It pisses me off that for something of this magnitude this guy will probably only be paid no more than a couple thousand dollars, if at all. He still has no response.
How I hijacked the top-level domain of a sovereign state
51–60 of 65 posts
Re: How I hijacked the top-level domain of a sovereign state
#52Earlier quoted context omitted.
The guy has no reason to expect a reward if the city has no bug bounty program. They could just sue him.
sue him for what? Discovering an exploit without disclosing the details?
Re: How I hijacked the top-level domain of a sovereign state
#53I had a gut feeling it will be '.cd' before clicking on the article and I was right. Dealing with the state entity (SCPT) that manages this TLD is quite a pain. It's so painful that I've given up managing all the .cd domains I used to own. .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously.
Re: How I hijacked the top-level domain of a sovereign state
#54> Although one of the contacts replied and delegated to their colleague, as of this writing, I haven’t received any follow-up confirmation that they fixed the issue. Wonder if that means they're investigating a "legal response" to his report? eg the old "shoot the messenger" approach :/
Re: How I hijacked the top-level domain of a sovereign state
#55Earlier quoted context omitted.
Quoting the article: >On January 7th, I reached out to the Administrative and Technical contacts listed for .cd on [ https://www.iana.org/domains/root/db/cd.html ].
A week after he registered the domain name. That's not the same thing as "before," which I believe the top comment in this thread was implying about what he should have done instead of what he did do.
Seems odd to wait a week to make contact if this was purely a white-hat exercise.
Re: How I hijacked the top-level domain of a sovereign state
#56Earlier quoted context omitted.
> .cd domains are also some of the most expensive to get. Hopefully the new government will take this seriously. I bought one a few years ago for 80 Euros / year. Aren't there a lot of TLDs that are way more expensive?
The new crop of TLDs are really cheap. I bought a .download for like $2 a year or something. Not all are that cheap (I bought it as a throwaway for a project that relied on my having DNS control) but there are literally hundreds of them that are.
Re: How I hijacked the top-level domain of a sovereign state
#57The most ethical move would have been to write to people listed at https://www.iana.org/domains/root/db/cd.html and put IANA in copy (likely ROOT-MGMT@IANA.ORG as listed in the public document: 24x7 Emergency Process Step-by-Step Description).
I feel it's problematic that whenever someone writes about an ethically tricky security vulnerability disclosure someone will come up with some variant of "but doing it a bit differently would've been more ethical". The reason I think this is problematic is that there are already more than enough people in the security community who will either say "fuck it, I'm not gonna bother with that" or "let's sell it to the hi…
Re: How I hijacked the top-level domain of a sovereign state
#58Earlier quoted context omitted.
sue him for what? Discovering an exploit without disclosing the details?
It depends on the country, but in France for instance, there is a maximum sentence of one year in prison and a 15000€ fine just for "fraudulently accessing a data processing system", or trying to do so even if you don't succeed.
Re: How I hijacked the top-level domain of a sovereign state
#59Earlier quoted context omitted.
Kiribati (.ki) comes to mind - 900€ per year via ghandi.net or 1350€ at eurodns...
According to tld-list.com, the .th TLD is the most expensive ccTLD at $5000 and .ru is the cheapest at $2.99
Re: How I hijacked the top-level domain of a sovereign state
#60Earlier quoted context omitted.
I feel it's problematic that whenever someone writes about an ethically tricky security vulnerability disclosure someone will come up with some variant of "but doing it a bit differently would've been more ethical". The reason I think this is problematic is that there are already more than enough people in the security community who will either say "fuck it, I'm not gonna bother with that" or "let's sell it to the hi…
I think this situation is like knowing a car crash is about to happen and then still waiting for it to happen though. Why not email someone to pay their bill?