Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Happy #ICANN Reveal Fresh Hell Day!

Happy #ICANN Reveal Fresh Hell Day!

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
icanndnsrevealdayblueteamtld
67 Indlæg 45 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • albi@furry.engineerA albi@furry.engineer

    @badsamurai We already have DNS servers that blanket ban "unsafe" TLDs. Are we asking for even more trouble?
    If you run an org/corp, how could you not ban .pdf or .official?

    badsamurai@infosec.exchangeB This user is from outside of this forum
    badsamurai@infosec.exchangeB This user is from outside of this forum
    badsamurai@infosec.exchange
    wrote sidst redigeret af
    #38

    @Albi Oh def, I already blocked .gram on principle. The problem is when they target your customers, partners and supply chains outside of your network. This is commonly observed with recruiting related domains like {brand}jobs and {brand}careers. The domains remain parked, but they’ll have active MX records and never send to your org specifically.

    Then your average user or small business doesn’t have the skill or tooling to configure firewalls, NextDNS, etc. I take security by design to not just be memory safe computing, but holistic prevention at conceptual birth.

    albi@furry.engineerA 1 Reply Last reply
    0
    • viss@mastodon.socialV viss@mastodon.social

      @badsamurai see i WOULDA said these would be fantastic redteaming domains, but since ai kinda killed redteaming, its now just prompt fodder for various prompt injection attacks and phishing shits

      ai6yr@m.ai6yr.orgA This user is from outside of this forum
      ai6yr@m.ai6yr.orgA This user is from outside of this forum
      ai6yr@m.ai6yr.org
      wrote sidst redigeret af
      #39

      @Viss @badsamurai is ".wtf" a TLD yet?

      theorangetheme@en.osm.townT himysyed@littleone.littlefedi.socialH logaldeveloper@infosec.exchangeL 3 Replies Last reply
      0
      • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

        @Albi Oh def, I already blocked .gram on principle. The problem is when they target your customers, partners and supply chains outside of your network. This is commonly observed with recruiting related domains like {brand}jobs and {brand}careers. The domains remain parked, but they’ll have active MX records and never send to your org specifically.

        Then your average user or small business doesn’t have the skill or tooling to configure firewalls, NextDNS, etc. I take security by design to not just be memory safe computing, but holistic prevention at conceptual birth.

        albi@furry.engineerA This user is from outside of this forum
        albi@furry.engineerA This user is from outside of this forum
        albi@furry.engineer
        wrote sidst redigeret af
        #40

        @badsamurai I already advocate for taking down/replacing/avoiding the current domain name system due to it's architecture constraints, control and censorship concerns and lack of ownership.
        From what I know the only viable alternative is namecoin, which I am not too fond of and still disagree with the way it works fundamentally.
        We need an alternative URI for an alternative DNS revolution, not just a patch on the current infrastructure.
        When we mix 2 DNS authorities together, we get problems.

        1 Reply Last reply
        0
        • ai6yr@m.ai6yr.orgA ai6yr@m.ai6yr.org

          @Viss @badsamurai is ".wtf" a TLD yet?

          theorangetheme@en.osm.townT This user is from outside of this forum
          theorangetheme@en.osm.townT This user is from outside of this forum
          theorangetheme@en.osm.town
          wrote sidst redigeret af
          #41

          @ai6yr @Viss @badsamurai It could be! 😉

          5cifigirl@indieverse.social5 1 Reply Last reply
          0
          • ai6yr@m.ai6yr.orgA ai6yr@m.ai6yr.org

            @Viss @badsamurai is ".wtf" a TLD yet?

            himysyed@littleone.littlefedi.socialH This user is from outside of this forum
            himysyed@littleone.littlefedi.socialH This user is from outside of this forum
            himysyed@littleone.littlefedi.social
            wrote sidst redigeret af
            #42

            @ai6yr@m.ai6yr.org @Viss@mastodon.social @badsamurai@infosec.exchange https://en.wikipedia.org/wiki/.wtf

            viss@mastodon.socialV 1 Reply Last reply
            0
            • himysyed@littleone.littlefedi.socialH himysyed@littleone.littlefedi.social

              @ai6yr@m.ai6yr.org @Viss@mastodon.social @badsamurai@infosec.exchange https://en.wikipedia.org/wiki/.wtf

              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.social
              wrote sidst redigeret af
              #43

              @himysyed @ai6yr @badsamurai i own a couple .wtf domains 😄

              1 Reply Last reply
              0
              • ai6yr@m.ai6yr.orgA ai6yr@m.ai6yr.org

                @Viss @badsamurai is ".wtf" a TLD yet?

                logaldeveloper@infosec.exchangeL This user is from outside of this forum
                logaldeveloper@infosec.exchangeL This user is from outside of this forum
                logaldeveloper@infosec.exchange
                wrote sidst redigeret af
                #44

                @ai6yr @Viss @badsamurai my go to IP checker is https://myip.wtf/

                viss@mastodon.socialV autoiue@mastodon.xn--cfa.xyzA 2 Replies Last reply
                0
                • logaldeveloper@infosec.exchangeL logaldeveloper@infosec.exchange

                  @ai6yr @Viss @badsamurai my go to IP checker is https://myip.wtf/

                  viss@mastodon.socialV This user is from outside of this forum
                  viss@mastodon.socialV This user is from outside of this forum
                  viss@mastodon.social
                  wrote sidst redigeret af
                  #45

                  @logaldeveloper @ai6yr @badsamurai hah, wtf indeed

                  1 Reply Last reply
                  0
                  • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                    @mttaggart But no one was really paying attention when CRR (Google) acquired .zip and .mov in 2013.

                    This round we're going to file those objections (string confusion).

                    No filenames, no intranet names, no assumed trust names.

                    So I hope these orgs enjoyed their $227,000 donation to ICANN.

                    https://newgtlds.icann.org/en/program-status/odr#objection-dispute-resolution

                    drwho@masto.hackers.townD This user is from outside of this forum
                    drwho@masto.hackers.townD This user is from outside of this forum
                    drwho@masto.hackers.town
                    wrote sidst redigeret af
                    #46

                    @badsamurai @mttaggart They'll get what they paid for.

                    1 Reply Last reply
                    0
                    • mustardfacial@infosec.exchangeM mustardfacial@infosec.exchange

                      @badsamurai not gonna lie, I kinda hope this one passes

                      Also the amount of numbered companies in this list is fucking staggering

                      varx@cybersecurity.theaterV This user is from outside of this forum
                      varx@cybersecurity.theaterV This user is from outside of this forum
                      varx@cybersecurity.theater
                      wrote sidst redigeret af
                      #47

                      @Mustardfacial @badsamurai Frankly, I'm a TLD accelerationist. The sooner we can have strings like "README.md" stop being auto-garbled into clickable URLs, the better.

                      1 Reply Last reply
                      0
                      • theorangetheme@en.osm.townT theorangetheme@en.osm.town

                        @ai6yr @Viss @badsamurai It could be! 😉

                        5cifigirl@indieverse.social5 This user is from outside of this forum
                        5cifigirl@indieverse.social5 This user is from outside of this forum
                        5cifigirl@indieverse.social
                        wrote sidst redigeret af
                        #48

                        @theorangetheme @ai6yr @Viss @badsamurai

                        It has been for a while! My previous masto server for several years ( that just shut down in August), was starbase80.wtf!

                        And see: https://en.wikipedia.org/wiki/.wtf

                        1 Reply Last reply
                        0
                        • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                          Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                          And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                          #DNS #RevealDay #blueTeam #tld

                          opha@void.lgbtO This user is from outside of this forum
                          opha@void.lgbtO This user is from outside of this forum
                          opha@void.lgbt
                          wrote sidst redigeret af
                          #49
                          @badsamurai Give me a .trans domain.
                          1 Reply Last reply
                          0
                          • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                            Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                            And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                            #DNS #RevealDay #blueTeam #tld

                            ewhac@mastodon.socialE This user is from outside of this forum
                            ewhac@mastodon.socialE This user is from outside of this forum
                            ewhac@mastodon.social
                            wrote sidst redigeret af
                            #50

                            @badsamurai I call dibs on `.csv` and `.sh`.

                            andrewg@mastodon.ieA 1 Reply Last reply
                            0
                            • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                              The applicant list in case y’all want in on the and find something I’ve missed.

                              https://newgtldprogram-aps.icann.org/applications

                              sehaas@chaos.socialS This user is from outside of this forum
                              sehaas@chaos.socialS This user is from outside of this forum
                              sehaas@chaos.social
                              wrote sidst redigeret af
                              #51

                              @badsamurai one of my favorites is .scam
                              https://newgtldprogram-aps.icann.org/applications/XL2625T-T13533/summary

                              delcj@mas.toD 1 Reply Last reply
                              0
                              • sehaas@chaos.socialS sehaas@chaos.social

                                @badsamurai one of my favorites is .scam
                                https://newgtldprogram-aps.icann.org/applications/XL2625T-T13533/summary

                                delcj@mas.toD This user is from outside of this forum
                                delcj@mas.toD This user is from outside of this forum
                                delcj@mas.to
                                wrote sidst redigeret af
                                #52

                                @sehaas it's kind of cute that the applicant is xyz.com llc but their website is xyz.xyz @badsamurai

                                1 Reply Last reply
                                0
                                • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                  Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                                  And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                                  #DNS #RevealDay #blueTeam #tld

                                  dirk@gts.0x7be.netD This user is from outside of this forum
                                  dirk@gts.0x7be.netD This user is from outside of this forum
                                  dirk@gts.0x7be.net
                                  wrote sidst redigeret af
                                  #53

                                  @badsamurai So the #ICANN doesn’t care anymore about anything?

                                  On the other hand it’s funny that THIS would be a fully valid url.

                                  https://pdf.pdf/pdf.pdf/pdf.pdf
                                  
                                  1 Reply Last reply
                                  0
                                  • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                    Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                                    And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                                    #DNS #RevealDay #blueTeam #tld

                                    dd0ul@mastodon.radioD This user is from outside of this forum
                                    dd0ul@mastodon.radioD This user is from outside of this forum
                                    dd0ul@mastodon.radio
                                    wrote sidst redigeret af
                                    #54

                                    @badsamurai .exe

                                    1 Reply Last reply
                                    0
                                    • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                      Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

                                      And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

                                      #DNS #RevealDay #blueTeam #tld

                                      lritter@mastodon.gamedev.placeL This user is from outside of this forum
                                      lritter@mastodon.gamedev.placeL This user is from outside of this forum
                                      lritter@mastodon.gamedev.place
                                      wrote sidst redigeret af
                                      #55

                                      @badsamurai DNS was a mistake

                                      1 Reply Last reply
                                      0
                                      • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                                        I missed .lan, .corp and .mail were also submitted. Corp and mail were originally rejected by ICANN in 2012 as thought too dangerous. Somehow 2026 is safer?

                                        .pdf and .php are technically backup choices, but still an absurd submissions. As is .csr and .bin.

                                        The inherent trust words have their own issues: .login .auth .account .admin .official .verified. I don't see how these are anything but a ransom against organizations to preempt squatting.

                                        cblte@nrw.socialC This user is from outside of this forum
                                        cblte@nrw.socialC This user is from outside of this forum
                                        cblte@nrw.social
                                        wrote sidst redigeret af
                                        #56

                                        @badsamurai Maybe we are just getting out of ideas for other creative names? To many tabs

                                        1 Reply Last reply
                                        0
                                        • logaldeveloper@infosec.exchangeL logaldeveloper@infosec.exchange

                                          @ai6yr @Viss @badsamurai my go to IP checker is https://myip.wtf/

                                          autoiue@mastodon.xn--cfa.xyzA This user is from outside of this forum
                                          autoiue@mastodon.xn--cfa.xyzA This user is from outside of this forum
                                          autoiue@mastodon.xn--cfa.xyz
                                          wrote sidst redigeret af
                                          #57

                                          @logaldeveloper @ai6yr @Viss @badsamurai

                                          also on mastodon @wtfismyip 😉

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper