The
administrative email
address associated
with the domain is
the backdoor
to hijack the domain
name. It is the key
to unlock the domain
control panel. So to
take full control of
the domain, the
hacker will hack the
administrative email
associated with it.
Email hacking has
been discussed in my
previous post
how to hack an email
account.
Once
the hacker take full
control of this
email account, he
will visit the
domain registrar’s
website and click on
forgot password
in the login
page. There he
will be asked to
enter either the
domain name or
the
administrative email
address to
initiate the
password reset
process. Once this
is done all the
details to reset the
password will be
sent to the
administrative email
address. Since the
hacker has
the access to this
email account he can
easily reset the
password of domain
control panel. After
resetting the
password, he logs
into the control
panel with the new
password and from
there he can hijack
the domain within
minutes.