we are not at risk, the idea is it is just another easy method to hit the lowest common denominator, and it did not need to happen
general
Jump to date
Wednesday, May 17, 2023
http://fortnite.zip
Fortnite.zip Domain Name
I love the name fortnite, it sounds nice
fortnite.zipit's real
I don't think it's the file that's risky Max
It is bad because its retarded and they did not need to do this
I think the trick would be to host a file website.zip at the domain website.zip
All this said, if josh gets his .net repo'd some how, he should get kiwifarms.zip
I think that is a banger name
and then within the .zip file, I think you'd have way more attack vectors to execute code in-browser, that is beyond what you could get away via javascript
maybe I'm wrong, or missing something
but I think the way it would treat it was you were accessing a remote file via your browser, aliased as a website
which is probably doable now
so idk if this really changes anything
but I feel like there's something I'm missing
that's not just "lol DL this file"
based
A lot of people bought domains to redirect to their actual sites
that is what I am seeing if you search site:.zip
and click around
I'm routing for someone to actually make use of these for a big scam
probably have to limit it to X characters
what's the longest TLD rn?
ok Max, compromise
you can have any custom TLD you want, that's 5-16 char
but <4 is reserved for ICANN, governments, and Google
phijkchu.travelersinsurance
let's go
