Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Happy #ICANN Reveal Fresh Hell Day!

Happy #ICANN Reveal Fresh Hell Day!

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
icanndnsrevealdayblueteamtld
67 Indlæg 45 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • svavar@masto.svavar.comS svavar@masto.svavar.com

    @riverpunk @badsamurai

    .com used to be for DOS executables.

    https://command.com/ is a home hardware company.

    Not sure why this is a problem now all of a sudden.

    netzblockierer@tech.lgbtN This user is from outside of this forum
    netzblockierer@tech.lgbtN This user is from outside of this forum
    netzblockierer@tech.lgbt
    wrote sidst redigeret af
    #23

    @svavar @riverpunk @badsamurai how many #MSDOS machines were on the internet when it was relevant?

    • Tinkerers like @rasteri are not the norm and shouldn't be taken as normative example!
    svavar@masto.svavar.comS 1 Reply Last reply
    0
    • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

      Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

      And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

      #DNS #RevealDay #blueTeam #tld

      ww@xyzzy.linkW This user is from outside of this forum
      ww@xyzzy.linkW This user is from outside of this forum
      ww@xyzzy.link
      wrote sidst redigeret af
      #24
      @badsamurai i still can't believe they allowed .zip and .app
      1 Reply Last reply
      0
      • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

        Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

        And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

        #DNS #RevealDay #blueTeam #tld

        fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
        fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
        fuzzyfuzzyfungus@cyberplace.social
        wrote sidst redigeret af
        #25

        @badsamurai Namespace Ian Malcom has some choice words about why they are called ICANN not ISHOULD.

        1 Reply Last reply
        0
        • viss@mastodon.socialV viss@mastodon.social

          @badsamurai see i WOULDA said these would be fantastic redteaming domains, but since ai kinda killed redteaming, its now just prompt fodder for various prompt injection attacks and phishing shits

          netzblockierer@tech.lgbtN This user is from outside of this forum
          netzblockierer@tech.lgbtN This user is from outside of this forum
          netzblockierer@tech.lgbt
          wrote sidst redigeret af
          #26

          @Viss @badsamurai exactly!

          1 Reply Last reply
          0
          • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

            Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

            And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

            #DNS #RevealDay #blueTeam #tld

            badsamurai@infosec.exchangeB This user is from outside of this forum
            badsamurai@infosec.exchangeB This user is from outside of this forum
            badsamurai@infosec.exchange
            wrote sidst redigeret af
            #27

            The applicant list in case y’all want in on the and find something I’ve missed.

            https://newgtldprogram-aps.icann.org/applications

            sehaas@chaos.socialS 1 Reply Last reply
            0
            • darkuncle@infosec.exchangeD This user is from outside of this forum
              darkuncle@infosec.exchangeD This user is from outside of this forum
              darkuncle@infosec.exchange
              wrote sidst redigeret af
              #28

              @rl_dane @badsamurai it’s almost like there’s nobody at ICANN who has even vaguely considered the past few decades of cybersecurity

              badsamurai@infosec.exchangeB 1 Reply Last reply
              0
              • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                #DNS #RevealDay #blueTeam #tld

                alice@mk.nyaa.placeA This user is from outside of this forum
                alice@mk.nyaa.placeA This user is from outside of this forum
                alice@mk.nyaa.place
                wrote sidst redigeret af
                #29

                @badsamurai@infosec.exchange just need .exe now

                cstross@wandering.shopC 1 Reply Last reply
                0
                • darkuncle@infosec.exchangeD darkuncle@infosec.exchange

                  @rl_dane @badsamurai it’s almost like there’s nobody at ICANN who has even vaguely considered the past few decades of cybersecurity

                  badsamurai@infosec.exchangeB This user is from outside of this forum
                  badsamurai@infosec.exchangeB This user is from outside of this forum
                  badsamurai@infosec.exchange
                  wrote sidst redigeret af
                  #30

                  @darkuncle @rl_dane Wait until the infosec $vendors stay mum through the entire process. Stopping pre-crime doesn’t exactly increase shareholder value.

                  darkuncle@infosec.exchangeD 1 Reply Last reply
                  0
                  • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                    Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                    And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                    #DNS #RevealDay #blueTeam #tld

                    kemotep@mastodo.neoliber.alK This user is from outside of this forum
                    kemotep@mastodo.neoliber.alK This user is from outside of this forum
                    kemotep@mastodo.neoliber.al
                    wrote sidst redigeret af
                    #31

                    @badsamurai No! No god no! Zip was already bad enough what the hell?

                    1 Reply Last reply
                    0
                    • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                      @darkuncle @rl_dane Wait until the infosec $vendors stay mum through the entire process. Stopping pre-crime doesn’t exactly increase shareholder value.

                      darkuncle@infosec.exchangeD This user is from outside of this forum
                      darkuncle@infosec.exchangeD This user is from outside of this forum
                      darkuncle@infosec.exchange
                      wrote sidst redigeret af
                      #32

                      @badsamurai @rl_dane there’s a lot more money to be made in selling a mitigation, than in a problem not existing in the first place

                      1 Reply Last reply
                      0
                      • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                        Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                        And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                        #DNS #RevealDay #blueTeam #tld

                        kevinrns@mstdn.socialK This user is from outside of this forum
                        kevinrns@mstdn.socialK This user is from outside of this forum
                        kevinrns@mstdn.social
                        wrote sidst redigeret af
                        #33

                        @badsamurai

                        I have applied for .invalid and .404

                        1 Reply Last reply
                        0
                        • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                          Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                          And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                          #DNS #RevealDay #blueTeam #tld

                          albi@furry.engineerA This user is from outside of this forum
                          albi@furry.engineerA This user is from outside of this forum
                          albi@furry.engineer
                          wrote sidst redigeret af
                          #34

                          @badsamurai I can accept every single one of them, but .php. There is no reason to use .php but to scam people. Nobody wants to have a domain name associated directly with php, other than php itself probably.

