Dynadot — .com Transfer

Flaw in DNS

SpaceshipSpaceship
Watch

Delete

Account Suspended
Impact
0
I saw this on DNF and thought it was really funny. The gus says I hate google so I hacked them check out the site http://www.google.com (Google didn't really get hacked) You can mask any domain lol. I think I will do one for Yahoo!
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
Unstoppable Domains — AI StorefrontUnstoppable Domains — AI Storefront
thats good ..lol
 
0
•••
How do you do that?
 
0
•••
That's not really the best thing ever... In fact, it's an Internet Explorer security bug discovered some days ago.

Check out the URL: http://www.google.com%00@google-sucks.org. Did you see it? That is like accessing the google-sucks.org domain with the www.google.com username (that's like FTP, you have ftp://username:[email protected]/folder/) but, thanks to the mentioned bug (well, simply add that special symbol before the @), Internet Explorer doesn't see it right and only shows www.google.com.

That can be really a serious problem (think of PayPal scam mails with links made so...), that is why Microsoft has already been informed; they hopefully will fix this in a short time.
 
Last edited:
0
•••
Thats actually really cool how that works. I wonder who thought of that
 
0
•••
pretty cool! I can think of a lot of uses for that.
 
0
•••
Not cool at all, as this could be exploited for fraudulent activities. :(
 
0
•••
Indeed. Unlike those trusty 419'ers...lol

I think it's more of a "visual" floor than anything else.

Matt
 
0
•••
Originally posted by armstrong
Not cool at all, as this could be exploited for fraudulent activities. :(

SECOND THAT.
 
0
•••
Originally posted by Whisper
That's not really the best thing ever... In fact, it's an Internet Explorer security bug discovered some days ago.

Check out the URL: http://www.google.com%00@google-sucks.org. Did you see it? That is like accessing the google-sucks.org domain with the www.google.com username (that's like FTP, you have ftp://username:[email protected]/folder/) but, thanks to the mentioned bug (well, simply add that special symbol before the @), Internet Explorer doesn't see it right and only shows www.google.com.

That can be really a serious problem (think of PayPal scam mails with links made so...), that is why Microsoft has already been informed; they hopefully will fix this in a short time.

I don't know -- it didn't work when I tried it. If it works on other domains, then it can be very very bad. Another M$ bug :(
 
0
•••
It does work on any domain. There's just something slightly off wrong with Whisper's coding.
 
0
•••
Originally posted by armstrong
It does work on any domain. There's just something slightly off wrong with Whisper's coding.

I guess that's a good thing, although I assume the actual coding isn't too difficult to figure out... :|
 
0
•••
Delete has it right in his link. There's no use hiding this info, as its too easy and too exploitable. Be very wary about clicking links on emails and websites you don't trust.

The flaw doesn't work as well in Netscape, which displays the real url (complete with the additional characters), but it still forwards to the fake domain. In IE, none of the extra characters display at all.
 
0
•••
Originally posted by armstrong
Delete has it right in his link. There's no use hiding this info, as its too easy and too exploitable. Be very wary about clicking links on emails and websites you don't trust.

The flaw doesn't work as well in Netscape, which displays the real url (complete with the additional characters), but it still forwards to the fake domain. In IE, none of the extra characters display at all.

Good advice, as always, Armstrong. I am still having fun with this at my friends expense, all in good fun of course. :laugh:
 
0
•••
Dynadot — .com TransferDynadot — .com Transfer
Appraise.net

We're social

Spaceship
Domain Recover
CatchDoms
DomainEasy — Zero Commission
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back