorrect one. You need contact your registrar and have them remove the non Cloudflare name server.
No, your site should not go down when you remove the name server, but it’s one less variable in troubleshooting the issue.
Regarding your other questions, if you think you’ve been hacked, change all your passwords (cf, host, registrar), (use a pw manager), rotate your api key, turn on 2fa, and scan all devices for malware.
This domain has a non-cf name server (decentralbox.com) that should be removed. Seems if you remove the incorrect name server on dezentralbox.org and where ever else you have an extra one on any of your other domains, we’ll be at a point where we can figure out what issue we’re facing:
Finally, this domain (also called a zone) is not even on Cloudflare and that leaves it vulnerable to takeover as it has Cloudflare name servers (and a non-cf one). You need to add this zone to your account ASAP, verify the name server names, and give those two names to your registrar and have them update them.
@user382, when you contact them, here is what I suspect happened:
I suspect you started to see issues about 20 days ago?
The name servers for dezentralbox.org were changed to Cloudflare george & dorthy 4 months ago, based on the security trails link below, but not added to a Cloudflare account. Does that timing make sense?
@user382, I’d ask your agency to add dezentralbox.org to your Cloudflare account, verify the nameservers you’re assigned are george & dorthy, and then make sure those are the only two your registrar has for that domain.