4 ms·
I got tired of editing my host file for local development. Have been meaning to do this for a while, but I never had a domain name short enough so as not to be
by jtolj 12y ago
I got tired of editing my host file for local development. Have been meaning to do this for a while, but I never had a domain name short enough so as not to be annoying to type.
- hydrogen18 12y agoThis is brilliant. Just wait till lots of people are using this, load up a ton of patched software for every known protocol to record usernames and passwords on a machine. Then you can just intermittently have the domain resolve to that machine and collect the usernames and passwords. It'll be difficult to detect because it won't even be reproducible.
- jtolj 12y agoNot following how this might present a security issue, but I'm curious for you to expand on this. Seems like even if the DNS record managed to change in the midst of a POST request, the post would pretty obviously fail to perform as expected. But yes, an obvious disclaimer of "don't trust me by POSTing your bank passwords to any of these subdomains" might be in order.
- thedufer 12y agoYou can trivially farm data that people are sending to their local apps by having DNS occasionally change to an IP you own (and then immediately back, to avoid detection). On that IP, you would have something that remembers the parts of the request that might be interesting (query parameters, body) and return a benign-looking error (just severing the connection without a response would probably do it). At the very least, you'd probably get some email/pass pairs that work on a few major sites.
- extc 12y agoFrom your browser's perspective, the POST would fail, if it expected a certain response. That would happen after the site already recorded the contents of your POST.