Account Names Blacklist
blog.7sheep.net
blog.7sheep.net
For example, training.7sheep.net is an official subdomain, but I could create docs.7sheep.net and make it look like an official subdomain and request peoples account information or do other bad things. GitHub ran into the same problem when they started supporting GitHub pages. Originally these were subdomains off of github.com, but after all the spoofing and other issues they moved them all to github.io. This way you never need to create a list of 'reserved' names and don't need to worry about confusion down the road.
You can read about GitHub's transition and reasoning at https://github.com/blog/1452-new-github-pages-domain-github-....
The separate domain is a good advice, but I'd rather use something really different (e.g. github-user.com) if I was to let anyone post anything they wanted there.
Neither did I; but a browser does make the distinction. It is a security separation.
I think this passage is the main reason for the GitHub switch: «Because Pages sites may include custom JavaScript and were hosted on github.com subdomains, it was possible to write (but not read) github.com domain cookies»
This is well know cookie security problem: if you have live at x.example.co.uk you can set cookies for example.co.uk and co.uk itself. This is usually evident in organizations like universities that let their departments have their own subdomains run by different software. Usually the root domain contains dozens of unrelated cookies.
Mozilla is addressing this with the public suffix list [1], but I think a more solid solution is needed.
Overall, I'd advise against giving subdomains to users, too.
[1] http://www.quora.com/How-do-sites-prevent-vanity-URLs-from-c... [2] https://encrypted.google.com/search?hl=en&q=search%20github%... [3] https://github.com/nccgroup/typofinder/blob/f0fe2ac4e5181746... [4] https://github.com/sandeepshetty/subdomain-blacklist/blob/ma... [5] https://gist.github.com/artgon/5366868
login promotion promo secure legal terms bonus free contact
Or how about mispellings good for phishing?
biling biIIing
etc etc
Pay very great heed to the people advising a separate domain for user generated names.
Sometimes a scrolling page just works :)
Amusingly, you missed "www" off your blacklist. I just created an account to test it. Luckily it hasn't hijacked your main site - but I also can't use my account :)
sometimes you can't see the wood for the trees …
Or, depending on volume, having manual validation of names.
Do you really want porn.7sheep.net?