bar.com seems inaccessible. Can someone who saw the site in the past few hours confirm that http://web.archive.org/web/20110707211652/http://bar.com/ is up to date?
foo@bar.com is a real email address
91–98 of 98 posts
Re: foo@bar.com is a real email address
#92Re: foo@bar.com is a real email address
#93Re: foo@bar.com is a real email address
#94Re: foo@bar.com is a real email address
#95Re: foo@bar.com is a real email address
#96Earlier quoted context omitted.
the guy who owns test.com emailed me once because I wrote a paper on IIS vulnerabilities and had 'test.com' as example URL's. turns out a lot of people reading my paper would copy+paste the example exploits and own the test.com server (which just happen to be running IIS).
Man, this is really beautiful. Care to share more details? (I suppose all exploits are long patched now). It could be an interesting blog post...
http://web.archive.org/web/20040210183242/http://black.wiret...
that server.com server was hilarious. it ended up becoming a mini-BBS with people posting funny messages, file names etc. to it. When I went to check it out to see what was going on, I ran a dir on the c drive, and there were almost 500 funny folder and file names there, with 'X WAS HERE' etc.
someone then put out a URL on IRC which would fire up a reverse shell. and that server.com server ended up running gaming servers, porn ftp sites, warez, the works. the guy emailed me around 2-3 months later asking for help to patch the box because it kept getting owned.
fun fact: I wrote a scanner in C back then that would check for these vulnerabilities. The scanner had two 0day vulnerabilities that weren't in this paper. one night at a friends house we were playing around with NXFR transfers from DNS servers (this is back when you could do them and before people figured out to lock this down). we started downloading lists of all the domain names from various TLD's. for eg we had .net, .org, .com etc. then we started downloading various countries, for eg. .at, .co,
we were talking to each other about what to do with them, and he said 'lets run one of these through your scanner'. so I made a quick change that would check the Server banner returned, and if it was IIS, it would then try these different exploits and run a command. we couldn't work out which command we wanted to run, so I had the idea of just creating a file called 'heh.txt' in C. I set it all up and ran it against all the Austrian domains. within a few seconds it was obvious that it was working too well - because it was churning through 5-10 hosts per second and a lot of them were 'SUCCESS'. I left it running, no idea when it finished, but when I picked it back up again the next day around 40% or servers (may have been more) were running IIS and of those, around 98% had our 'heh' command run successfully.
tl;dr hacked ~40% of all servers in austria. if you ever found a file called 'heh.txt' in the root of your C drive, that was me.
Re: foo@bar.com is a real email address
#97Earlier quoted context omitted.
The "+" trick is great, except for sites that use hair-brained email "validation" scripts which reject the address. Sadly enough, these are often the ones that I most want to use the "+" for (its a great way to also keep track of who hands out your email address to spammers).
I have the solution for you there: If your email is mylittlepony@gmail.com Then your can use as many '.' and filter it out. You will also receive emails sendt too my.little.pony@gmail.com M.y.l.i.t.t.l.e.p.o.n.y@gmail.com Gmail ignores punktum. Thats smart!
Re: foo@bar.com is a real email address
#98We get a lot of crap email address signups at http://feefighters.com We do a little bit of filtering to check that the email address is legit, but let you get by anyway (with an additional click) if it isn't... we have a 1-click unsubscribe but this is making me rethink whether we should let fake email addresses through at all. We recently got this email from Fake.com Hello We own the domain fake.com, and from time t…
How do you tell fake from real?
What if someone who works at fake.com wants an account?