5 ms·
In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears
by kencausey 1mo ago
In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.
- inigyou 1mo agoWhois has been replaced by RDAP.
- b112 1mo agoThere are whois servers, and the whois command, so no, it has not. I agree that this is the goal.
- kencausey 1mo agoAs far as I am able to find Google does not provide an RDAP server for gle either.
- keane 1mo agoICANN: “All gTLD registries and registrars are required to provide RDAP services.” They are listed at lookup.icann.org and the one in question is https://pubapi.registry.google/rdap/domain/c.gle https://pubapi.registry.google/rdap/domain/c.gle
- ButlerianJihad 1mo agohttps://en.wikipedia.org/wiki/Registration_Data_Access_Protocol#WHOIS_replacement https://en.wikipedia.org/wiki/Registration_Data_Access_Proto... Even if you retrieve registration information about a domain, that will not necessarily help a consumer figure out if it is legitimate, or who owns it. There will be a lot of redactions and shell companies and generic information. The target market for WHOIS and RDAP has always been administrators and registrants and others on their level. Obviously--RDAP is a JSON format, not plain text anymore! As a consumer, if you're trying OSINT, try not to spread that around, because it is another opportunity for deception, confusion, and cargo culting. What you want is good malware protection, according to your actual risk profile. If your browser protection is worthwhile then it will stop attacks from domains like that. If you are particularly worried about strange domains, many 3rd-party DNS services can block those. NextDNS had a checkbox for "block newly-registered domains" as well as filtering any sus gTLD or ccTLD type ones.
- varun_ch 1mo agonot that it really helps to know now, but .gle is a TLD operated by Google. the only domains on a .gle domain will be Google (in theory). Plus, a single letter domain (on any TLD), like c.gle would be expensive to burn on a phishing scam. But no one should need to know this. I don't know what's so wrong about just using google.com, or even .google for anything user facing... I understand the idea that they want an official TLD that doesn't necessarily have their trademark in it, so you know it's a link to a Google service but potentially user content, but why have c.gle links to official/urgent messaging?? (at least they don't use 1drv.com in emails like Microsoft.. seriously...)
- Terr_ 1mo agoI assume it's tied somehow to SMS character limits, where somebody decided a couple extra letters of content was worth it somehow.
- xethos 1mo agoI agree, but I'd also challenge you to find a cellphone that a normal person carries that doesn't just concatonate multiple messages and turn them into MMS. My Pinephone and Librem 5 did that, but that reinforces my point: this is not something a normal person will see
- kevin_thibedeau 1mo agoMMS costs more on the backend.
- martheen 1mo agoWait, multiple messages get concatenated to MMS? In early 2010s I remember in my country it's still concatenated as regular text (so if one part is somehow missing or comes in very late, some phones will only show the surviving parts as one, others dump each parts separately), I guess they remove that functionality? Back then each part cost roughly one cent and plenty of phones in use still don't support MMS, then people just jump into WhatsApp entirely when Nokia support it in their feature phone.