Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Happy #ICANN Reveal Fresh Hell Day!

Happy #ICANN Reveal Fresh Hell Day!

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
icanndnsrevealdayblueteamtld
67 Indlæg 45 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • badsamurai@infosec.exchangeB This user is from outside of this forum
    badsamurai@infosec.exchangeB This user is from outside of this forum
    badsamurai@infosec.exchange
    wrote sidst redigeret af
    #1

    Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

    And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

    #DNS #RevealDay #blueTeam #tld

    mttaggart@infosec.exchangeM ? pberry@me.dmP mustardfacial@infosec.exchangeM luja@chaos.socialL 30 Replies Last reply
    1
    0
    • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

      Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

      And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

      #DNS #RevealDay #blueTeam #tld

      mttaggart@infosec.exchangeM This user is from outside of this forum
      mttaggart@infosec.exchangeM This user is from outside of this forum
      mttaggart@infosec.exchange
      wrote sidst redigeret af
      #2

      @badsamurai .zip about to have a lot of friends on some lists.

      Waitaminit...

      badsamurai@infosec.exchangeB 1 Reply Last reply
      0
      • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

        Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

        And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

        #DNS #RevealDay #blueTeam #tld

        ? Offline
        ? Offline
        Gæst
        wrote sidst redigeret af
        #3

        @badsamurai All these extra TLDs is a scam enabling scamming.

        1 Reply Last reply
        0
        • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

          @badsamurai .zip about to have a lot of friends on some lists.

          Waitaminit...

          badsamurai@infosec.exchangeB This user is from outside of this forum
          badsamurai@infosec.exchangeB This user is from outside of this forum
          badsamurai@infosec.exchange
          wrote sidst redigeret af
          #4

          @mttaggart But no one was really paying attention when CRR (Google) acquired .zip and .mov in 2013.

          This round we're going to file those objections (string confusion).

          No filenames, no intranet names, no assumed trust names.

          So I hope these orgs enjoyed their $227,000 donation to ICANN.

          https://newgtlds.icann.org/en/program-status/odr#objection-dispute-resolution

          gbargoud@masto.nycG drwho@masto.hackers.townD 2 Replies Last reply
          0
          • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

            Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

            And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

            #DNS #RevealDay #blueTeam #tld

            pberry@me.dmP This user is from outside of this forum
            pberry@me.dmP This user is from outside of this forum
            pberry@me.dm
            wrote sidst redigeret af
            #5

            @badsamurai so… https://pdf.pdf/pdf.pdf could be a legit url 🤣

            svavar@masto.svavar.comS 1 Reply Last reply
            0
            • pberry@me.dmP pberry@me.dm

              @badsamurai so… https://pdf.pdf/pdf.pdf could be a legit url 🤣

              svavar@masto.svavar.comS This user is from outside of this forum
              svavar@masto.svavar.comS This user is from outside of this forum
              svavar@masto.svavar.com
              wrote sidst redigeret af
              #6

              @pberry @badsamurai

              This is not a new thing.

              https://md.md/md.md has been valid for decades.

              https://readme.md is run by some AI slop directory.

              pberry@me.dmP badsamurai@infosec.exchangeB 2 Replies Last reply
              0
              • svavar@masto.svavar.comS svavar@masto.svavar.com

                @pberry @badsamurai

                This is not a new thing.

                https://md.md/md.md has been valid for decades.

                https://readme.md is run by some AI slop directory.

                pberry@me.dmP This user is from outside of this forum
                pberry@me.dmP This user is from outside of this forum
                pberry@me.dm
                wrote sidst redigeret af
                #7

                @svavar @badsamurai yeah, but pdf is way funnier than md

                1 Reply Last reply
                0
                • svavar@masto.svavar.comS svavar@masto.svavar.com

                  @pberry @badsamurai

                  This is not a new thing.

                  https://md.md/md.md has been valid for decades.

                  https://readme.md is run by some AI slop directory.

                  badsamurai@infosec.exchangeB This user is from outside of this forum
                  badsamurai@infosec.exchangeB This user is from outside of this forum
                  badsamurai@infosec.exchange
                  wrote sidst redigeret af
                  #8

                  @svavar @pberry

                  Correct, .md is a ccTLD that's been around longer than markdown. But this is 2026 and these domains have an extremely high likelihood for abuse in phishing, clickfix, and supply chain attacks. ICANN allowing these would be irresponsible.

