[unisog] Problems with EDU.COM domain

Alan Amesbury amesbury at oitsec.umn.edu
Thu Mar 23 22:15:50 GMT 2006

H. Morrow Long wrote:

> As well as anything at zzz.edu.com such as XXX.ZZZ.EDU.COM
> They all resolve to the same IP for me (
> Thing is, if you use a name it recognizes (www.yale.edu.com)
> it presents a Yale University specific web page.  If you use a
> name it doesn't ( http://xxx.zzz.edu.com/ ) you just get a
> generic advertising page.

 From a technical standpoint, the potential problem I see here is that 
people with hosts that use a misconfigured or broken resolver may end up 
at the *.edu.com sites first.  Consider what would happen if your 
resolv.conf search line contained

	search mysite.com com

Sure, such a configuration is arguable lunacy, but it's not entirely out 
of the realm of possibility.  More importantly, some web browsers "help" 
their users out by completing URLs with ".com".

Something to keep in mind, I guess.

Alan Amesbury
University of Minnesota

More information about the unisog mailing list