attacker-controlled-site.com
Reading

Articles

  1. Dangling references: domains still wired into your systems

    SPF includes, OAuth callbacks, webhooks and package metadata all name domains. Some of those names are no longer controlled by anyone you trust.

    2026-07-25
  2. I registered the domain from the security tutorials

    attacker-controlled-site.com sat in advisories and documentation for years while staying publicly registrable. What I found, and what I chose not to build.

    2026-07-25
  3. Who actually owns evil.com and the other tutorial domains

    evil.com has been registered since 1995, hacker.com since 1994. We checked eighteen placeholder domains from security writing. All eighteen are owned.

    2026-07-25
  4. Use .example, .test and .invalid — the RFC everyone ignores

    Standards reserve four names so documentation never points at a domain someone can buy. What to use instead, and the places people forget.

    2026-07-24