Networking-Forums.com

Professional Discussions => Security => Topic started by: deanwebb on March 16, 2016, 10:16:38 AM

Title: Type carefully, my friends...
Post by: deanwebb on March 16, 2016, 10:16:38 AM
http://www.scmagazine.com/endgame-exposes-malware-that-punishes-poor-spelling/article/483371/

1. Find a popular website
2. register a domain name for {popular website}c.om
3. wait for people to type in the name of the popular domain, then type c.om instead of .com
4. ????
5. PROFIT!
:problem?:

turns out #4 is "set up a website that pushes malware to the browser of the person making a typo"

Welcome to the world of typosquatting.
Title: Re: Type carefully, my friends...
Post by: icecream-guy on March 16, 2016, 11:17:29 AM
Quote from: deanwebb on March 16, 2016, 10:16:38 AM
http://www.scmagazine.com/endgame-exposes-malware-that-punishes-poor-spelling/article/483371/

1. Find a popular website
2. register a domain name for {popular website}c.om
3. wait for people to type in the name of the popular domain, then type c.om instead of .com
4. ????
5. PROFIT!
:problem?:

turns out #4 is "set up a website that pushes malware to the browser of the person making a typo"

Welcome to the world of typosquatting.

may value idea was to register popular domain names with ,com added to the end, with the benefit of the browser adding .com to the end, users mistype , instead of . ( i do it all the time) so user goes to networking-forums,com and goes to networking-forums,com.com and all he77 breaks loose.
Title: Re: Type carefully, my friends...
Post by: Otanx on March 16, 2016, 11:37:59 AM
I don't think a comma is an allowed character in a domain name, but I like the way you think. A side bonus would be all the failures that would be caused by scripts incorrectly parsing csv files, etc.

-Otanx
Title: Re: Type carefully, my friends...
Post by: Dieselboy on March 16, 2016, 07:44:19 PM
When i was in high school a kid in the library accidentally mistyped yahoo.com and ended up at a porn site.

For reasons like this I'm glad I've now got firepower in our asas.

(I've tried to find what he accidentally typed but no joy)
Title: Re: Type carefully, my friends...
Post by: Reggle on March 17, 2016, 01:49:51 AM
I'm considering DNS blackholing .om here now, it's not like I'd ever visited that TLD on purpose.

Also, just as scary: bitsquatting. http://dinaburg.org/bitsquatting.html
Title: Re: Type carefully, my friends...
Post by: deanwebb on March 17, 2016, 09:40:52 AM
Yep, there's no good on .om.

Then there was the malware campaign that hijacked ads on BBC, Newsweek, and The New York Times. Adblocker FTW.