New TLDs are available. .zip and .mov and it seems a bit concerning
Posted by NerdWhoLikesTrees@reddit | sysadmin | View on Reddit | 525 comments
I found a great comment by u/LudwikTR
>I feel like most people in the comments are not understanding the mechanism that makes this potentially problematic. I will admit that the author of the website, focusing primarily on his disdain for a particular corporation, doesn't help clarify the point.
A **significant** amount of software automatically converts parts of text that *appear* to be URLs (even without an explicit protocol) into clickable links. These include mail clients, messengers, internet forums, social media sites, CMS systems, text editors, etc.
Until now, such software would convert *hello.com* into a clickable link (since .com is a valid TLD) but would leave *hello.zip* as is (since .zip wasn't one). This won't change overnight, but gradually it will, as software libraries are updated with the current list of valid TLDs. This means that soon, whenever anyone mentions a zip file by name (in a message, email or a post), it will inadvertently become a link. To the reader, it will appear as if the author intentionally linked the file to assist the reader in finding it (e.g., "Then you need to download [documents-backup.zip](https://documents-backup.zip) from our intranet portal"). So, they'll click on the link expecting to download the file.
As an attacker, all I have to do is register the *documents-backup.zip* domain and upload a malicious zip file to the root of the domain. It will starts downloading as soon as someone opens http://documents-backup.zip. The individual clicking on the link expects a zip file to download - and it will, but it will be a malicious file from a third-party, not from the author of the message or a post.
So as a result we get a **trusted** source inadvertently linking to a malicious file, which is very different from scenarios discussed in other comments.
**EDIT:** There were questions whether a zip file can be downloaded by simply accessing the root of a domain so I registered the domain and created a simple demo here: [documents-backup.zip](https://documents-backup.zip)
525 Comments
tickpig@reddit
HanSolo71@reddit
hellomistershifty@reddit
Knotebrett@reddit
epsiblivion@reddit
GullibleDetective@reddit
CydeWeys@reddit
silentrawr@reddit
FlatwormAltruistic@reddit
GnarlyNarwhalNoms@reddit
HanSolo71@reddit
alvarkresh@reddit
saysthingsbackwards@reddit
HanSolo71@reddit
reddit_user33@reddit
HanSolo71@reddit
saysthingsbackwards@reddit
Dekklin@reddit
Asleep-Measurement82@reddit
AfternoonFederal6502@reddit
CynicalTree@reddit
alvarkresh@reddit
rootofallworlds@reddit
ExcitingTabletop@reddit
al3arabcoreleone@reddit
ITaggie@reddit
therealperchy22@reddit
Hulkstern@reddit
Nomaddo@reddit
Hulkstern@reddit
Nomaddo@reddit
Hulkstern@reddit
Alzzary@reddit
8siYv@reddit
Alzzary@reddit
billyalt@reddit
AltoidStrong@reddit
sivadbp@reddit
toadofsteel@reddit
Cyhawk@reddit
Daeurth@reddit
HotPieFactory@reddit
Xzenor@reddit
