Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Happy #ICANN Reveal Fresh Hell Day!

Happy #ICANN Reveal Fresh Hell Day!

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
icanndnsrevealdayblueteamtld
67 Indlæg 45 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • mustardfacial@infosec.exchangeM mustardfacial@infosec.exchange

    @badsamurai not gonna lie, I kinda hope this one passes

    Also the amount of numbered companies in this list is fucking staggering

    badsamurai@infosec.exchangeB This user is from outside of this forum
    badsamurai@infosec.exchangeB This user is from outside of this forum
    badsamurai@infosec.exchange
    wrote sidst redigeret af
    #11

    @Mustardfacial I am not at all worried typo squatting on .fart

    And some solid future fedi server TLDs! .furry .meow .uwu .slay .neko

    ashirley@hachyderm.ioA 1 Reply Last reply
    0
    • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

      Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

      And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

      #DNS #RevealDay #blueTeam #tld

      gsuberland@chaos.socialG This user is from outside of this forum
      gsuberland@chaos.socialG This user is from outside of this forum
      gsuberland@chaos.social
      wrote sidst redigeret af
      #12

      @badsamurai the IETF could do something very funny right now: publish an RFC that preemptively reserves the abusable ones.

      netzblockierer@tech.lgbtN 1 Reply Last reply
      0
      • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

        Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

        And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

        #DNS #RevealDay #blueTeam #tld

        somebody@circumstances.runS This user is from outside of this forum
        somebody@circumstances.runS This user is from outside of this forum
        somebody@circumstances.run
        wrote sidst redigeret af
        #13

        @badsamurai oh come tf on 😭

        1 Reply Last reply
        0
        • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

          Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

          And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

          #DNS #RevealDay #blueTeam #tld

          jcm@wafrn.jcm.reJ This user is from outside of this forum
          jcm@wafrn.jcm.reJ This user is from outside of this forum
          jcm@wafrn.jcm.re
          wrote sidst redigeret af
          #14

          @badsamurai@infosec.exchange

          RFC 8369 would fix DNS, just saying

          1 Reply Last reply
          0
          • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

            @mttaggart But no one was really paying attention when CRR (Google) acquired .zip and .mov in 2013.

            This round we're going to file those objections (string confusion).

            No filenames, no intranet names, no assumed trust names.

            So I hope these orgs enjoyed their $227,000 donation to ICANN.

            https://newgtlds.icann.org/en/program-status/odr#objection-dispute-resolution

            gbargoud@masto.nycG This user is from outside of this forum
            gbargoud@masto.nycG This user is from outside of this forum
            gbargoud@masto.nyc
            wrote sidst redigeret af
            #15

            @badsamurai @mttaggart

            I did want someone to get .gif and .jpg so when someone comments "thatsthejoke.gif" or "surprisedpikachu.jpg" it could point to the appropriate one. Kind of like a URI for commonly used memes. It's definitely worth the security issues.

            1 Reply Last reply
            0
            • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

              Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

              And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

              #DNS #RevealDay #blueTeam #tld

              riverpunk@defcon.socialR This user is from outside of this forum
              riverpunk@defcon.socialR This user is from outside of this forum
              riverpunk@defcon.social
              wrote sidst redigeret af
              #16

              @badsamurai if submissions of this kind are likely to be rejected, it seems the red teamer's approach is simple -- pick pre-existing TLDs, and introduce them as file extensions for important file types!

              Let's invent a new kind of .ai file, or a .net file (a file that connects you to the internet, maybe?)

              (Of course, if you're a reasonable human being, this all is actually a terrible idea)

              svavar@masto.svavar.comS 1 Reply Last reply
              0
              • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                #DNS #RevealDay #blueTeam #tld

                yuki@im-in.spaceY This user is from outside of this forum
                yuki@im-in.spaceY This user is from outside of this forum
                yuki@im-in.space
                wrote sidst redigeret af
                #17

                @badsamurai I'd imagine Adobe would definitely object to this, as well as PHP also objecting to .php

                derickr@phpc.socialD 1 Reply Last reply
                0
                • riverpunk@defcon.socialR riverpunk@defcon.social

                  @badsamurai if submissions of this kind are likely to be rejected, it seems the red teamer's approach is simple -- pick pre-existing TLDs, and introduce them as file extensions for important file types!

