Using Example Domain Names in Exploits

From: bandreggat_private
Date: Mon Jan 25 1999 - 13:25:40 PST

  • Next message: Wietse Venema: "Repost: Wietse's FTP site has moved"

    On Sun, 24 Jan 1999 20:23:40 -0500, "Tabor J. Wells" wrote:
    >On Fri, Jan 22, 1999 at 08:58:33PM -0000,
    >mnemonix <mnemonixat_private> is thought to have said:
    >
    >> In all versions of IIS, where a  website has been configured to interpret
    >> perl scripts using the perl executable (perl.exe), a problem exists where a
    >> request for a non-existent file will return the physical location on a disk
    >> of a web directory. A request for:
    >>
    >> http://www.server.com/scripts/no-such-file.pl
    >
    >I really wish people wouldn't do this. www.server.com is a legitimate
    >site (it's hosted on my network) and they certainly don't run IIS.
    
    The domains example.com, example.org, and example.net have all been reserved
    by IANA and NIC for just this purpose. Use them.
    --
                    Bryan C. Andregg * <bandreggat_private> * Red Hat Software
    
        "Gee, I'm glad you're around to tell me the almighty-truth[tm]."
                            -- Patrick J. Volkerding
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:30:52 PDT