PayPal updated their terms and conditions / acceptable use policy, which caused an internet rage fest, and appears to now have been repealed.
Note that PayPal is odd in that it has registered (and uses) domains of the form "paypal*.com", eg. paypalobjects.com where it publishes its AUP, and paypalcommunication.com for email.
reg() { whois $1 | grep Registrant.Org || echo not found; }
reg paypalobjects.com
Registrant Organization: PayPal Inc.
reg paypalcommunication.com
Registrant Organization: PayPal Inc.
reg paypalpolicy.com
Registrant Organization: PayPal Inc.
reg paypaldocuments.com
not found
This seems like it makes phishing easier since anyone could register paypaldocuments.com and serve evil from there. How are we to know that paypalobjects.com was authored by PayPal? There is nothing in their DNS records that ties it back to paypal.com.
q() { dig "$@" | sed 's/[^ \t-]\{32,\}/.../g' | fmt -t; }
for t in soa a txt ns ; do
q +noall +answer $t paypalobjects.com
done
paypalobjects.com. 300 IN SOA
ppdns.paypal.com. hostmaster.paypal.com. 2008113266 7200 600 1209600
300
paypalobjects.com. 194 IN A 64.4.250.38
paypalobjects.com. 194 IN A 64.4.250.39
paypalobjects.com. 300 IN TXT "_globalsign-domain-...
paypalobjects.com. 300 IN TXT "_globalsign-domain-...
paypalobjects.com. 300 IN TXT
"google-site-...-JNKqxxY8LSxtbsRg"
paypalobjects.com. 300 IN NS pdns100.ultradns.com.
paypalobjects.com. 300 IN NS ns1.p57.dynect.net.
paypalobjects.com. 300 IN NS ns2.p57.dynect.net.
paypalobjects.com. 300 IN NS pdns100.ultradns.net.
The only reference to paypal.com is via the SOA record's MNAME, except that it's
a hidden master and isn't queriable.
q paypalobjects.com @ppdns.paypal.com dig: couldn't get address for 'ppdns.paypal.com': not found
Looking at the EV cert at https://paypalobjects.com -- none of the domains are paypal.com.
openssl s_client -connect paypalobjects.com:443 < /dev/null |
sed -n '/BEGIN.CERT/,/END.CERT/ p' |
openssl x509 -text -noout -in - |
sed -n '
/Subject:/ { s/.*CN = //; p}
/Subject.Alter/,/Key.Usage/ { /DNS:/! d; s/DNS://g; s/, /\n/g; p }' |
tr -d ' ' | sort | fmt
paypal.at paypal-australia.com.au paypal.be paypalbenefits.com
paypal-businesscenter.com paypal-business.com.au paypal-business.co.uk
paypal.ca paypal.ch paypal.cl PAYPAL.CO paypal.co.id paypal.co.il
paypal.co.in paypal.com.ar paypal.com.au paypal.com.br paypal.com.cn
paypal.com.hk paypal-communications.com paypal-community.com
paypal.com.mx PAYPAL.COM.MY paypal.com.pe paypal.com.sa paypal.com.sg
paypal.com.tr paypal.com.tw paypal.com.ve paypal.co.nz paypal.co.th
paypal.co.uk paypal.co.uk paypal.co.za paypal-danmark.dk
paypal.de PAYPAL-DEUTSCHLAND.DE paypal.dk paypal-donations.com
paypal-donations.co.uk paypal.es paypal.eu paypal.fi paypal.fr
paypal-gifts.com paypalgivingfund.org paypal-globalshops.com paypal.ie
paypal.in paypal-information.com paypal.it paypal.jp paypal-knowledge.com
paypal-knowledge-test.com paypal-latam.com paypal.lu paypal-marketing.ca
paypal-marketing.co.uk PAYPAL-MARKETING.PL paypal.me paypal-media.com
paypal-mena.com paypal-mktg.com paypal-nakit.com paypal.nl paypal.no
paypal-norge.no paypalobjects.com paypal-optimizer.com paypal-partners.com
paypal-passport.com paypal.ph paypal.pl paypal-prepagata.com
paypal-promo.es paypal.pt paypal.se paypal-sverige.se paypal-turkiye.com
paypal.vn thepaypalblog.com
At points like these, towels are thrown....