▲ 1 ▼ What are these comments on lemmy posts? (lemmy.sdf.org) submitted 3 years ago by Fleecer74@lemmy.sdf.org to c/asklemmy@lemmy.ml 12 comments fedilink hide all child comments Are they just an issue with wefwef or trying to use an exploit
[–] Dirk@lemmy.ml 1 point 3 years ago (2 children) Another reason to block this TLD in the firewall solution. permalink fedilink source parent hideshow 4 child comments replies: [–] tarjeezy@lemmy.ca 1 point 3 years ago (1 child) Yea I've got both .zip and .mov blocked on my pihole permalink fedilink source parent hideshow 2 child comments replies: [+] Snipe_AT@lemmy.atay.dev -7 points 3 years ago sorry i’m missing it. why this specific TLD? can’t they just use any TLD for this and achieve the same thing? is there something special with .mov? permalink fedilink source parent [–] Snipe_AT@lemmy.atay.dev -5 points 3 years ago* (1 child) sorry i’m missing it. why this specific TLD? can’t they just use any TLD for this and achieve the same thing? why is this a reason to block it? permalink fedilink source parent hideshow 2 child comments replies: [–] Dirk@lemmy.ml 0 points 3 years ago (1 child) Because .zip is a commonly used file extension. permalink fedilink source parent hideshow 2 child comments replies: [–] Snipe_AT@lemmy.atay.dev -5 points 3 years ago (1 child) i think i understand that part but why is this specific event "another reason to block this TLD"? can’t they just use any TLD for this and achieve the same thing? is there another inherit security issue with .zip that doesn't exist with other domains? permalink fedilink source parent hideshow 2 child comments replies: [–] Dirk@lemmy.ml 0 points 3 years ago (1 child) They can and they do. Using a commonly known and used file extension to “hide” a malicious URL is just easier. https://www.youtube.com/watch?v=GCVJsz7EODA permalink fedilink source parent hideshow 2 child comments replies: [+] Snipe_AT@lemmy.atay.dev -6 points 3 years ago gotcha ok i think i’m getting it. just to make sure i’m not missing anything, you’re saying that in this case it didn’t matter as in the end they could use any TLD and achieve the same effect. but in general, threat actors hope to confuse people into thinking this “.zip” TLDs are only referencing local files instead of web addresses. right? permalink fedilink source parent
[–] tarjeezy@lemmy.ca 1 point 3 years ago (1 child) Yea I've got both .zip and .mov blocked on my pihole permalink fedilink source parent hideshow 2 child comments replies: [+] Snipe_AT@lemmy.atay.dev -7 points 3 years ago sorry i’m missing it. why this specific TLD? can’t they just use any TLD for this and achieve the same thing? is there something special with .mov? permalink fedilink source parent
[+] Snipe_AT@lemmy.atay.dev -7 points 3 years ago sorry i’m missing it. why this specific TLD? can’t they just use any TLD for this and achieve the same thing? is there something special with .mov? permalink fedilink source parent
[–] Snipe_AT@lemmy.atay.dev -5 points 3 years ago* (1 child) sorry i’m missing it. why this specific TLD? can’t they just use any TLD for this and achieve the same thing? why is this a reason to block it? permalink fedilink source parent hideshow 2 child comments replies: [–] Dirk@lemmy.ml 0 points 3 years ago (1 child) Because .zip is a commonly used file extension. permalink fedilink source parent hideshow 2 child comments replies: [–] Snipe_AT@lemmy.atay.dev -5 points 3 years ago (1 child) i think i understand that part but why is this specific event "another reason to block this TLD"? can’t they just use any TLD for this and achieve the same thing? is there another inherit security issue with .zip that doesn't exist with other domains? permalink fedilink source parent hideshow 2 child comments replies: [–] Dirk@lemmy.ml 0 points 3 years ago (1 child) They can and they do. Using a commonly known and used file extension to “hide” a malicious URL is just easier. https://www.youtube.com/watch?v=GCVJsz7EODA permalink fedilink source parent hideshow 2 child comments replies: [+] Snipe_AT@lemmy.atay.dev -6 points 3 years ago gotcha ok i think i’m getting it. just to make sure i’m not missing anything, you’re saying that in this case it didn’t matter as in the end they could use any TLD and achieve the same effect. but in general, threat actors hope to confuse people into thinking this “.zip” TLDs are only referencing local files instead of web addresses. right? permalink fedilink source parent
[–] Dirk@lemmy.ml 0 points 3 years ago (1 child) Because .zip is a commonly used file extension. permalink fedilink source parent hideshow 2 child comments replies: [–] Snipe_AT@lemmy.atay.dev -5 points 3 years ago (1 child) i think i understand that part but why is this specific event "another reason to block this TLD"? can’t they just use any TLD for this and achieve the same thing? is there another inherit security issue with .zip that doesn't exist with other domains? permalink fedilink source parent hideshow 2 child comments replies: [–] Dirk@lemmy.ml 0 points 3 years ago (1 child) They can and they do. Using a commonly known and used file extension to “hide” a malicious URL is just easier. https://www.youtube.com/watch?v=GCVJsz7EODA permalink fedilink source parent hideshow 2 child comments replies: [+] Snipe_AT@lemmy.atay.dev -6 points 3 years ago gotcha ok i think i’m getting it. just to make sure i’m not missing anything, you’re saying that in this case it didn’t matter as in the end they could use any TLD and achieve the same effect. but in general, threat actors hope to confuse people into thinking this “.zip” TLDs are only referencing local files instead of web addresses. right? permalink fedilink source parent
[–] Snipe_AT@lemmy.atay.dev -5 points 3 years ago (1 child) i think i understand that part but why is this specific event "another reason to block this TLD"? can’t they just use any TLD for this and achieve the same thing? is there another inherit security issue with .zip that doesn't exist with other domains? permalink fedilink source parent hideshow 2 child comments replies: [–] Dirk@lemmy.ml 0 points 3 years ago (1 child) They can and they do. Using a commonly known and used file extension to “hide” a malicious URL is just easier. https://www.youtube.com/watch?v=GCVJsz7EODA permalink fedilink source parent hideshow 2 child comments replies: [+] Snipe_AT@lemmy.atay.dev -6 points 3 years ago gotcha ok i think i’m getting it. just to make sure i’m not missing anything, you’re saying that in this case it didn’t matter as in the end they could use any TLD and achieve the same effect. but in general, threat actors hope to confuse people into thinking this “.zip” TLDs are only referencing local files instead of web addresses. right? permalink fedilink source parent
[–] Dirk@lemmy.ml 0 points 3 years ago (1 child) They can and they do. Using a commonly known and used file extension to “hide” a malicious URL is just easier. https://www.youtube.com/watch?v=GCVJsz7EODA permalink fedilink source parent hideshow 2 child comments replies: [+] Snipe_AT@lemmy.atay.dev -6 points 3 years ago gotcha ok i think i’m getting it. just to make sure i’m not missing anything, you’re saying that in this case it didn’t matter as in the end they could use any TLD and achieve the same effect. but in general, threat actors hope to confuse people into thinking this “.zip” TLDs are only referencing local files instead of web addresses. right? permalink fedilink source parent
[+] Snipe_AT@lemmy.atay.dev -6 points 3 years ago gotcha ok i think i’m getting it. just to make sure i’m not missing anything, you’re saying that in this case it didn’t matter as in the end they could use any TLD and achieve the same effect. but in general, threat actors hope to confuse people into thinking this “.zip” TLDs are only referencing local files instead of web addresses. right? permalink fedilink source parent