Discussion in 'privacy technology' started by TheWindBringeth, Mar 2, 2013.

  TheWindBringeth

    TheWindBringeth Registered Member

    Feb 29, 2012
    Best title I could think of, here is what I mean...

    The page at [noparse]http://www.example.com/[/noparse] has content from svr1.example.com, which may be a machine run by the example.com folks who you think trustworthy, or it may be a machine run by someone else that you think untrustworthy and want to block. A few examples:

    1) svr1.example.com has an A record of XXX.XXX.XXX.XXX, rDNS for which is someadnetwork.com.

    2) svr1.example.com has a CNAME of someadnetwork.com, rDNS lookup of someadnetwork.com's IP Address fails so #1 won't catch this.

    3) [noparse]www.example.com[/noparse] has an address of X.X.X.X, svr1.example.com has no CNAME and an A record of Y.Y.Y.Y, the rDNS of Y.Y.Y.Y is svr1.example.com. So previous two checks won't throw up a red flag but seeing X.X.X.X and Y.Y.Y.Y being different class A's or B's, maybe even C's, would draw your attention to what may be a case of svr1.example.com being operated by someadnetwork.com folks.

    Has anyone seen a FF addon that helps to check for such things? Perhaps something that dumps requests like Web Console but with a column and/or color warning to alert you to items of interest?