                  Let's invent a new kind of .ai file, or a .net file (a file that connects you to the internet, maybe?)

                  (Of course, if you're a reasonable human being, this all is actually a terrible idea)

                  svavar@masto.svavar.comS This user is from outside of this forum
                  svavar@masto.svavar.comS This user is from outside of this forum
                  svavar@masto.svavar.com
                  wrote sidst redigeret af
                  #18

                  @riverpunk @badsamurai

                  .com used to be for DOS executables.

                  https://command.com/ is a home hardware company.

                  Not sure why this is a problem now all of a sudden.

                  netzblockierer@tech.lgbtN 1 Reply Last reply
                  0
                  • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                    Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                    And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                    #DNS #RevealDay #blueTeam #tld

                    netzblockierer@tech.lgbtN This user is from outside of this forum
                    netzblockierer@tech.lgbtN This user is from outside of this forum
                    netzblockierer@tech.lgbt
                    wrote sidst redigeret af
                    #19

                    @badsamurai kinda like .zip is being blocked by many corporate firewalls.

                    1 Reply Last reply
                    0
                    • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                      Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                      And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                      #DNS #RevealDay #blueTeam #tld

                      badsamurai@infosec.exchangeB This user is from outside of this forum
                      badsamurai@infosec.exchangeB This user is from outside of this forum
                      badsamurai@infosec.exchange
                      wrote sidst redigeret af
                      #20

                      I missed .lan, .corp and .mail were also submitted. Corp and mail were originally rejected by ICANN in 2012 as thought too dangerous. Somehow 2026 is safer?

                      .pdf and .php are technically backup choices, but still an absurd submissions. As is .csr and .bin.

                      The inherent trust words have their own issues: .login .auth .account .admin .official .verified. I don't see how these are anything but a ransom against organizations to preempt squatting.

                      viss@mastodon.socialV cblte@nrw.socialC 2 Replies Last reply
                      0
                      • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                        I missed .lan, .corp and .mail were also submitted. Corp and mail were originally rejected by ICANN in 2012 as thought too dangerous. Somehow 2026 is safer?

                        .pdf and .php are technically backup choices, but still an absurd submissions. As is .csr and .bin.

                        The inherent trust words have their own issues: .login .auth .account .admin .official .verified. I don't see how these are anything but a ransom against organizations to preempt squatting.

                        viss@mastodon.socialV This user is from outside of this forum
                        viss@mastodon.socialV This user is from outside of this forum
                        viss@mastodon.social
                        wrote sidst redigeret af
                        #21

                        @badsamurai see i WOULDA said these would be fantastic redteaming domains, but since ai kinda killed redteaming, its now just prompt fodder for various prompt injection attacks and phishing shits

                        netzblockierer@tech.lgbtN ai6yr@m.ai6yr.orgA 2 Replies Last reply
                        0
                        • gsuberland@chaos.socialG gsuberland@chaos.social

                          @badsamurai the IETF could do something very funny right now: publish an RFC that preemptively reserves the abusable ones.

                          netzblockierer@tech.lgbtN This user is from outside of this forum
                          netzblockierer@tech.lgbtN This user is from outside of this forum
                          netzblockierer@tech.lgbt
                          wrote sidst redigeret af
                          #22

                          @gsuberland @badsamurai yes, like .example or .local are…

                          1 Reply Last reply
                          0
                          • svavar@masto.svavar.comS svavar@masto.svavar.com

                            @riverpunk @badsamurai

                            .com used to be for DOS executables.

                            https://command.com/ is a home hardware company.

                            Not sure why this is a problem now all of a sudden.

