Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead.

Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead.

Scheduled Pinned Locked Moved Uncategorized
25 Posts 18 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchange
    wrote last edited by
    #1

    Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

    "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

    Link Preview Image
    Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

    Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

    favicon

    gofundme.com (www.gofundme.com)

    Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

    Link Preview Image
    hopelessdemigod@mstdn.socialH fancysandwiches@neuromatch.socialF womble@infosec.exchangeW ohir@social.vivaldi.netO jorismeys@mstdn.socialJ 12 Replies Last reply
    1
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

      "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

      Link Preview Image
      Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

      Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

      favicon

      gofundme.com (www.gofundme.com)

      Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

      Link Preview Image
      hopelessdemigod@mstdn.socialH This user is from outside of this forum
      hopelessdemigod@mstdn.socialH This user is from outside of this forum
      hopelessdemigod@mstdn.social
      wrote last edited by
      #2

      @briankrebs

      I thought squatting was prohibited? They need to enforce the policy and release the name.

      Having laws, policies or rules that aren’t enforced wastes people’s time.

      womble@infosec.exchangeW en3py@onlyarts.socialE 2 Replies Last reply
      0
      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

        Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

        "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

        Link Preview Image
        Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

        Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

        favicon

        gofundme.com (www.gofundme.com)

        Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

        Link Preview Image
        fancysandwiches@neuromatch.socialF This user is from outside of this forum
        fancysandwiches@neuromatch.socialF This user is from outside of this forum
        fancysandwiches@neuromatch.social
        wrote last edited by
        #3

        @briankrebs publicly declaring a campaign to buy the domain back seems like a great way to make the price go up.

        poing@chaos.socialP 1 Reply Last reply
        0
        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

          Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

          "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

          Link Preview Image
          Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

          Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

          favicon

          gofundme.com (www.gofundme.com)

          Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

          Link Preview Image
          womble@infosec.exchangeW This user is from outside of this forum
          womble@infosec.exchangeW This user is from outside of this forum
          womble@infosec.exchange
          wrote last edited by
          #4

          @briankrebs why reward the lowlifes who are squatting the name? It's not entirely dissimilar to paying ransomware. Instead, put up the site on a new domain and do a search and replace in the NVD. It doesn't fix all the other dead links out there, but it's better than paying a rentier.

          1 Reply Last reply
          0
          • hopelessdemigod@mstdn.socialH hopelessdemigod@mstdn.social

            @briankrebs

            I thought squatting was prohibited? They need to enforce the policy and release the name.

            Having laws, policies or rules that aren’t enforced wastes people’s time.

            womble@infosec.exchangeW This user is from outside of this forum
            womble@infosec.exchangeW This user is from outside of this forum
            womble@infosec.exchange
            wrote last edited by
            #5

            @HopelessDemigod domain squatting is against the rules. Speculation, on the other hand, is perfectly fair and reasonable.

            the_moep@mastodon.deT 1 Reply Last reply
            0
            • womble@infosec.exchangeW womble@infosec.exchange

              @HopelessDemigod domain squatting is against the rules. Speculation, on the other hand, is perfectly fair and reasonable.

              the_moep@mastodon.deT This user is from outside of this forum
              the_moep@mastodon.deT This user is from outside of this forum
              the_moep@mastodon.de
              wrote last edited by
              #6

              @womble @HopelessDemigod
              How?

              womble@infosec.exchangeW 1 Reply Last reply
              0
              • the_moep@mastodon.deT the_moep@mastodon.de

                @womble @HopelessDemigod
                How?

                womble@infosec.exchangeW This user is from outside of this forum
                womble@infosec.exchangeW This user is from outside of this forum
                womble@infosec.exchange
                wrote last edited by
                #7

                @the_moep bad people squat domains, savvy businesspeople speculate.

                1 Reply Last reply
                0
                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                  Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

                  "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

                  Link Preview Image
                  Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

                  Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

                  favicon

                  gofundme.com (www.gofundme.com)

                  Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

                  Link Preview Image
                  ohir@social.vivaldi.netO This user is from outside of this forum
                  ohir@social.vivaldi.netO This user is from outside of this forum
                  ohir@social.vivaldi.net
                  wrote last edited by
                  #8

                  @briankrebs It would be way better for "security nerds" to register securityfocus.is or whatever.eu and supply the non nerd community with `s/securityfocus.com/whatever.eu/` solution.

                  Were times better the ACPA and pro bono lawyers would be enough.

                  1 Reply Last reply
                  0
                  • R relay@relay.an.exchange shared this topic
                  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                    Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

                    "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

                    Link Preview Image
                    Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

                    Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

                    favicon

                    gofundme.com (www.gofundme.com)

                    Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

                    Link Preview Image
                    jorismeys@mstdn.socialJ This user is from outside of this forum
                    jorismeys@mstdn.socialJ This user is from outside of this forum
                    jorismeys@mstdn.social
                    wrote last edited by
                    #9

                    @briankrebs
                    Nah, not paying for thieves and opportunistic bags of shite. 175k for a domain? Hell no.

                    1 Reply Last reply
                    0
                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                      Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

                      "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

                      Link Preview Image
                      Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

                      Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

                      favicon

                      gofundme.com (www.gofundme.com)

                      Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

                      Link Preview Image
                      x41h@infosec.exchangeX This user is from outside of this forum
                      x41h@infosec.exchangeX This user is from outside of this forum
                      x41h@infosec.exchange
                      wrote last edited by
                      #10

                      @briankrebs The whole vulnerability publication lifecycle is such a shit show. Vulnerability management tools are now handling their own CVE databases and enriching data without waiting for NISTs bottleneck.

                      1 Reply Last reply
                      0
                      • hopelessdemigod@mstdn.socialH hopelessdemigod@mstdn.social

                        @briankrebs

                        I thought squatting was prohibited? They need to enforce the policy and release the name.

                        Having laws, policies or rules that aren’t enforced wastes people’s time.

                        en3py@onlyarts.socialE This user is from outside of this forum
                        en3py@onlyarts.socialE This user is from outside of this forum
                        en3py@onlyarts.social
                        wrote last edited by
                        #11

                        @HopelessDemigod @briankrebs maybe someone could escalate the problem to ICANN?

                        Symantec is awesome at breaking down things... it almost feels like it's their mission.

                        Let's buy this awesome product. And ruin it.

                        poing@chaos.socialP 1 Reply Last reply
                        0
                        • en3py@onlyarts.socialE en3py@onlyarts.social

                          @HopelessDemigod @briankrebs maybe someone could escalate the problem to ICANN?

                          Symantec is awesome at breaking down things... it almost feels like it's their mission.

                          Let's buy this awesome product. And ruin it.

                          poing@chaos.socialP This user is from outside of this forum
                          poing@chaos.socialP This user is from outside of this forum
                          poing@chaos.social
                          wrote last edited by
                          #12

                          @en3py @HopelessDemigod @briankrebs

                          This is nothing that ICANN really has anything to do with. Unless an ICANN contracted party did something wrong or if this would fall under DNS abuse, but even then the registrar would be the one investigating. I don't think this is a case of either.

                          And as others already said, domain squatting is only the case if it infringes on the rights of others and us abusive. Selling domains itself does not constitute squatting.

                          1 Reply Last reply
                          0
                          • fancysandwiches@neuromatch.socialF fancysandwiches@neuromatch.social

                            @briankrebs publicly declaring a campaign to buy the domain back seems like a great way to make the price go up.

                            poing@chaos.socialP This user is from outside of this forum
                            poing@chaos.socialP This user is from outside of this forum
                            poing@chaos.social
                            wrote last edited by
                            #13

                            @fancysandwiches @briankrebs

                            Yeah I think it might have been better to try to reach out to the owners first. According to archive org, it looks like Accenture had control over the domain already in 2023, unless the subdomain redirect messed up the archives somehow.

                            johnlogic@sfba.socialJ 1 Reply Last reply
                            0
                            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                              Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

                              "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

                              Link Preview Image
                              Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

                              Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

                              favicon

                              gofundme.com (www.gofundme.com)

                              Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

                              Link Preview Image
                              michael@westergaard.socialM This user is from outside of this forum
                              michael@westergaard.socialM This user is from outside of this forum
                              michael@westergaard.social
                              wrote last edited by
                              #14
                              “Lets reward domain squatting instead of running a search/replace”
                              1 Reply Last reply
                              0
                              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

                                "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

                                Link Preview Image
                                Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

                                Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

                                favicon

                                gofundme.com (www.gofundme.com)

                                Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

                                Link Preview Image
                                J This user is from outside of this forum
                                J This user is from outside of this forum
                                john_philip_bell@defcon.social
                                wrote last edited by
                                #15

                                @briankrebs
                                What am I missing here? Getting the domain back does not restore the information the links point to. Is someone saying there is a backup somewhere to restore?

                                Restore it (old target website) anywhere (to a new host), I've downloaded the (NVD) database for local processing many times in my life... In your own copy, search and replace the domain reference to a new host...

                                If this is important enough to the community at large, work on getting the NVD data itself to be updated. It is all text (once upon a time, XML, now I think JSON)

                                🤔

                                Edit: clarified 'it' as "(old target website)...(to a new host)"; and 'database' as "(NVD)"

                                1 Reply Last reply
                                0
                                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                  Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

                                  "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

                                  Link Preview Image
                                  Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

                                  Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

                                  favicon

                                  gofundme.com (www.gofundme.com)

                                  Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

                                  Link Preview Image
                                  rusty_shackleford@colorlessgreenvoid.comR This user is from outside of this forum
                                  rusty_shackleford@colorlessgreenvoid.comR This user is from outside of this forum
                                  rusty_shackleford@colorlessgreenvoid.com
                                  wrote last edited by
                                  #16
                                  @briankrebs
                                  Why in the hell would you pay a squatter for a domain? Fuck that guy
                                  1 Reply Last reply
                                  0
                                  • poing@chaos.socialP poing@chaos.social

                                    @fancysandwiches @briankrebs

                                    Yeah I think it might have been better to try to reach out to the owners first. According to archive org, it looks like Accenture had control over the domain already in 2023, unless the subdomain redirect messed up the archives somehow.

                                    johnlogic@sfba.socialJ This user is from outside of this forum
                                    johnlogic@sfba.socialJ This user is from outside of this forum
                                    johnlogic@sfba.social
                                    wrote last edited by
                                    #17

                                    @poing @fancysandwiches @briankrebs

                                    Why not just fix the links and automatically point them to pages at archive org ?

                                    poing@chaos.socialP 1 Reply Last reply
                                    0
                                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                      Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

                                      "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

                                      Link Preview Image
                                      Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

                                      Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

                                      favicon

                                      gofundme.com (www.gofundme.com)

                                      Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

                                      Link Preview Image
                                      quinn@social.circl.luQ This user is from outside of this forum
                                      quinn@social.circl.luQ This user is from outside of this forum
                                      quinn@social.circl.lu
                                      wrote last edited by
                                      #18

                                      @briankrebs Accenture. Of fucking course.

                                      1 Reply Last reply
                                      0
                                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                        Security nerds have launched a Gofundme to buy back securityfocus.com, a domain that hosted the Bugtraq site and more than 120,000 links from the National Vulnerability Database that are now dead. Whoops.

                                        "Symantec killed Bugtraq in 2020 and let the domain lapse. Now it's squatted for $175k," writes Jonathan Brossard. "The NVD has 120,000+ broken links pointing there. The security community's memory is being held hostage."

                                        Link Preview Image
                                        Donate to Restore SecurityFocus & Bugtraq, organized by Jonathan Brossard

                                        Hi, I'm endrazine — a cybersecurity researcher, and author of security tools used by… Jonathan Brossard needs your support for Restore SecurityFocus & Bugtraq

                                        favicon

                                        gofundme.com (www.gofundme.com)

                                        Not sure if this matters, but DomainTools says the domain was transferred to Accenture.com, Accenture Global Services Limited in Ireland.

                                        Link Preview Image
                                        franga2000@chaos.socialF This user is from outside of this forum
                                        franga2000@chaos.socialF This user is from outside of this forum
                                        franga2000@chaos.social
                                        wrote last edited by
                                        #19

                                        @briankrebs fuck that, sed -i all the links in the NVD to point at archive.org and donate the 175k to them. Getting the domain won't restore the content anyways.

                                        rusty_shackleford@colorlessgreenvoid.comR 1 Reply Last reply
                                        0
                                        • franga2000@chaos.socialF franga2000@chaos.social

                                          @briankrebs fuck that, sed -i all the links in the NVD to point at archive.org and donate the 175k to them. Getting the domain won't restore the content anyways.

                                          rusty_shackleford@colorlessgreenvoid.comR This user is from outside of this forum
                                          rusty_shackleford@colorlessgreenvoid.comR This user is from outside of this forum
                                          rusty_shackleford@colorlessgreenvoid.com
                                          wrote last edited by
                                          #20
                                          @franga2000 @briankrebs

                                          This. Buying the domain from a squatter is a retard move.
                                          rusty_shackleford@colorlessgreenvoid.comR freediverx@mastodon.socialF 2 Replies Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups