Now that the ICANN is allowing custom Top Level Domain names and often corporate IT workers like to use .local
as the TLD for internal networks, if someone does buy the .local TLD what are some possible dangers a user could encounter?
The main example I can think of is spear-phishing attacks. If a company has computers like SuperSecureServer.local
on their LAN and a malicious attacker makes TotallyARealCorporateServer.local
would TotallyARealCorporateServer.local
resolve to the attackers IP? If it did, the attacker could send a bad link then could impersonate a real server and get domain login credentials.