dosmage@reddit
KaitRaven@reddit
ZippyDan@reddit
dosmage@reddit
vee_lan_cleef@reddit
LogicalExtension@reddit
dosmage@reddit
LogicalExtension@reddit
Poot_McGoot@reddit
dosmage@reddit
ElectroSpore@reddit
dosmage@reddit
epsiblivion@reddit
ripzipzap@reddit
lighthawk16@reddit
blazze_eternal@reddit
toadofsteel@reddit
jdeath@reddit
joeshmo101@reddit
aVarangian@reddit
joeshmo101@reddit
lupjo@reddit
laplongejr@reddit
port53@reddit
GiveEmWatts@reddit
throwmamadownthewell@reddit
enfly@reddit
Consistent_Pick9500@reddit
jason_steakums@reddit
Daniel15@reddit
Sophira@reddit
Creshal@reddit
Appoxo@reddit
DenseDifficulty8317@reddit
therealperchy22@reddit
amunak@reddit
ollomulder@reddit
Sky_hippo@reddit
louis-lau@reddit
dotikk@reddit
Consistent_Pick9500@reddit
alejandroiam@reddit
dotikk@reddit
Reelix@reddit
ACSquiggle@reddit
ollomulder@reddit
CharcoaI@reddit
dotikk@reddit
louis-lau@reddit
dotikk@reddit
louis-lau@reddit
charonn0@reddit
ollomulder@reddit
charonn0@reddit
5erif@reddit
alejandroiam@reddit
5erif@reddit
RandomComputerFellow@reddit
alejandroiam@reddit
abqcheeks@reddit
Equal_Coach6307@reddit
IAmWrong@reddit
alejandroiam@reddit
IAmWrong@reddit
nightwatch_admin@reddit
AnteaterProboscis@reddit
eXtc_be@reddit
Mehlsuppe@reddit
crowruin@reddit
R0tareneg@reddit
lkraider@reddit
quintus_horatius@reddit
LividLager@reddit
EpicCyndaquil@reddit
AlexanderDaychilde@reddit
Asleep-Measurement82@reddit
OverlordXenu@reddit
spyingwind@reddit
therealperchy22@reddit
NuclearBiceps@reddit
langlo94@reddit
Cyhawk@reddit
PJBthefirst@reddit
n3rdopolis@reddit
PJBthefirst@reddit
AfternoonFederal6502@reddit
rehab212@reddit
Somedudesnews@reddit
throwawayPzaFm@reddit
n3rdopolis@reddit
CobblerYm@reddit
n3rdopolis@reddit
framejunkie@reddit
RobotTreeProf@reddit
n3rdopolis@reddit
GBU_28@reddit
CarefulAstronomer255@reddit
Ams197624@reddit
mavrc@reddit
4kVHS@reddit
TumsFestivalEveryDay@reddit
jshackles@reddit
Real_Lemon8789@reddit
alvarkresh@reddit
Pelatov@reddit
QuitLookingAtMe@reddit
gramathy@reddit
forte_bass@reddit
Gamefan211@reddit
forte_bass@reddit
gramathy@reddit
forte_bass@reddit
Borgoff@reddit
International-Big-97@reddit
Extreme-Yam7693@reddit
hasthisusernamegone@reddit
ueberbelichtetesfoto@reddit
hasthisusernamegone@reddit
Prod_Is_For_Testing@reddit
thatguyonthevicinity@reddit
MagnificoReattore@reddit
zuckerballs@reddit
PoopyMouthwash84@reddit
Daniel15@reddit
PoopyMouthwash84@reddit
Daniel15@reddit
Pelatov@reddit
PoopyMouthwash84@reddit
Pelatov@reddit
PMental@reddit
CloudHostedGarbage@reddit
al3arabcoreleone@reddit
Kael_Alduin@reddit
themeatbridge@reddit
Geminii27@reddit
sagewah@reddit
Matir@reddit
Kael_Alduin@reddit
TheHouseofOne@reddit
TouristNo4039@reddit
kizzle69@reddit
Calexander3103@reddit
CannonPinion@reddit
HildartheDorf@reddit
framejunkie@reddit
ApricotPenguin@reddit
farva_06@reddit
TDR-Java@reddit
Pseudoboss11@reddit
firefish5000@reddit
neoplastic_pleonasm@reddit
FractalParadigm@reddit
jpc0za@reddit
FractalParadigm@reddit
jpc0za@reddit
puhtahtoe@reddit
puhtahtoe@reddit
jadkik94@reddit
Katana__@reddit
Mooshberry_@reddit
firefish5000@reddit
StaffOfDoom@reddit
iceph03nix@reddit
mini4x@reddit
postfu@reddit
trainmaster247@reddit
postfu@reddit
trainmaster247@reddit
Reelix@reddit
Rude_Strawberry@reddit
officeboy@reddit
ruralconnection@reddit
HanSolo71@reddit
officeboy@reddit
HanSolo71@reddit
_aaronallblacks@reddit
sys_sadmin00@reddit
jamesaepp@reddit
sys_sadmin00@reddit
Matir@reddit
_aaronallblacks@reddit
FalconX88@reddit
flunky_the_majestic@reddit
FalconX88@reddit
silviustitus@reddit
Reelix@reddit
Fugalism@reddit
Reelix@reddit
Fugalism@reddit
Slasher1738@reddit
Creshal@reddit
stucjei@reddit
Terminal_Monk@reddit
ElectroNeutrino@reddit
augugusto@reddit
CloudHostedGarbage@reddit
kayjaykay87@reddit
MajStealth@reddit
HipsterSlug@reddit
peichma75@reddit
fakehalo@reddit
uffefl@reddit
fakehalo@reddit
SATIRICthrowaway@reddit
uffefl@reddit
jarfil@reddit
Edexote@reddit
hugglesthemerciless@reddit
Deae_Hekate@reddit
NeoQwerty2002@reddit
calcium@reddit
Sharpymarkr@reddit
calcium@reddit
Ekgladiator@reddit
YetAnotherSysadmin58@reddit
illhaveubent@reddit
YetAnotherSysadmin58@reddit
Syndic_Thrass@reddit
jr_sys@reddit
Syndic_Thrass@reddit
jr_sys@reddit
Shendare@reddit
OverlordXenu@reddit
Incrarulez@reddit
Speeddymon@reddit
amunak@reddit
BronzeAgeTea@reddit
DJOMaul@reddit
BaconEatingChamp@reddit
DJOMaul@reddit
calcium@reddit
nephelokokkygia@reddit
AlexanderDaychilde@reddit
atred@reddit
all_of_the_lightss@reddit
n-of-one@reddit
azdood85@reddit
m0nk37@reddit
jimbobjames@reddit
gex80@reddit
GrapeAyp@reddit
warezeater@reddit
MageFood@reddit
CaseyChaos1212@reddit
314ish@reddit
DenseDifficulty8317@reddit
Bioman312@reddit
Hale-at-Sea@reddit
TDR-Java@reddit
DenseDifficulty8317@reddit
SoftShakes@reddit
EarlyEditor@reddit
FudgeeO98@reddit
SoftShakes@reddit
Elethor@reddit
micalm@reddit
therealperchy22@reddit
0x1f606@reddit
EarlyEditor@reddit
SpicyHotPlantFart@reddit
EvanH123@reddit
yParticle@reddit
datenwolf@reddit
holly_hoots@reddit
GoogleDrummer@reddit
yajCee@reddit
GoogleDrummer@reddit
CarryTheRemainder@reddit
jherazob@reddit
opuses@reddit
Fugalism@reddit
opuses@reddit
Fugalism@reddit
opuses@reddit
NerdWhoLikesTrees@reddit (OP)
rigsta@reddit
jarfil@reddit
droans@reddit
doggxyo@reddit
flunky_the_majestic@reddit
Trash-Alt-Account@reddit
getsmartt@reddit
jacod1982@reddit
NerdWhoLikesTrees@reddit (OP)
jacod1982@reddit
NerdWhoLikesTrees@reddit (OP)
marklein@reddit
cyberentomology@reddit
marklein@reddit
Reelix@reddit
marklein@reddit
Reelix@reddit
marklein@reddit
cyberentomology@reddit
therealperchy22@reddit
cyberentomology@reddit
marklein@reddit
erythro@reddit
marklein@reddit
Mithious@reddit
marklein@reddit
Appoxo@reddit
cyberentomology@reddit
uniquehr@reddit
Sergster1@reddit
Fugalism@reddit
Reasonable_Ticket_84@reddit
ConsumeDontThink@reddit
TimTam4UandU@reddit
TimTam4UandU@reddit
konaya@reddit
SDI-tech@reddit
reddig33@reddit
Karmaisthedevil@reddit
NerdWhoLikesTrees@reddit (OP)
binaryhextechdude@reddit
grumpyfrench@reddit
tgp1994@reddit
TheSpixxyQ@reddit
ZenAdm1n@reddit
wreckedcarzz@reddit
