9 ms·
Indeed. I've owned `invaliddomain.com` for almost 20 years. You'll be surprised how many use it for testing. One morning I woke up to 30,000 e-mails from Sony J
by davemtl 6y ago
Indeed. I've owned `invaliddomain.com` for almost 20 years. You'll be surprised how many use it for testing. One morning I woke up to 30,000 e-mails from Sony Japan with PDFs attached of scanned hand-written part orders. Something similar with Boeing sending me backup notifications. I notified each of these companies about their configuration through their official channels, only to be told "no, it's your server doing this" then usually followed up with an e-mail a few weeks later along the lines of "sorry, our bad". So, if you're testing something and using a test domain, use the IANA reserved domains, please. Theses were the days when I was running my own servers. I don't see it as often now as my e-mail is now hosted.
- chrismeller 6y agoHaha. That’s actually surprising, I mean that one takes some work to even type. I’ve mentioned previously on HN that I own doesnthaveone.com, which is constantly bombarded with random crap. I wish I had some big public customer data to see what other fake ones show up.
- CydeWeys 6y ago.app, .dev, .prod, and .zip all had substantial volume of problematic traffic that was discovered during the Controlled Interruption period (which occurs prior to launch and consists of a wildcard DNS entry placed on the entire TLD). You would not believe some of the brokenness that was happening there. .zip may need some explanation -- apparently there are lots of library API calls out there that take a path string as input and try to load it as either a local or remote file. You can see where this is going. https://www.icann.org/en/system/files/files/name-collision-framework-30jul14-en.pdf https://www.icann.org/en/system/files/files/name-collision-f...
- monadic2 6y agoRuby's `open` accepts urls. I can't say I've ever used this functionality.
- dogma1138 6y agoAsk your red team about that ;)
- diamondo25 6y agoPHP's file_get_contents supports it as well.
- cyberbanjo 6y agoClojure a slurp too.. never been bitten, I thought it was useful.
- ben0x539 6y agoI've only ever used it for that! For files there's `File.open`! ;)
- abiogenesis 6y agoI don't know Ruby enough to comment on that but I would guess it requires a scheme as well.
- giantrobot 6y agoI've personally run into the .zip problem thanks to browser's omni address/search/chocolate bars. I intend to search for a zip file whose name I know but the browser "helpfully" realizes the term includes no spaces and ends in dotsomething and attempts to treat it as a URL. A simple workaround is to add a preceding space or something like inurl: but that's isn't an automatic behavior so whoever owns mlpdwarfporn.zip is getting a lot of unintentional hits.
- jdxcode 6y agoif we could go back I wonder if it would be better if we had required a leading dot in domain names ".google.com"
- giantrobot 6y agoI think that ends up as user unfriendly as requiring the dot after the TLD. I don't read up on all the gTLDs so I didn't realize zip was one for the longest time. I think ICANN just went nuts with TLDs, especially ones like .app and .zip that have long-standing associations with ubiquitous file extensions. That combined with the "smart bar" just leads to trouble.
- Ekaros 6y agoOr if browsers weren't trying to be too smart enough and use the same box for both searching and addresses. Trips me with .py files all time time.
- BiteCode_dev 6y agoAfter ".py", use " ?" (the space is important) to force the search in firefox.
- oauea 6y agoOr just start the query with `?` Typing `?bla.py` in the omnibar will perform a search for `bla.py` on both Firefox and Chrome
- captn3m0 6y agoICANN should never have assigned .zip, there's just too much potential for abuse, confusion giving away a common extension as a TLD.
- jedberg 6y agoBut it made them so much money!!
- CydeWeys 6y agoThere's a lot of overlap between file extensions and TLDs though. .py, .sh, and .app are some more examples (but a fully exhaustive list would be in the dozens if not hundreds). At some point you have to just treat them as the separate namespaces that they actually are (and not somehow try to block a TLD from being used as a file extension, or vice-versa). Besides, accidentally resolving a file extension to a TLD is only one of many possible different serious errors that can result from exposing an API that can load files locally or remotely, and thus make network calls that you might not be expecting. Fundamentally you need to fix that API either way.
- schwartzworld 6y agonot to mention .com
- CydeWeys 6y agoGeez, that's by far the best example and it didn't even occur to me. And it's an executable file type. Good call.
- johnzim 6y agoWe just never should have allowed filename extensions to have semantic power. Resource forks are far more elegant and you could do simple look ahead checks to verify types etc.
- bigiain 6y ago
- miki123211 6y agoMy college's online system for everything is called edukacja.cl. A lot of people type that into the address bar, expecting to be redirected to the login page. Fortunately, the person who bought that domain didn't misuse it. I can imagine someone putting a fake login page there, and getting access to a lot of sensitive student details.
- FlingPoo 6y agoI registered non-existent-domain.com many years ago when I saw it referenced in some article as a place-holder domain name.
- Wistar 6y agoI owned forexample.com for 15 years or so and saw all kinds of mail but the most persistent was a record company owner who, from time-to-time, wrote semi-deranged angry emails demanding that I turn the domain over to him. I always had grand plans for the domain but never acted and, a couple years ago, I forgot to renew and the domain is now in someone else's hands. I don't miss it, especially the record company guy.
- nullsense 6y agoI wish there were a site that all this stuff could be posted so we can all share in the fun. Always entertaining hearing about this stuff.
- m463 6y agohttps://thedailywtf.com/ https://thedailywtf.com/ is pretty close When I read reddit (before it jumped the shark imo) there was something similar in a non-tech way called /r/idontworkherelady
- nullsense 6y agoI've run out of funnies to find in the codebase I work on. This looks like a fresh supply of much much more. Much appreciated.
- Jon_Lowtek 6y ago> "no, it's your server doing this" at that point i expected the story to go "and then they sued me for stealing their documents"
- xmprt 6y agoHe orchestrated a man in the middle attack by being in the middle of the engineers and their incompetence.
- tus88 6y agoWhy would you tell them and bring an end to the lolz?
- colejohnson66 6y agoBecause, technically, opening those emails when they contain confidential information could be construed as a violation of the CFAA (it’s very broad).
- bigiain 6y agoIndeed it's probably broad enough that you could likely find an ambulance chaser who'd go after people who _send_ you those emails "in excess of their authorized access" to your mail server. You could weaponise this the same way companies use defensive patents... "Sure, I opened one of your emails, but you've connected to my mail server without authorisation <checks logs> 27,943 time so far this month. Go on, lawyer up. Bring it on!"
- tus88 6y agoThis.
- BerislavLopac 6y agoI remember reading - long time ago - a story of a developer who used http://xxx http://xxx as a placeholder for unknown domains, until at some point the browsers started resolved single-word links into www.<word>.com... :-o
- bigiain 6y agoBack in the days before I'd ever heard of multicast DNS or zeroconf networking, I had a local dns server set up with all our subdomain.ourdomain.com duplicated as subdomain.ourdomain.local and pointing to our local dev/staging versions of our websites. It worked wonderfully, until I think MacOS 10.2 arrived (so, like 20 years ago almost) which had mDNS support for the first time and "broke" it all on me... I switched to using subdomain.ourdomain.staging instead and got on with life. I wonder if anyone's gonna have to deal with the fallout of that decision when someone oneway pays ICANN enough money to own the .staging TLD? (I wonder how much "interesting" stuff would land in your mail/web/ssh/whatever log files, if you registered .staging and .dev and just logged everything that came past (or intentionally/actively honey potted everything there?)
- marcthe12 6y agoUse Lan. Reserved so no issues
- xmprt 6y agoI was about 5 seconds away from clicking this link on my work laptop until I realized what it would redirect to. For others like me, it's very NSFW
- BerislavLopac 6y agoIt doesn't seem that the browsers still to the expansion things; I've tried it, and am just getting the "We’re having trouble finding that site." error message, or similar. But for some time that expansion was real.
- anonytrary 6y agoOn the other hand, you knew what you were getting into when you decided to be the owner of a meme domain! People should use properly reserved domains, but I can't really blame them for accidentally using meme domains.
- retox 6y agoI had my.homepage.com for a while back in the early 2000s, unfortunately I wasn't allowed to monetize it, but looking at the referral logs was always interesting.