                  Once these are approved, there will be no oversight. .duo was applied for by ShortDot, a notorious bulletproof operator known for some of the most abused TLDs on the internet today: .bond .sbs .icu and .cyou

                  1 Reply Last reply
                  0
                  • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                    Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                    And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                    #DNS #RevealDay #blueTeam #tld

                    mustardfacial@infosec.exchangeM This user is from outside of this forum
                    mustardfacial@infosec.exchangeM This user is from outside of this forum
                    mustardfacial@infosec.exchange
                    wrote sidst redigeret af
                    #9

                    @badsamurai not gonna lie, I kinda hope this one passes

                    Also the amount of numbered companies in this list is fucking staggering

                    badsamurai@infosec.exchangeB varx@cybersecurity.theaterV 2 Replies Last reply
                    0
                    • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                      Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                      And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                      #DNS #RevealDay #blueTeam #tld

                      luja@chaos.socialL This user is from outside of this forum
                      luja@chaos.socialL This user is from outside of this forum
                      luja@chaos.social
                      wrote sidst redigeret af
                      #10

                      @badsamurai
                      .alder
                      .bruder

                      1 Reply Last reply
                      0
                      • mustardfacial@infosec.exchangeM mustardfacial@infosec.exchange

                        @badsamurai not gonna lie, I kinda hope this one passes

                        Also the amount of numbered companies in this list is fucking staggering

                        badsamurai@infosec.exchangeB This user is from outside of this forum
                        badsamurai@infosec.exchangeB This user is from outside of this forum
                        badsamurai@infosec.exchange
                        wrote sidst redigeret af
                        #11

                        @Mustardfacial I am not at all worried typo squatting on .fart

                        And some solid future fedi server TLDs! .furry .meow .uwu .slay .neko

                        ashirley@hachyderm.ioA 1 Reply Last reply
                        0
                        • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                          Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                          And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                          #DNS #RevealDay #blueTeam #tld

                          gsuberland@chaos.socialG This user is from outside of this forum
                          gsuberland@chaos.socialG This user is from outside of this forum
                          gsuberland@chaos.social
                          wrote sidst redigeret af
                          #12

                          @badsamurai the IETF could do something very funny right now: publish an RFC that preemptively reserves the abusable ones.

                          netzblockierer@tech.lgbtN 1 Reply Last reply
                          0
                          • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                            Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                            And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                            #DNS #RevealDay #blueTeam #tld

                            somebody@circumstances.runS This user is from outside of this forum
                            somebody@circumstances.runS This user is from outside of this forum
                            somebody@circumstances.run
                            wrote sidst redigeret af
                            #13

                            @badsamurai oh come tf on 😭

                            1 Reply Last reply
                            0
                            • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                              Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                              And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                              #DNS #RevealDay #blueTeam #tld

                              jcm@wafrn.jcm.reJ This user is from outside of this forum
                              jcm@wafrn.jcm.reJ This user is from outside of this forum
                              jcm@wafrn.jcm.re
                              wrote sidst redigeret af
                              #14

                              @badsamurai@infosec.exchange

                              RFC 8369 would fix DNS, just saying

                              1 Reply Last reply
                              0
                              • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                @mttaggart But no one was really paying attention when CRR (Google) acquired .zip and .mov in 2013.

                                This round we're going to file those objections (string confusion).

                                No filenames, no intranet names, no assumed trust names.

                                So I hope these orgs enjoyed their $227,000 donation to ICANN.

                                https://newgtlds.icann.org/en/program-status/odr#objection-dispute-resolution

                                gbargoud@masto.nycG This user is from outside of this forum
                                gbargoud@masto.nycG This user is from outside of this forum
                                gbargoud@masto.nyc
                                wrote sidst redigeret af
                                #15

                                @badsamurai @mttaggart

                                I did want someone to get .gif and .jpg so when someone comments "thatsthejoke.gif" or "surprisedpikachu.jpg" it could point to the appropriate one. Kind of like a URI for commonly used memes. It's definitely worth the security issues.

                                1 Reply Last reply
                                0
                                • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                  Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                                  And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                                  #DNS #RevealDay #blueTeam #tld

                                  riverpunk@defcon.socialR This user is from outside of this forum
                                  riverpunk@defcon.socialR This user is from outside of this forum
                                  riverpunk@defcon.social
                                  wrote sidst redigeret af
                                  #16

                                  @badsamurai if submissions of this kind are likely to be rejected, it seems the red teamer's approach is simple -- pick pre-existing TLDs, and introduce them as file extensions for important file types!

                                  Let's invent a new kind of .ai file, or a .net file (a file that connects you to the internet, maybe?)

                                  (Of course, if you're a reasonable human being, this all is actually a terrible idea)

                                  svavar@masto.svavar.comS 1 Reply Last reply
                                  0
                                  • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                    Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                                    And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                                    #DNS #RevealDay #blueTeam #tld

                                    yuki@im-in.spaceY This user is from outside of this forum
                                    yuki@im-in.spaceY This user is from outside of this forum
                                    yuki@im-in.space
                                    wrote sidst redigeret af
                                    #17

                                    @badsamurai I'd imagine Adobe would definitely object to this, as well as PHP also objecting to .php

                                    derickr@phpc.socialD 1 Reply Last reply
                                    0
                                    • riverpunk@defcon.socialR riverpunk@defcon.social

                                      @badsamurai if submissions of this kind are likely to be rejected, it seems the red teamer's approach is simple -- pick pre-existing TLDs, and introduce them as file extensions for important file types!

                                      Let's invent a new kind of .ai file, or a .net file (a file that connects you to the internet, maybe?)

                                      (Of course, if you're a reasonable human being, this all is actually a terrible idea)

                                      svavar@masto.svavar.comS This user is from outside of this forum
                                      svavar@masto.svavar.comS This user is from outside of this forum
                                      svavar@masto.svavar.com
                                      wrote sidst redigeret af
                                      #18

                                      @riverpunk @badsamurai

                                      .com used to be for DOS executables.

                                      https://command.com/ is a home hardware company.

                                      Not sure why this is a problem now all of a sudden.

                                      netzblockierer@tech.lgbtN 1 Reply Last reply
                                      0
                                      • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                        Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                                        And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                                        #DNS #RevealDay #blueTeam #tld

                                        netzblockierer@tech.lgbtN This user is from outside of this forum
                                        netzblockierer@tech.lgbtN This user is from outside of this forum
                                        netzblockierer@tech.lgbt
                                        wrote sidst redigeret af
                                        #19

                                        @badsamurai kinda like .zip is being blocked by many corporate firewalls.

                                        1 Reply Last reply
                                        0
                                        • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                          Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                                          And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                                          #DNS #RevealDay #blueTeam #tld

                                          badsamurai@infosec.exchangeB This user is from outside of this forum
                                          badsamurai@infosec.exchangeB This user is from outside of this forum
                                          badsamurai@infosec.exchange
                                          wrote sidst redigeret af
                                          #20

                                          I missed .lan, .corp and .mail were also submitted. Corp and mail were originally rejected by ICANN in 2012 as thought too dangerous. Somehow 2026 is safer?

                                          .pdf and .php are technically backup choices, but still an absurd submissions. As is .csr and .bin.

                                          The inherent trust words have their own issues: .login .auth .account .admin .official .verified. I don't see how these are anything but a ransom against organizations to preempt squatting.

                                          viss@mastodon.socialV cblte@nrw.socialC 2 Replies Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper