dotPH and Wildcard Abuse
In the world of cybersecurity, typosquatting is a fairly boring but effective attack strategy. If you can find an available domain within close proximity (either visually or by qwerty layout standards) to a target website, you are pretty much guaranteed to trick someone eventually. You don't need to actively do much after registering it either - humans are fallible and, given enough time, will typo their way onto your domain. So it goes without saying, it would be incredibly shady for any official body of the internet, say, the official domain name registry of the Philippines, to engage in such a practice.
I first discovered this dodgy behaviour when investigating an alert regarding a domain impersonation. Through periodic fraud intel, we were told OurCompanyName.ph had been registered. Upon investigation - it did seem like a server was linked to the domain.

The ad provider being ParkLogic. This company is owned by fellow Aussie, CEO Michael Gilmour. I'd take screenshots of the ads, but I'd rather not give views to the various gambling, adult sites, and 'free iphone giveaway' forms. If you want to test your luck, you can try heading on over to router.parklogic.net yourself and giving it a spin. It's kind of a lucky dip whether you'll get redirected to a strangely vague google search, get some Service Worker adware from an article slop website, or end up being flashed. Which is kind of Michael's intent I believe. According to ParkLogic's website, it seems their main selling point is a vast ad feed, dynamically choosing the 'winning' ad to serve. From an advertising perspective, it seems win-win given it causes the companies advertising to remain competitive with one another, and allows maximum ad revenue for the target site. Unfortunately, the win doesn't usually translate to the user's experience.

Once I'd worked out we likely had a true positive typosquatting incident on our hands, I went to find the details about the culprit. That's when I ran into some difficulties.

Nothing from WHOIS. And this is through the official dotPH registry. Just to be safe, I did try all other WHOIS services I could find, however no WHOIS record was identified.
Not to worry - WHOIS is old news

No luck either for RDAP, regardless of which service I tried. That's super weird. It has an IP address, surely someone must have control over it's DNS entries. Let's look closer at what other records exist for it.
Ok what the hell? It's got records used in DNSSEC. And recently too, those records indicate they were set only in the last few days. Surely someone is controlling this domain. And this is the .ph nameserver giving me these answers, I'm not being fed poisoned answers from a bogus DNS server. Remembering back to when I visited the site on my browser and was shown more skin than I'd asked for, I didn't recall seeing a "this website is insecure" warning. Sure enough, checking the site again, it had a valid and recent TLS cert.
Issued To
Issued By
Validity Period
At this point, I made the mistake of assuming dotPH was doing a poor job in maintaining their WHOIS service. A closer look, however, showed that it wasn't some random bad actor that was squatting the domain. It was dotPH themselves.
Did dotPH get hacked? Surely a respectable TLD wouldn't throw away the concept of NXDOMAIN responses for some revenue.

Damn. That dotph-nxd domain name and nxdTemplate value from the page js sure does look intentional from ParkLogic's side. But maybe someone impersonating dotPH struck the deal with ParkLogic? I'm not sure how comprehensive an advertiser's KYC might be.

Oh hang on, there's this 50 minute long podcast Michael did with dotPH CEO Joel Disini
A TLD intentionally choosing to serve everybody ads on every typo? It seems awfully money-hungry. It also doesn't seem like it respects the core principles of the internet. Surely if it was allowed by governing bodies like ICANN, every TLD ever would do it by the laws of enshittification...
Introducing: the Site Finder debacle
Site Finder was a service run by the registry VeriSign that did pretty much that. Way back in 2003, they created a wildcard DNS record for all of .com and .net. It was such an infamous incident that it has it's own Wikipedia page
As a result of this debacle, ICANN (and SSAC) have published multiple pieces over the years explaining why this practice causes harm.

Unfortunately, from what I've found online, it seems ICANN doesn't have as much jurisdiction over ccTLDs as it does over gTLDs like VeriSign. While they strongly argue against it, it seems ccTLDs are not forced in any meaningful way to conform.
I don't understand how people can sell their integrity so cheaply- Michael Gilmour, Conversations - Joel Disini [44:10]
It'll be interesting to see how this continues to play out. From reading up on Joel, it sounds like the world of TLDs is fraught with politics. Having crawled through hours of DotAsia board meetings and details on lawsuits and corruption, I would have loved to play pretend investigative journalist and give a whole exposé on the hidden world of the people overseeing the internet. But honestly the more I read, the messier it all appears, and the more scared I become that talking about any of it would lead to a lawsuit of my own. If you want to waste a few hours piecing it together yourself, you're free to go through the further reading resources.

Already now, there has been some development. Instead of the ParkLogic page redirecting straight to a random advert, you now have to click through some buttons to reach the same ads. Still a violation of ICANN recommendations, but less egregious. I wonder if it was dotPH or ParkLogic that was strongarmed into changing that. My hope is stronger regulation is forced upon the ccTLDs - otherwise bodies like dotPH may continue to gradually push the envelope further.