Don’t Whois my Domain

On July 14, 2007, in XSS Corner, by Zoiz

This morning, I took a walk to register.net.id , and wanted to change my profile. The reason is that I don’t want other people can have my personal information easily when they whois my web. As we know that regisrating an .id domain, they ask me to send them a scanned version of identity card (KTP), and the profile submited there must match the information on the identity card. SO, that’s kinda f*cking easy of information gathering for somebody else if i don’t change my profile after this domain approved xD~

When I intend to change my profile, I found out that they don’t have any XSS filter there. Maybe they think that all user all bound to be honest (hum..honest?? :P ). Nah, so now when anyone trying to whois my domain, he’ll get a present, so becareful :D

Tagged with:  

10 Responses to “Don’t Whois my Domain”

  1. CalvinLimuel says:

    hadiahnya apaan tuh :)

  2. CalvinLimuel says:

    apa tuh hadiahnya? mau tau nih :)

  3. Zoiz says:

    It’s something interesting :P but Don’t Try It at Home :D

  4. sishimaru says:

    wew..
    i like to try at home :)

  5. sishimaru says:

    i think it will be exciting to try at home :P

  6. [...] I noticed that the XSS was actually same with mine. Here is the article I posted : Don’t Whois My Domain [...]

  7. [...] noticed that the XSS was actually same with mine. Here is the article I posted : Don’t Whois My Domain This remind me a funny thing that is when the Administrator of the Domain Registrar found out [...]

  8. [...] XSS vulnerability on the Whois engine first time found by me on 14 July 2007. You can read this post about how I found it, and this post that I rewrite. It’s not a big vulnerability though, but due to it’s a [...]

  9. [...] XSS vulnerability on the Whois engine first time found by me on 14 July 2007. You can read this post about how I found it, and this post that I rewrite. It’s not a big vulnerability though, but due to it’s mass, so [...]

  10. [...] I noticed that the XSS was actually same with mine. Here is the article I posted :D on’t Whois My Domain [...]

Leave a Reply