« Killing the beast...Part I | Main | What's behind the "Nine Ball" attacks? »

2009.06.17

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d835018afd53ef01157026707b970c

Listed below are links to weblogs that reference Killing the beast...Part II:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

In the wild js-virus-injector, only use in sandbox!
hxxp://odyrt.net/

Site also used to scan others for php-bugs, a php-sniffer:
http://odyrt.net/info/templates/cmd.txt

maybe not directly, but they are the group responsible for worldwide dns. they get to say who has accreditation or not. you can't register a domain without it. they should be reviewing all the domains that get registered, especially for reason(s) below.

one gripe i have is with the whois hiders, such as domainsbyproxy. these groups have to go away. it's bad enough that domains are registered to obviously fake locations and fake names, that we also have companies that intentionally put useless info into the whois records.

they're not the only types of people omitting proper data on the whois records, i just checked my .ca address and noticed that CIRA withholds everything except it's active/expiry statii.

if you saw that list of domains, would you register them? i wouldn't.

joe,
The domains aren't fake, anymore than fireeye.com is fake. What they are is malicious, or used solely for malicious purposes. There is a process to shut these down, it takes time though, and effort.

I don't think ICANN is directly responsible here, though certainly they could enact some policy that allowed faster action against well known (how to show/prove that?) actors and domains.

i've been saying for years that there needs to be some serious reform over at icann... so many registrars should be losing their accreditation for blindly registering fake domains.

The comments to this entry are closed.