Cakemagick@reddit
stilettoblade@reddit
0x1f606@reddit
DrDragonKiller@reddit
epsiblivion@reddit
aVarangian@reddit
ywBBxNqW@reddit
ywBBxNqW@reddit
TheOriginalSoni2@reddit
steveinbuffalo@reddit
Alzzary@reddit
nullbyte420@reddit
Alzzary@reddit
nullbyte420@reddit
Alzzary@reddit
michaelist@reddit
Intelligent-Magician@reddit
NightOfTheLivingHam@reddit
mikbob@reddit
delightfulsorrow@reddit
therealperchy22@reddit
delightfulsorrow@reddit
Le_Vagabond@reddit
sefocs@reddit
jarfil@reddit
Whitestrake@reddit
kz393@reddit
Whitestrake@reddit
Ruben_NL@reddit
bishop40404@reddit
tfpZeroDay@reddit
sefocs@reddit
jantari@reddit
uffefl@reddit
Probably_a_Shitpost@reddit
ComeAndGetYourPug@reddit
AfternoonFederal6502@reddit
nullbyte420@reddit
LeaveTheMatrix@reddit
rafalmio@reddit
michaelpaoli@reddit
firefish5000@reddit
Extreme-Yam7693@reddit
Reelix@reddit
MiataCory@reddit
Reelix@reddit
Virtual_Low83@reddit
Karfedix_of_Pain@reddit
da_chicken@reddit
jantari@reddit
ChristophCross@reddit
Cormacolinde@reddit
flunky_the_majestic@reddit
simask234@reddit
rustyflavor@reddit
Mothringer@reddit
VulturE@reddit
m0nk37@reddit
jonblackgg@reddit
jmbpiano@reddit
private_entity@reddit
AfternoonFederal6502@reddit
jrcomputing@reddit
TDSheridan05@reddit
dezmd@reddit
guest13@reddit
corkyskog@reddit
stick-insect-enema@reddit
d1smalnow@reddit
ganymede_boy@reddit
Cachar@reddit
jantari@reddit
janbacher@reddit
ipaqmaster@reddit
-aledo@reddit
ZAFJB@reddit
eddyjay85@reddit
louis-lau@reddit
uffefl@reddit
louis-lau@reddit
therealperchy22@reddit
elislider@reddit
BoredTechyGuy@reddit
Pseudoboss11@reddit
AlphaO4@reddit
esorciccio@reddit
therealperchy22@reddit
bermudi86@reddit
wgc123@reddit
port53@reddit
boli99@reddit
Dependent_Hold8463@reddit
TehWhale@reddit
TopHatProductions115@reddit
ruttin_mudders@reddit
constantstranger@reddit
hotdwag@reddit
janhy@reddit
a_shootin_star@reddit
powercow@reddit
NerdWhoLikesTrees@reddit (OP)
JustZisGuy@reddit
InitializedVariable@reddit
TrueStoriesIpromise@reddit
PC509@reddit
ApostropheusDeletus@reddit
jmcgit@reddit
ApostropheusDeletus@reddit
Yum-z@reddit
100GbE@reddit
SoldierHawk@reddit
NotFlameRetardant@reddit
speakeasyboy@reddit
Echo71Niner@reddit
flunky_the_majestic@reddit
slater126@reddit
groupwhere@reddit
Taladar@reddit
TouristNo4039@reddit
HildartheDorf@reddit
Taladar@reddit
jarfil@reddit
groupwhere@reddit
RedKnightBegins@reddit
ch1llboy@reddit
groupwhere@reddit
ctrl_alt_lynx@reddit
admincee@reddit
GreenWoodDragon@reddit
bshea@reddit
Pallidum_Treponema@reddit
Skullpuck@reddit
louis-lau@reddit
Administratr@reddit
TheLightingGuy@reddit
IustinRaznic@reddit
whyareyouemailingme@reddit
wgc123@reddit
whyareyouemailingme@reddit
ku3i@reddit
meeu@reddit
sldrfounder@reddit
prestigious_delay_7@reddit
aVarangian@reddit
maztron@reddit
silentdon@reddit
Pazuuuzu@reddit
BloomerzUK@reddit
SK4T3RG4M3R@reddit
DungaRD@reddit
DungaRD@reddit
DungaRD@reddit
mrzaius@reddit
_aaronallblacks@reddit
Dolapevich@reddit
AnApexBread@reddit
Fallingdamage@reddit
esabys@reddit
SandyTech@reddit
OtisB@reddit
VexingRaven@reddit