Pretty horrible negligence on the part of .mobi to leave a domain like this to expire.
We spent $20 to achieve RCE and accidentally became the admins of .mobi
291–300 of 391 posts
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#292Earlier quoted context omitted.
I'm wondering, many SaaS offer companyname.mysaas.com. Is that totally secure?
If it's on the PSL it gets treated similarly to second level "TLDs" like co.uk.
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#293Earlier quoted context omitted.
interesting, why is this?
I can think of two reasons: 1. it's immediately clear to users that they're seeing content that doesn't belong to your business but instead belongs to your business's users. maybe less relevant for github, but imagine if someone uploaded something phishing-y and it was visible on a page with a url like google.com/uploads/asdf. 2. if a user uploaded something like an html file, you wouldn't want it to be able to run j…
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#294Obviously there are a lot of errors by a lot of people that led to this, but here's one that would've prevented this specific exploit: > As part of our research, we discovered that a few years ago the WHOIS server for the .MOBI TLD migrated from whois.dotmobiregistry.net to whois.nic.mobi – and the dotmobiregistry.net domain had been left to expire seemingly in December 2023. Never ever ever ever let a domain expire.…
How do mega corps remember to pay their domain bills? Do they pay an (overpriced) registrar for "infinity" years of renewals? This seems like a genuinely hard business operations problem.
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#295Obviously there are a lot of errors by a lot of people that led to this, but here's one that would've prevented this specific exploit: > As part of our research, we discovered that a few years ago the WHOIS server for the .MOBI TLD migrated from whois.dotmobiregistry.net to whois.nic.mobi – and the dotmobiregistry.net domain had been left to expire seemingly in December 2023. Never ever ever ever let a domain expire.…
I like the point you are making in this post. It makes me think about the Backblaze blog posts where they discuss the likelihood of enough drive failures to lose user data. Then, they decided the calculation result hardly matters, because people are more likely to forget to pay due to an expired credit card or email spam filtering (missed renewal reminders!). How do mega corps remember to pay their domain bills? Do t…
Even when companies don't have their own top-level domain, they can have their own domain registrar. For example "facebook.com" is registered with "registrarsafe.com" as registrar. The latter registrar is a wholly owned subsidiary of Facebook. I learned this from this HN thread https://news.ycombinator.com/item?id=28751497
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#296Earlier quoted context omitted.
[flagged]
Do you have any references/examples of this?
rapid7 for example use LLMs to analyze code and identify vulnerabilities such as SQL injection, XSS, and buffer overflows. Their platform can also identify vulnerabilities in third-party libraries and frameworks from what i can see
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#297Earlier quoted context omitted.
Can they? I thought ICANN prevented such steep increases?
Only for a few TLD's, stuff like ccTLD's there's no limit on how much a registry can charge.
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#298Obviously there are a lot of errors by a lot of people that led to this, but here's one that would've prevented this specific exploit: > As part of our research, we discovered that a few years ago the WHOIS server for the .MOBI TLD migrated from whois.dotmobiregistry.net to whois.nic.mobi – and the dotmobiregistry.net domain had been left to expire seemingly in December 2023. Never ever ever ever let a domain expire.…
I like the point you are making in this post. It makes me think about the Backblaze blog posts where they discuss the likelihood of enough drive failures to lose user data. Then, they decided the calculation result hardly matters, because people are more likely to forget to pay due to an expired credit card or email spam filtering (missed renewal reminders!). How do mega corps remember to pay their domain bills? Do t…
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#299Earlier quoted context omitted.
I think it's a sane practice to keep the marketing landing page on a separate domain than the product in case of SaaS.
Why? I always get frustrated when I end up in some parallel universe of a website (like support or marketing) and I can't easily click back to the main site.
Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi
#300Earlier quoted context omitted.
Yes, port it to Google voice.
I think that costs $20.
Though AFAIK there's no law or contract term preventing Google from starting to charge a monthly fee in the future.
And after some time — for me it was 5+ years, porting from a baby Bell land line to a postpaid T-Mobile family plan for a couple years and then to Google Voice — your number will be tarred and feathered as a "VoIP" number and rejected for identity verification by some parties until it's ported back to a paid service (again, after some time).
Even so, it's nice that Google lets me keep the number I was born with for $0/month for as long as it lasts.