TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Hostnames and usernames to reserve

206 点作者 paulproteus超过 9 年前

13 条评论

zimbatm超过 9 年前
When github used to host &quot;pages&quot; under github.com I remember registering &quot;blog.github.com&quot; (and reporting obviously). If you take the social-engineering into account the list should be made long: login, support, status, help, ...<p>Just to say, the list could be made much longer (eg: login)
评论 #10639345 未加载
jakobdabo超过 9 年前
Thanks, this was very informative.<p>I wonder how the pull requests for the public suffix domains are being checked. Can somebody use it as an attack surface by adding the victim&#x27;s domain in that list and effectively blocking their website from setting cookies?
_theskumar超过 9 年前
Faced with similar issues, I maintain a python library called python-usernames[1] with list of closed to 400 reserved words[2].<p>Publishing this as a library helps a lot collecting the wordlist over time and be able to use the same list in all my projects.<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;theskumar&#x2F;python-usernames" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;theskumar&#x2F;python-usernames</a><p>[2] <a href="https:&#x2F;&#x2F;github.com&#x2F;theskumar&#x2F;python-usernames&#x2F;blob&#x2F;master&#x2F;usernames&#x2F;reserved_words.py#L4" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;theskumar&#x2F;python-usernames&#x2F;blob&#x2F;master&#x2F;us...</a>
beneater超过 9 年前
See also <a href="https:&#x2F;&#x2F;www.ietf.org&#x2F;rfc&#x2F;rfc2142.txt" rel="nofollow">https:&#x2F;&#x2F;www.ietf.org&#x2F;rfc&#x2F;rfc2142.txt</a>
jnky超过 9 年前
I would suggest adding &quot;autodiscover&quot; to the list of disallowed hosts. It is used by Microsoft Outlook and Exchange ActiveSync clients (e.g. in smartphones) to automatically detect the correct server settings.
ecesena超过 9 年前
Also, you should include the name of your service itself, especially if users can produce content.<p>Edit: for similar reasons to blog.&#x2F;login.&#x2F;support. etc. (just read other comments)
J_Darnley超过 9 年前
Congratulations for using example.com as it is meant to be used.
jonasvp超过 9 年前
Well, that would have been helpful when I announced <a href="http:&#x2F;&#x2F;www.browser-details.com" rel="nofollow">http:&#x2F;&#x2F;www.browser-details.com</a> on HN - it allows you to reserve a subdomain and it never even occurred to me that I&#x27;d have to restrict them (apart from the obvious regex).<p>So a thoughtful HNer taught me a lesson and reserved &quot;www&quot;. Took me a second to figure out why the site didn&#x27;t behave as expected...
dmd超过 9 年前
A popular MS Exchange cloud provider is <a href="http:&#x2F;&#x2F;webmail.domainlocalhost.com" rel="nofollow">http:&#x2F;&#x2F;webmail.domainlocalhost.com</a><p>Seriously. domainlocalhost.com.
shurcooL超过 9 年前
The article looks great and makes many good points, but I&#x27;ll pick on one: why disallow upper case letters from usernames?
评论 #10639022 未加载
评论 #10638931 未加载
protomyth超过 9 年前
helpdesk is a pretty good choice to reserve just to keep people from doing some foolish things.
zimbatm超过 9 年前
Just compiled the list and added a few others:<p><a href="https:&#x2F;&#x2F;zimbatm.github.io&#x2F;hostnames-and-usernames-to-reserve&#x2F;" rel="nofollow">https:&#x2F;&#x2F;zimbatm.github.io&#x2F;hostnames-and-usernames-to-reserve...</a><p>Feel free to use for your next PaaS !
supper超过 9 年前
I have handled this by only allowing more-than-one-word names to be use as subdomains, and made a slug out out of it, like so:<p>My Name =&gt; my-name.site.com<p>Is there any gotcha&#x27;s here for me?