Live data from Hacker News

Is it an accident? No, it's a wildcard subdomain

ebay.c.uk

1–10 of 49 posts

Re: Is it an accident? No, it's a wildcard subdomain

#2
I think this is a good demo to share with family and am glad this organization has c.uk.

Another more general example to share with family is:

http://www2.scotiaonline.scotiabank.com.online.authenticatio...

These are both cases where the subdomain can trick people. The .c.uk one is a bit more dangerous as they claim a lot of people end up landing on those pages. I had a quick look through some other second level domains to see if anyone else had a site like this.

The more details on two level domains here: http://en.wikipedia.org/wiki/Second-level_domain

Re: Is it an accident? No, it's a wildcard subdomain

#4
post #3

Interesting that they would allow such an odd domain to be registered in the first place. It seems like a big security hole.

Why is that interesting? c.uk is a registered domain, the WHOIS for subdomains correctly states that it can't be registered.

Re: Is it an accident? No, it's a wildcard subdomain

#7
post #3

Interesting that they would allow such an odd domain to be registered in the first place. It seems like a big security hole.

Why is that interesting? c.uk is a registered domain, the WHOIS for subdomains correctly states that it can't be registered.

> Why is that interesting?

Because I found it interesting.

Re: Is it an accident? No, it's a wildcard subdomain

#9

I didn't know single letter domains were allowed? For example none of a.com, b.com, c.com etc. work - do other gTLD allow single letter domains then?

https://t.co/ is very well known. Probably the most used single-character domain in existence :)

Unrelated, but I've never understood why t.co counts against your tweet length.. for example, if you tweeted "ebay.c.uk", it would count for length(http://t.co/xxxxxxxxxx) characters (15 characters even though you only typed 9).

Re: Is it an accident? No, it's a wildcard subdomain

#10
post #3

Interesting that they would allow such an odd domain to be registered in the first place. It seems like a big security hole.

You're missing something here. The UK is a country that allows second-level domains e.g., co.uk, gov.uk, org.uk as well as just domains ending in .uk.

This organizations owns c.uk (so the who-is you should lookup is just c.uk.

What I find hard to believe is that ti looks like it was registered on: 10-Jun-2014!?

Post reply on HN