                            netzblockierer@tech.lgbtN This user is from outside of this forum
                            netzblockierer@tech.lgbtN This user is from outside of this forum
                            netzblockierer@tech.lgbt
                            wrote sidst redigeret af
                            #23

                            @svavar @riverpunk @badsamurai how many #MSDOS machines were on the internet when it was relevant?

                            • Tinkerers like @rasteri are not the norm and shouldn't be taken as normative example!
                            svavar@masto.svavar.comS 1 Reply Last reply
                            0
                            • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                              Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                              And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                              #DNS #RevealDay #blueTeam #tld

                              ww@xyzzy.linkW This user is from outside of this forum
                              ww@xyzzy.linkW This user is from outside of this forum
                              ww@xyzzy.link
                              wrote sidst redigeret af
                              #24
                              @badsamurai i still can't believe they allowed .zip and .app
                              1 Reply Last reply
                              0
                              • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                                And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                                #DNS #RevealDay #blueTeam #tld

                                fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                fuzzyfuzzyfungus@cyberplace.social
                                wrote sidst redigeret af
                                #25

                                @badsamurai Namespace Ian Malcom has some choice words about why they are called ICANN not ISHOULD.

                                1 Reply Last reply
                                0
                                • viss@mastodon.socialV viss@mastodon.social

                                  @badsamurai see i WOULDA said these would be fantastic redteaming domains, but since ai kinda killed redteaming, its now just prompt fodder for various prompt injection attacks and phishing shits

                                  netzblockierer@tech.lgbtN This user is from outside of this forum
                                  netzblockierer@tech.lgbtN This user is from outside of this forum
                                  netzblockierer@tech.lgbt
                                  wrote sidst redigeret af
                                  #26

                                  @Viss @badsamurai exactly!

                                  1 Reply Last reply
                                  0
                                  • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                    Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                                    And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                                    #DNS #RevealDay #blueTeam #tld

                                    badsamurai@infosec.exchangeB This user is from outside of this forum
                                    badsamurai@infosec.exchangeB This user is from outside of this forum
                                    badsamurai@infosec.exchange
                                    wrote sidst redigeret af
                                    #27

                                    The applicant list in case y’all want in on the and find something I’ve missed.

                                    https://newgtldprogram-aps.icann.org/applications

                                    sehaas@chaos.socialS 1 Reply Last reply
                                    0
                                    • darkuncle@infosec.exchangeD This user is from outside of this forum
                                      darkuncle@infosec.exchangeD This user is from outside of this forum
                                      darkuncle@infosec.exchange
                                      wrote sidst redigeret af
                                      #28

                                      @rl_dane @badsamurai it’s almost like there’s nobody at ICANN who has even vaguely considered the past few decades of cybersecurity

                                      badsamurai@infosec.exchangeB 1 Reply Last reply
                                      0
                                      • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                        Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                                        And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                                        #DNS #RevealDay #blueTeam #tld

                                        alice@mk.nyaa.placeA This user is from outside of this forum
                                        alice@mk.nyaa.placeA This user is from outside of this forum
                                        alice@mk.nyaa.place
                                        wrote sidst redigeret af
                                        #29

                                        @badsamurai@infosec.exchange just need .exe now

                                        cstross@wandering.shopC 1 Reply Last reply
                                        0
                                        • darkuncle@infosec.exchangeD darkuncle@infosec.exchange

                                          @rl_dane @badsamurai it’s almost like there’s nobody at ICANN who has even vaguely considered the past few decades of cybersecurity

                                          badsamurai@infosec.exchangeB This user is from outside of this forum
                                          badsamurai@infosec.exchangeB This user is from outside of this forum
                                          badsamurai@infosec.exchange
                                          wrote sidst redigeret af
                                          #30

                                          @darkuncle @rl_dane Wait until the infosec $vendors stay mum through the entire process. Stopping pre-crime doesn’t exactly increase shareholder value.

                                          darkuncle@infosec.exchangeD 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper