Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
badsamurai@infosec.exchangeB

badsamurai@infosec.exchange

@badsamurai@infosec.exchange
About
Indlæg
9
Emner
1
Fremhævelser
0
Grupper
0
Følgere
0
Følger
0

Vis Original

Indlæg

Seneste Bedste Controversial

  • i have lived here my whole life, and i have never once seen a plane take off from the Willamette…
    badsamurai@infosec.exchangeB badsamurai@infosec.exchange

    @cabel Seems illegal, but Willamette is a navigable waterway and allowed under OAR. And “flying under” bridges has a loophole for take off. 😬

    But def a choice. That’s some AK bush pilot shenanigans.

    Ikke-kategoriseret

  • Happy #ICANN Reveal Fresh Hell Day!
    badsamurai@infosec.exchangeB badsamurai@infosec.exchange

    @Albi Oh def, I already blocked .gram on principle. The problem is when they target your customers, partners and supply chains outside of your network. This is commonly observed with recruiting related domains like {brand}jobs and {brand}careers. The domains remain parked, but they’ll have active MX records and never send to your org specifically.

    Then your average user or small business doesn’t have the skill or tooling to configure firewalls, NextDNS, etc. I take security by design to not just be memory safe computing, but holistic prevention at conceptual birth.

    Ikke-kategoriseret icann dns revealday blueteam tld

  • Happy #ICANN Reveal Fresh Hell Day!
    badsamurai@infosec.exchangeB badsamurai@infosec.exchange

    @darkuncle @rl_dane Wait until the infosec $vendors stay mum through the entire process. Stopping pre-crime doesn’t exactly increase shareholder value.

    Ikke-kategoriseret icann dns revealday blueteam tld

  • Happy #ICANN Reveal Fresh Hell Day!
    badsamurai@infosec.exchangeB badsamurai@infosec.exchange

    The applicant list in case y’all want in on the and find something I’ve missed.

    https://newgtldprogram-aps.icann.org/applications

    Ikke-kategoriseret icann dns revealday blueteam tld

  • Happy #ICANN Reveal Fresh Hell Day!
    badsamurai@infosec.exchangeB badsamurai@infosec.exchange

    I missed .lan, .corp and .mail were also submitted. Corp and mail were originally rejected by ICANN in 2012 as thought too dangerous. Somehow 2026 is safer?

    .pdf and .php are technically backup choices, but still an absurd submissions. As is .csr and .bin.

    The inherent trust words have their own issues: .login .auth .account .admin .official .verified. I don't see how these are anything but a ransom against organizations to preempt squatting.

    Ikke-kategoriseret icann dns revealday blueteam tld

  • Happy #ICANN Reveal Fresh Hell Day!
    badsamurai@infosec.exchangeB badsamurai@infosec.exchange

    @Mustardfacial I am not at all worried typo squatting on .fart

    And some solid future fedi server TLDs! .furry .meow .uwu .slay .neko

    Ikke-kategoriseret icann dns revealday blueteam tld

  • Happy #ICANN Reveal Fresh Hell Day!
    badsamurai@infosec.exchangeB badsamurai@infosec.exchange

    @svavar @pberry

    Correct, .md is a ccTLD that's been around longer than markdown. But this is 2026 and these domains have an extremely high likelihood for abuse in phishing, clickfix, and supply chain attacks. ICANN allowing these would be irresponsible.

    Once these are approved, there will be no oversight. .duo was applied for by ShortDot, a notorious bulletproof operator known for some of the most abused TLDs on the internet today: .bond .sbs .icu and .cyou

    Ikke-kategoriseret icann dns revealday blueteam tld

  • Happy #ICANN Reveal Fresh Hell Day!
    badsamurai@infosec.exchangeB badsamurai@infosec.exchange

    @mttaggart But no one was really paying attention when CRR (Google) acquired .zip and .mov in 2013.

    This round we're going to file those objections (string confusion).

    No filenames, no intranet names, no assumed trust names.

    So I hope these orgs enjoyed their $227,000 donation to ICANN.

    https://newgtlds.icann.org/en/program-status/odr#objection-dispute-resolution

    Ikke-kategoriseret icann dns revealday blueteam tld

  • Happy #ICANN Reveal Fresh Hell Day!
    badsamurai@infosec.exchangeB badsamurai@infosec.exchange

    Happy #ICANN Reveal Fresh Hell Day! A company in the Caymans would like the TLD .pdf

    And these other spectacular submissions that surely won't end poorly: .sys .key .duo .lab .private .state .auth .conf .config .loc .log .php .url .vpn

    #DNS #RevealDay #blueTeam #tld

    Ikke-kategoriseret icann dns revealday blueteam tld
  • Log ind

  • Login or register to search.
Powered by NodeBB Contributors
Graciously hosted by data.coop
  • First post
    Last post
0
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper