3 ms·
See my response below and the logs were secure removed shortly after (as stated in the blog post).
by mandatory 10y ago
See my response below and the logs were secure removed shortly after (as stated in the blog post).
- xuki 10y agoNot that I don't believe you, but you already lost white hat status in this case the moment you log traffic on 20k domains. Just do an attack on another domain you own is white hat, 20k domains is not.
- mandatory 10y agoYou're probably right about the logging being a bit too far, it was mainly my curiosity getting the best of me. One of my big assumptions was that all of these domains were just owned by one domain broker and this wasn't actually a systemic problem with the implemented importation methodology. I also thought it would be mild because if they had been deleted from an account they were likely no longer used (or so I had wrongfully assumed).
- IanCal 10y agoI certainly don't attribute malice on your part, and I'm sorry if my comment came across this way. My point was (at least intended to be) that I'm not really surprised at DO banning you. I would be careful about doing something like this on a large scale, I would actually be surprised if this doesn't technically violate some laws. Please be careful, you don't want to end up trying to explain nameservers to a judge. [edit - and the rest of us don't want that either, even just selfishly I would like as many security researchers practicing their craft as possible, but also I don't want people being punished for trying to do the right thing]