📜 ⬆️ ⬇️

"Forbid them to ban" or the reverse side of the registry of banned sites



Perhaps the creators of the registry of banned sites did not think that this is possible. Or maybe they were aware of this possibility, but they did not attach due importance to it. Or maybe they did not care about possible technical problems in the implementation of the registry, and "just to prohibit." Or maybe they understood that it was impossible to avoid such problems, and why worry about it ahead of time? ..

One can speculate for a long time about what they thought and what they did not think, but the fact is a fact: by blocking any site they unwittingly hand a powerful tool, not to say a tool, to protect and attack the domain owner’s name on the registry.

Attention! The examples provided in this article are not a guide to action and serve only to illustrate weaknesses in the technical implementation of the registry. If you are going to actually do what is suggested below, I strongly recommend that you read the relevant articles of the Criminal Code of the Russian Federation and act only soberly assessing the possible risks of criminal prosecution.
')

Registry as a means of self-defense



If you suddenly turned out to be the owner of such a site, on the occasion included in the notorious registry, and if your main audience cannot reach your site because of the registry, which means, frankly, you have nothing more to lose, you can achieve the exclusion of your site from the registry is the old and proven way to protect against some types of DDoS.

For what you need only to make technical redirection from your domain to any other IP or domain. It is clear that redirection to 127.0.0.1, as it is done with DDoS, will not surprise anyone and only laugh Roskomnadzor (although for some telecom operators this may have unexpected consequences), for practical effect you should redirect to the site or sites that have direct or mediocre attitude to the creators of the registry, adding either a CNAME record for the domain of that site, or A record for the IP of that site.

Such redirection will lead to the actual inclusion of the IP of the site in the registry , followed by blocking access to it from end users . Which will quite naturally lead to the deletion of your domain from the registry , for otherwise there is no way to quickly remove the lock.

It can be assumed that when the target of the redirection should be chosen, the exclusion of the site from the black lists will occur very quickly, which means that for the redirecting records it is optimal to deliver a relatively short TTL, not more than 10 minutes.

Roskomnadzor can protect itself against such self-defense by compiling white lists of IP addresses that should never be blocked, with their distribution among operators like blacklists. Only sites related to the inventors of this registry will be affected by such an application of the registry.

Registry as a means of attack



This is the most annoying use of the registry for the general public, because there is nothing that can prevent a villain from making CNAME on any otherwise completely innocent website, thereby including its IP in the registry and blocking access to it without any practical possibility to appeal such a lock. If large companies can stand up for themselves and quickly solve this problem, then for small companies such blocking can have very unpleasant and long-lasting consequences.

I predict the appearance on the black market of services for “ordering” competitors' sites by entering their IP into the registry without their knowledge, selling domains already entered in the registry and renting sub-domains for later use at the buyer's request, placing hosted materials on your turnkey domain "And the like.

What's in it for you?



As long as this registry exists, as an administrator or site owner, you will no longer be able to sleep well, as before, before reading this article. It also means that if you used to be neutral and indifferent to this registry, now to restore your peace of mind and night sleep it is necessary that this stupid, meaningless and useless registry, invented by cretins far from the Internet, ceases to exist. Do not even think that it will not affect you.

Source: https://habr.com/ru/post/216153/


All Articles