                          1 Reply Last reply
                          0
                          • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                            Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                            And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                            #DNS #RevealDay #blueTeam #tld

                            ddlyh@topspicy.socialD This user is from outside of this forum
                            ddlyh@topspicy.socialD This user is from outside of this forum
                            ddlyh@topspicy.social
                            wrote sidst redigeret af
                            #35

                            @badsamurai
                            At this point, let's just create .exe as a honeypot and mark as phishing any domain that uses it?

                            1 Reply Last reply
                            0
                            • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                              Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                              And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                              #DNS #RevealDay #blueTeam #tld

                              ddlyh@topspicy.socialD This user is from outside of this forum
                              ddlyh@topspicy.socialD This user is from outside of this forum
                              ddlyh@topspicy.social
                              wrote sidst redigeret af
                              #36

                              @badsamurai
                              How long before ".corn" is a thing?

                              1 Reply Last reply
                              0
                              • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                                And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                                #DNS #RevealDay #blueTeam #tld

                                albi@furry.engineerA This user is from outside of this forum
                                albi@furry.engineerA This user is from outside of this forum
                                albi@furry.engineer
                                wrote sidst redigeret af
                                #37

                                @badsamurai We already have DNS servers that blanket ban "unsafe" TLDs. Are we asking for even more trouble?
                                If you run an org/corp, how could you not ban .pdf or .official?

                                badsamurai@infosec.exchangeB 1 Reply Last reply
                                0
                                • albi@furry.engineerA albi@furry.engineer

                                  @badsamurai We already have DNS servers that blanket ban "unsafe" TLDs. Are we asking for even more trouble?
                                  If you run an org/corp, how could you not ban .pdf or .official?

                                  badsamurai@infosec.exchangeB This user is from outside of this forum
                                  badsamurai@infosec.exchangeB This user is from outside of this forum
                                  badsamurai@infosec.exchange
                                  wrote sidst redigeret af
                                  #38

                                  @Albi Oh def, I already blocked .gram on principle. The problem is when they target your customers, partners and supply chains outside of your network. This is commonly observed with recruiting related domains like {brand}jobs and {brand}careers. The domains remain parked, but they’ll have active MX records and never send to your org specifically.

                                  Then your average user or small business doesn’t have the skill or tooling to configure firewalls, NextDNS, etc. I take security by design to not just be memory safe computing, but holistic prevention at conceptual birth.

                                  albi@furry.engineerA 1 Reply Last reply
                                  0
                                  • viss@mastodon.socialV viss@mastodon.social

                                    @badsamurai see i WOULDA said these would be fantastic redteaming domains, but since ai kinda killed redteaming, its now just prompt fodder for various prompt injection attacks and phishing shits

                                    ai6yr@m.ai6yr.orgA This user is from outside of this forum
                                    ai6yr@m.ai6yr.orgA This user is from outside of this forum
                                    ai6yr@m.ai6yr.org
                                    wrote sidst redigeret af
                                    #39

                                    @Viss @badsamurai is ".wtf" a TLD yet?

                                    theorangetheme@en.osm.townT himysyed@littleone.littlefedi.socialH logaldeveloper@infosec.exchangeL 3 Replies Last reply
                                    0
                                    • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                      @Albi Oh def, I already blocked .gram on principle. The problem is when they target your customers, partners and supply chains outside of your network. This is commonly observed with recruiting related domains like {brand}jobs and {brand}careers. The domains remain parked, but they’ll have active MX records and never send to your org specifically.

                                      Then your average user or small business doesn’t have the skill or tooling to configure firewalls, NextDNS, etc. I take security by design to not just be memory safe computing, but holistic prevention at conceptual birth.

                                      albi@furry.engineerA This user is from outside of this forum
                                      albi@furry.engineerA This user is from outside of this forum
                                      albi@furry.engineer
                                      wrote sidst redigeret af
                                      #40

                                      @badsamurai I already advocate for taking down/replacing/avoiding the current domain name system due to it's architecture constraints, control and censorship concerns and lack of ownership.
                                      From what I know the only viable alternative is namecoin, which I am not too fond of and still disagree with the way it works fundamentally.
                                      We need an alternative URI for an alternative DNS revolution, not just a patch on the current infrastructure.
                                      When we mix 2 DNS authorities together, we get problems.

                                      1 Reply Last reply
                                      0
                                      • ai6yr@m.ai6yr.orgA ai6yr@m.ai6yr.org

                                        @Viss @badsamurai is ".wtf" a TLD yet?

                                        theorangetheme@en.osm.townT This user is from outside of this forum
                                        theorangetheme@en.osm.townT This user is from outside of this forum
                                        theorangetheme@en.osm.town
                                        wrote sidst redigeret af
                                        #41

                                        @ai6yr @Viss @badsamurai It could be! 😉

                                        5cifigirl@indieverse.social5 1 Reply Last reply
                                        0
                                        • ai6yr@m.ai6yr.orgA ai6yr@m.ai6yr.org

                                          @Viss @badsamurai is ".wtf" a TLD yet?

                                          himysyed@littleone.littlefedi.socialH This user is from outside of this forum
                                          himysyed@littleone.littlefedi.socialH This user is from outside of this forum
                                          himysyed@littleone.littlefedi.social
                                          wrote sidst redigeret af
                                          #42

                                          @ai6yr@m.ai6yr.org @Viss@mastodon.social @badsamurai@infosec.exchange https://en.wikipedia.org/wiki/.wtf

                                          viss@mastodon.socialV 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper