Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mandatory
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
mandatory
9y ago
Author here, thanks - glad you liked the post! :)
62.
▲
by
mandatory
9y ago
I'm in love with this, I have nothing constructive to add but you should be really proud of this work. Reminded me of this video: https://www.youtube.com/watch?v=8pTEmbeENF4 Think you're on to something that this
63.
▲
Russian DNS Leak (All .ru, .su, .tatar, .рф, and .дети Domains)
(github.com)
5 points
by
mandatory
9y ago
|
0 comments
64.
▲
The Journey to Hijacking a Country's DNS – The Hidden Risks of Domain Extensions
(thehackerblog.com)
2 points
by
mandatory
9y ago
|
0 comments
65.
▲
Hacking Guatemala’s DNS – Spying on Active Directory Users via a TLD Misconfig
(thehackerblog.com)
3 points
by
mandatory
10y ago
|
0 comments
66.
▲
TLDR Beta – View DNS Zone Data Dumps for Countries and Other TLDs
(tldrproject.thehackerblog.com)
1 points
by
mandatory
10y ago
|
0 comments
67.
▲
by
mandatory
10y ago
Of course. I'm a bit confused on this emphasis... Does the post make it seem as though you can take over an active site? The point of this attack is merely to take control of many domain names and doesn't make any point about taki
68.
▲
by
mandatory
10y ago
You wouldn't really need to "forge" SSL certificates, since you have control of the domain's DNS you can just request a long-term certificate and use DNS/HTTP as a validation method. Many/most CA's support
69.
▲
by
mandatory
10y ago
Author here, you do have a point, that distinction should have been made. This is merely taking control over the DNS for a domain and doesn't speak to actual ownership of the domain at the registry (which would be "ground truth&qu
70.
▲
The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability
(thehackerblog.com)
117 points
by
mandatory
10y ago
|
28 comments
71.
▲
MITMing Yahoo Mail with a Wifi Pineapple Mark V and Flash
(github.com)
1 points
by
mandatory
10y ago
|
0 comments
72.
▲
Snapshot of North Korea’s DNS data taken from zone transfers
(github.com)
213 points
by
mandatory
10y ago
|
95 comments
73.
▲
Breaching a CA – Blind XSS in the GeoTrust SSL Operations Panel Using XSS Hunter
(thehackerblog.com)
1 points
by
mandatory
10y ago
|
0 comments
74.
▲
by
mandatory
10y ago
Hey Jarland thanks for the thoughtful response. I don't think your actions were rude or inappropriate (what host would see this behavior and not act similarly?). I apologize that the discussion on the topic became so negative towards D
75.
▲
by
mandatory
10y ago
What was his/her flagged follow up if you don't mind me asking?
76.
▲
by
mandatory
10y ago
I believe I was clear about it. However sometimes my writing can be unclear so perhaps it wasn't properly understood (I assume you're talking about their security team's response and not Trust & Safety?). Kind of sad abou
77.
▲
by
mandatory
10y ago
You're probably right about the logging being a bit too far, it was mainly my curiosity getting the best of me. One of my big assumptions was that all of these domains were just owned by one domain broker and this wasn't actually
78.
▲
by
mandatory
10y ago
See my response below and the logs were secure removed shortly after (as stated in the blog post).
79.
▲
by
mandatory
10y ago
Fair point, my relucatance to stop was mainly due to companies usually disreguarding reports unless I have strong proof. Stopping short of the full scope would've left it up to speculation as to the full amount of vulnerable domains. I
80.
▲
TLDR – A Continuously Updated Historical TLD and Root Records Archive
(github.com)
1 points
by
mandatory
10y ago
|
0 comments
81.
▲
JetBrains IDE Remote Code Execution and Local File Disclosure
(blog.saynotolinux.com)
145 points
by
mandatory
10y ago
|
33 comments
82.
▲
Obtaining Arbitrary Wildcard SSL Certs from Comodo via Dangling Markup Injection
(thehackerblog.com)
2 points
by
mandatory
10y ago
|
0 comments
83.
▲
by
mandatory
10y ago
It also isn't secure as a few of us have noted, since it suffers from a Cross-site Scripting (XSS) vulnerability: https://github.com/TailorDev/monod/issues/122
84.
▲
The “Unhackable” WordPress Blog – Finding Security in the Static
(thehackerblog.com)
1 points
by
mandatory
11y ago
|
0 comments
85.
▲
Live view of orphaned domains pointed to release AWS IPs
(thehackerblog.com)
1 points
by
mandatory
11y ago
|
0 comments
86.
▲
Fishing the AWS IP Pool for Dangling Domains
(bishopfox.com)
7 points
by
mandatory
11y ago
|
0 comments
87.
▲
Dirty Browser Enumeration Tricks – Using Chrome:// to Identify Firefox Plugins
(thehackerblog.com)
5 points
by
mandatory
12y ago
|
1 comments
88.
▲
The Rickmote Controller: Hacking One Chromecast at a Time
(bishopfox.com)
1 points
by
mandatory
12y ago
|
0 comments
89.
▲
by
mandatory
12y ago
Right, didn't mean that in the original post - obviously this is how the function is designed to work. Fixed up the wording to clarify.
90.
▲
by
mandatory
13y ago
"Generating 5000 fake accounts falls into the script kiddie level of originality." Wasn't really trying to be very "leet" with this hack, was just something fun I decided to do. Also deleting the accounts wouldn
More ›