4 ms·
Practical waterholing through DNS typosquatting
- HappyTypist 9y agoAnother interesting approach is rely on cosmic background noise bit flips. Do it on Google.com and you can get a few thousand visitors a week I.e. Register a domain where the ASCII representaton is 1 bit off.
- gruez 9y agoBitsquatting
- YouKnowBetter 9y agoThe original idea has a better name: Bitsquatting[0] "Experiment To determine whether bit7errors can redirect connections to attacker controlled sites, the bitsquat domains in Table 3 were registered, and all HTTP requests to the domains were logged. The domains, such as li6e.com, mic2osoft.com, and fjcdn.net are very unlikely to be typos or keyboard errors." [0] https://media.blackhat.com/bh-us-11/Dinaburg/BH_US_11_Dinaburg_Bitsquatting_WP.pdf https://media.blackhat.com/bh-us-11/Dinaburg/BH_US_11_Dinabu...
- eru 9y agoThanks! That's brilliant.
- x0rz 9y agoYep, bitsquatting is also a very cool thing, first research on that topic was in 2011 IIRC :) Typosquatting = human error Bitsquatting = machine error (bitflip)
- brak1 9y agoISnt it more likely that it is just bots, that know your domain cos they have lists of every domain for that tld?
- jfaat 9y agos/Ethipia/Ethiopia
- tyingq 9y agoDidn't mention spinning up an SMTP server on the domain. That might catch some interesting info.
- SubiculumCode 9y agoInteresting. Tell me, is the affiliate stuff mentioned in the article actually illegal?
- eridius 9y agoIt's almost certainly against the TOS for the affiliate program in question.
- Bartweiss 9y agoThinking about high-profile domains: there are no close attacks on .gov (.gop is closest), but .mil is subject to both .mit (not so close) and .ml (Mali, quite close) attacks.
- chiefalchemist 9y agoHard to believe that many big traffic sites haven't bothered to snatch up any/all similar domains.