Hacker News new | ask | show | jobs
by megamark16 5510 days ago
It took me about 10 minutes to write a python script that grabs a list of recently expired domains and checks each domain to see if it's a valid Google Apps domain. This is a pretty serious issue, if indeed it's still possible to take ownership of accounts as the article suggests. Hopefully Google has added some mitigating steps to keep this sort of thing from happening.
5 comments

How do you verify if a domain has a google apps account? I actually need this for a different, legitimate purpose.
The off the cuff way I was doing it was to go to https://mail.google.com/a/DOMAIN_NAME/ and see if I get a login screen or an error saying that the domain wasn't using google apps.
I see. Some domains use SAML authentication, so it doesn't work as well for them. E.g. uw.edu
arbuz1.ru baka-club.ru infame.ru puzkarapuz.ru luxury-institute.ru khrip-time.ru oilgasservice.ru voxtelecom.ru skippy.ru relaxpnz.ru kupi-proektor.ru akr-komanda.ru madamfurne.ru instaforgeg.ru oblomfilm.ru cmt-mitishi.ru 2mq.ru 4low.ru obzori.ru 2v4.ru tvfreak.ru concurent-vrn.ru baztv.su de-ti.ru autokg.ru kovgok.ru briztur.ru all-rest.ru opti-pro.ru infomarker.ru smartcities.ru stroystudio.ru instrumentnn.ru ontam.su beage.ru eds63.ru klint.ru moda1.ru otwod.ru nonic.ru pl110.ru apk-vs.ru mirrpg.ru sement.ru 1078fm.ru animirk.ru bigbear.ru dudusya.ru emiflex.ru odp-spb.ru
tltbutik.ru
123
sad