[dns-operations] Web Proxy Auto-Discovery (WPAD) Information Disclosure

Rickard Dahlstrand rickard.dahlstrand at iis.se
Tue Dec 4 18:15:24 UTC 2007


Duane Wessels wrote:
> On Tue, 4 Dec 2007, Rickard Dahlstrand said:
>
>   
>> Most of the wpad.tld domains are already reserved like this one
>> http://wpad.com/ It's amazing that when they fixed it for .com etc. a
>> while back they missed that there where two-level tld-domains.
>>     
>
> I wouldnt say that they fixed it for .com, or probably ever will.
> I'm the lucky holder of wpad.{com,net,org,biz,us}.  You can see the
> number of 404's that I've served over the years at
> http://www.wpad.com/data/requests.png
>   
Amazing, I didn't realize that. A while back I looked thru some of our
traffic from our se-nameservers and found no traces of wpad.se queries
thought. But this is really hard proof!

Anyway, is the wpad.* an issue, are there any domains left for 'evil
doers' to use?

Rickard.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20071204/8099535a/attachment.html>


More information about the dns-operations mailing list