Happy #ICANN Reveal Fresh Hell Day!
-
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpn@badsamurai if submissions of this kind are likely to be rejected, it seems the red teamer's approach is simple -- pick pre-existing TLDs, and introduce them as file extensions for important file types!
Let's invent a new kind of .ai file, or a .net file (a file that connects you to the internet, maybe?)
(Of course, if you're a reasonable human being, this all is actually a terrible idea)
-
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpn@badsamurai I'd imagine Adobe would definitely object to this, as well as PHP also objecting to
.php -
@badsamurai if submissions of this kind are likely to be rejected, it seems the red teamer's approach is simple -- pick pre-existing TLDs, and introduce them as file extensions for important file types!
Let's invent a new kind of .ai file, or a .net file (a file that connects you to the internet, maybe?)
(Of course, if you're a reasonable human being, this all is actually a terrible idea)
.com used to be for DOS executables.
https://command.com/ is a home hardware company.
Not sure why this is a problem now all of a sudden.
-
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpn@badsamurai kinda like
.zipis being blocked by many corporate firewalls. -
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpnI missed
.lan,.corpand.mailwere also submitted. Corp and mail were originally rejected by ICANN in 2012 as thought too dangerous. Somehow 2026 is safer?.pdfand.phpare technically backup choices, but still an absurd submissions. As is.csrand.bin.The inherent trust words have their own issues:
.login.auth.account.admin.official.verified. I don't see how these are anything but a ransom against organizations to preempt squatting. -
I missed
.lan,.corpand.mailwere also submitted. Corp and mail were originally rejected by ICANN in 2012 as thought too dangerous. Somehow 2026 is safer?.pdfand.phpare technically backup choices, but still an absurd submissions. As is.csrand.bin.The inherent trust words have their own issues:
.login.auth.account.admin.official.verified. I don't see how these are anything but a ransom against organizations to preempt squatting.@badsamurai see i WOULDA said these would be fantastic redteaming domains, but since ai kinda killed redteaming, its now just prompt fodder for various prompt injection attacks and phishing shits
-
@badsamurai the IETF could do something very funny right now: publish an RFC that preemptively reserves the abusable ones.
@gsuberland @badsamurai yes, like
.exampleor.localare… -
.com used to be for DOS executables.
https://command.com/ is a home hardware company.
Not sure why this is a problem now all of a sudden.
@svavar @riverpunk @badsamurai how many #MSDOS machines were on the internet when it was relevant?
- Tinkerers like @rasteri are not the norm and shouldn't be taken as normative example!
-
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpn@badsamurai i still can't believe they allowed .zip and .app -
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpn@badsamurai Namespace Ian Malcom has some choice words about why they are called ICANN not ISHOULD.
-
@badsamurai see i WOULDA said these would be fantastic redteaming domains, but since ai kinda killed redteaming, its now just prompt fodder for various prompt injection attacks and phishing shits
@Viss @badsamurai exactly!
-
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpnThe applicant list in case y’all want in on the
and find something I’ve missed. -
@rl_dane @badsamurai it’s almost like there’s nobody at ICANN who has even vaguely considered the past few decades of cybersecurity
-
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpn@badsamurai@infosec.exchange just need .exe now
-
@rl_dane @badsamurai it’s almost like there’s nobody at ICANN who has even vaguely considered the past few decades of cybersecurity
@darkuncle @rl_dane Wait until the infosec
$vendorsstay mum through the entire process. Stopping pre-crime doesn’t exactly increase shareholder value. -
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpn@badsamurai No! No god no! Zip was already bad enough what the hell?
-
@darkuncle @rl_dane Wait until the infosec
$vendorsstay mum through the entire process. Stopping pre-crime doesn’t exactly increase shareholder value.@badsamurai @rl_dane there’s a lot more money to be made in selling a mitigation, than in a problem not existing in the first place
-
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpnI have applied for .invalid and .404
-
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpn@badsamurai I can accept every single one of them, but .php. There is no reason to use .php but to scam people. Nobody wants to have a domain name associated directly with php, other than php itself probably.
-
Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD
.pdfAnd these other spectacular submissions that surely won't end poorly:
.sys.key.duo.lab.private.state.auth.conf.config.loc.log.php.url.vpn@badsamurai
At this point, let's just create .exe as a honeypot and mark as phishing any domain that uses it?