Membership is FREE – with unlimited access to all features, tools, and discussions. Premium accounts get benefits like banner ads and newsletter exposure. ✅ Signature links are now free for all. 🚫 No AI-generated (LLM) posts allowed. Share your own thoughts and experience — accounts may be terminated for violations.

New Nominet drop catching flaw exposed

Status
Not open for further replies.

Hay

Joined
Jul 13, 2019
Posts
370
Reaction score
213
On 20/09/2020 i contacted Nominet via email to report a flaw being used by "multiple" people to catch domains...

it would appear certain people are not just "Abusing" the flaw but "Abusing" it to the extent that is causing large amounts of traffic on nominets network in a way that its not designed to handle and for that reason im going to expose the flaw so nominet fix the issue as quickly as possible and put a stop to the greedy bastard(s) that want to play hard ball!
 
Last edited:
Yeah they might be pissed off with me for exposing it but they will thank me in the long run for all the traffic and abuse they save :)

Those individual(s) im talking about know who they are and they are fully aware i know who they are.

I've also found code belonging to these individual(s) in an unprotected repository which contains TAGS, Usernames and Passwords which can be sent to Nom along with the screenshots...
 
Last edited:
I hope Nominet change it to where you just buy batches of EPP and all domains are dropped at the same time which will render flaws and multi taggers useless
 
Last edited:
Bring it up in the annual general meeting (or whatever they call their pat on the back tea party) tomorrow?
 
@ian - What so everyone else can take the piss before they patch it?
 
Last edited:
I meant more so they don't sweep it under the carpet as usual. If you tell the board in front of members, it will be minuted, logged, and will need them to deliver action. I get what you are saying about not wishing others to use it though, wasn't thinking about it that way.
 
So has this been happening with latest ror

I did notice that some premium domains had been caught by past active members

Very interesting
 
For the record... Anyone that thinks im talking about "Rob" im not... its nothing to do with him as far as im aware.
 
I tell you what it's days like this that I'm happy I've been so poor at finding flaws over the years.
 
On 20/09/2020 i contacted Nominet via email to report a flaw being used by "multiple" people to catch domains...

it would appear certain people are not just "Abusing" the flaw but "Abusing" it to the extent that is causing large amounts of traffic on nominets network in a way that its not designed to handle and for that reason im going to expose the flaw so nominet fix the issue as quickly as possible and put a stop to the greedy bastard(s) that want to play hard ball!
@Hay Did this get dealt with by Nominet?
 
Status
Not open for further replies.
Top Bottom