publicsuffix / list

The Public Suffix List
https://publicsuffix.org/
Mozilla Public License 2.0
2k stars 1.2k forks source link

remove cloudcontrol.com #2072

Closed brutasse closed 1 month ago

brutasse commented 1 month ago

Introduced in 56cd84e -- the domain is no longer a public suffix.

_psl records do not exist.

groundcat commented 1 month ago

Comments

Just because _psl records do not exist does not mean we can safely remove them from the PSL. They were added in 2013, and keeping _psl records was not mandatory, so people might not be aware of this. Further confirmation is required to ensure that removing them does not have an adverse impact or cause harm.

cloudcontrolapp.com:

WHOIS

PSL submission on 2013-07-23. Per WHOIS, Creation Date: 2013-04-05T09:52:13Z, which indicates that this domain is possibly still under control of original requester if it hadn't been transferred.

   Domain Name: CLOUDCONTROLAPP.COM
   Registry Domain ID: 1791489884_DOMAIN_COM-VRSN
   Registrar WHOIS Server: whois.domrobot.com
   Registrar URL: http://www.inwx.com
   Updated Date: 2024-04-06T07:10:24Z
   Creation Date: 2013-04-05T09:52:13Z
   Registry Expiry Date: 2025-04-05T09:52:13Z
   Registrar: INWX GmbH
   Registrar IANA ID: 1420
   Registrar Abuse Contact Email: abuse@inwx.com
   Registrar Abuse Contact Phone: +49.30983212123
   Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
   Name Server: NS.INWX.DE
   Name Server: NS2.INWX.DE
   Name Server: NS3.INWX.EU
   DNSSEC: unsigned
   URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of whois database: 2024-07-26T02:45:02Z <<<

Sources: whois utility generated at 2024-07-25 22:45:35

Organization Website and Nature Check

Website https://www.cloudcontrol.com/ not accessible.

Possible reason:

Submitted by Tobias Wilken <tw@cloudcontrol.com>

This domain @cloudcontrol.com still has MX records, so this email address is probably still accessible.

Recommend to email Tobias Wilken <tw@cloudcontrol.com> to confirm if they can be safely removed from the PSL?

Sources:

_psl TXT Record

Responses from multiple DNS servers for the _psl TXT record of the domain:

Response from 8.8.8.8: empty

Response from 1.1.1.1: empty

Response from 208.67.222.222: empty

Sources: dig command using DNS servers: Google (8.8.8.8), Cloudflare (1.1.1.1), OpenDNS (208.67.222.222)

Root-level Domain Usage Scan

As a potential indicator of domain usage, we scan the following records:

NS records (cloudcontrolapp.com) returns ns3.inwx.eu. ns.inwx.de. ns2.inwx.de.

Additionally, we scan the following records for possible website usage at the root level:

A record (cloudcontrolapp.com) returns 185.181.104.242

A record (www.cloudcontrolapp.com) returns 185.181.104.242

MX records (cloudcontrolapp.com) returns empty

Sources: dig command for A, NS, and MX records

Search Engine Checks

For possible website usage, we queried multiple different search engines:

image image image image image

Sources:

Subdomain Discovery

For potential usage of subdomains that are not discovered by the search engines, we used the following tools and here are the obtained observations:

No subdomain found.

image image

Sources:

crt.sh Certificate Transparency Logs

For potential website usage of subdomains that are not discovered by the search engines, we checked the Certificate Transparency Logs and here are the obtained observations:

No valid cert found.

image

Sources:

VirusTotal Check

To check for possible security issues, we used VirusTotal and here are the obtained observations:

Clean

image image

Sources:

cloudcontrolled.com:

WHOIS

PSL submission on 2013-07-23. Per WHOIS, Creation Date: 2009-01-04T21:21:31Z, which indicates that this domain is possibly still under control of original requester if it hadn't been transferred.

Please read the original WHOIS records below:

   Domain Name: CLOUDCONTROLLED.COM
   Registry Domain ID: 1536011968_DOMAIN_COM-VRSN
   Registrar WHOIS Server: whois.domrobot.com
   Registrar URL: http://www.inwx.com
   Updated Date: 2024-07-25T07:06:52Z
   Creation Date: 2009-01-04T21:21:31Z
   Registry Expiry Date: 2025-01-04T21:21:31Z
   Registrar: INWX GmbH
   Registrar IANA ID: 1420
   Registrar Abuse Contact Email: abuse@inwx.com
   Registrar Abuse Contact Phone: +49.30983212123
   Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
   Name Server: NS1.EXOSCALE.CH
   Name Server: NS1.EXOSCALE.COM
   Name Server: NS1.EXOSCALE.IO
   Name Server: NS1.EXOSCALE.NET
   DNSSEC: unsigned
   URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of whois database: 2024-07-26T02:53:02Z <<<

Sources: whois utility generated at 2024-07-25 22:53:31

Organization Website and Nature Check

Same as above

_psl TXT Record

Responses from multiple DNS servers for the _psl TXT record of the domain:

Response from 8.8.8.8: empty

Response from 1.1.1.1: empty

Response from 208.67.222.222: empty

Sources: dig command using DNS servers: Google (8.8.8.8), Cloudflare (1.1.1.1), OpenDNS (208.67.222.222)

Root-level Domain Usage Scan

As a potential indicator of domain usage, we scan the following records:

NS records (cloudcontrolled.com) returns ns1.dnsimple.com. ns2.dnsimple-edge.net. ns3.dnsimple.com. ns4.dnsimple-edge.org.

Additionally, we scan the following records for possible website usage at the root level:

A record (cloudcontrolled.com) returns empty

A record (www.cloudcontrolled.com) returns empty

MX records (cloudcontrolled.com) returns empty

Sources: dig command for A, NS, and MX records

Search Engine Checks

For possible website usage, we queried multiple different search engines:

image image image image image

Sources:

Subdomain Discovery

For potential usage of subdomains that are not discovered by the search engines, we used the following tools and here are the obtained observations:

image image

Sources:

crt.sh Certificate Transparency Logs

For potential website usage of subdomains that are not discovered by the search engines, we checked the Certificate Transparency Logs and here are the obtained observations:

All expired

image

Sources:

VirusTotal Check

To check for possible security issues, we used VirusTotal and here are the obtained observations:

image image

Sources:

simon-friedberger commented 1 month ago

@brutasse Ideally, you would add a _psl TXT record referencing this PR to let us know you have authority.

If you want I can ask for confirmation by mail to tw@cloudcontrol.com. Can you receive it and reply to confirm?

brutasse commented 1 month ago

@brutasse Ideally, you would add a _psl TXT record referencing this PR to let us know you have authority.

Thanks @simon-friedberger, done:

$ dog _psl.cloudcontrolapp.com TXT
TXT _psl.cloudcontrolapp.com. 1h00m00s   "https://github.com/publicsuffix/list/pull/2072"
$ dog _psl.cloudcontrolled.com TXT
TXT _psl.cloudcontrolled.com. 1h00m00s   "https://github.com/publicsuffix/list/pull/2072"

If you want I can ask for confirmation by mail to tw@cloudcontrol.com. Can you receive it and reply to confirm?

The email will bounce. Is it enough with the TXT records?