Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Suddenly "www.com"'s value has skyrocketed in the eyes of scammers. How about:

* login.<target_site>.www.com -> login.<target_site>.com

* members.<target_site>.www.com -> members.<target_site>.com

Even some carefully chosen <target_site>.www.com's will now be valuable:

* login.www.<target_site>.www.com -> login.<target_site>.com

What a stupid idea...



That's just a bug which I'm sure will be fixed in the next release.

For this to actually help scammers (after the bug is fixed) they'd need to own www.example.com but not example.com, which is unlikely to say the least.


Yes, it is a bug, but until it's fixed it's a potential attack vector.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: