7 ms·
As others have mentioned this is likely one of a couple of scenarios, roughly ordered by my guess on likelihood: - Attempting to use your legitimate content an
by TrueDuality 2y ago
As others have mentioned this is likely one of a couple of scenarios, roughly ordered by my guess on likelihood:
- Attempting to use your legitimate content and services to improve the SEO rank of other domains (even unrelated ones). This can usually be checked by looking for a sitemap.xml, there will be pages not redirected to your site that contain pages of links.
- Closely following the above, the pages may not be links to other sites but might be hosting phishing pages for other services unrelated to yours. The redirect here acts as a bluff for casual inspection of the domain. You won't see page entries in a sitemap.xml file for these ones.
- Attempting to "age" a domain. Not many talk about this option, but new domains are a red flag to a lot of automated security processes. When purchasing a domain and giving it a history associated with a legitimate service they make the domain look less suspicious for future malicious use.
- Preparation for a targeted campaign. This is pretty unlikely, you need to be really worth a dedicated long term campaign effort specifically against you or your company. If you're doing controversial/novel research, are managing millions of dollars, performing a service a state actor would object to, or have high profile clientele then maybe you fall into this category. These are patient campaigns and want to make the domain "feel normal and official". They won't do anything public with the domain such as SEO tweaking or link spam, they'll use these domains only for specific targeted one-off low-noise attacks. They're relying on staff to see that the domain has been connected to your service for years and is likely just a domain someone in marketing purchased and forgot about. This is exceptionally rare.
- meigwilym 2y agoI think the first one is pretty likely. OP, you can search for "site:getexample.com" which will list you any pages that have been indexed for that domain. They might have just redirected the homepage. Worth a shot.
- timewizard 2y agoI would expect the certificate mismatch to prevent this.
- maltelandwehr 2y agoThe certificate mismatch does not play any role in this SEO tactic. It just is not a factor.
- timewizard 2y agoI was thinking of CNAMEs.
- dccoolgai 2y agoIt could be a combo of 1 and 3: a competitor (or someone who thinks they might be in the future) ages those domains, then points it to their own product later.
- TrueDuality 2y agoThis is another great call-out and semi-common. I can definitely get blinded by my security focus but shady business tactics drive a lot of these similar domain purchases for exactly the reason you described.
- IncreasePosts 2y agoRegarding point two, OP should connect to a VPN in Japan or somewhere he very isn't, use incognito mode, and see if the same content is served. I've seen hacked sites that are set up to serve normal content to where the attacker thinks the owner of the site lives, but serve phishing content or malware or whatever to everywhere else. A 301 fits that bill because then the owners browser even when traveling will serve the good content
- TrueDuality 2y agoYeah this is a good call-out. If the site is being used for drive-by or targeted malware there are other checks that may be happening alongside the redirect such as user agent, country of origin (like you mentioned), plugins installed, OS, or even time of day. If they detect something that matches what they want, they may throw some intermediate 301's to pages that attempt to infect the user with something still ultimately redirecting to the "normal" page.
- SlightlyLeftPad 2y agoJust a note 301s are super sticky and browsers cache them even across incognito modes. Your best bet is to use a new browser after reconnecting to avoid false results.
- nneonneo 2y agoReally? That seems like a fantastic way to fingerprint people. I would be a bit surprised if that was the case... (Fingerprint usage: have https://myfingerprint.example.com https://myfingerprint.example.com 301 to https://myfingerprint.example.com/unique_id_3b136c1cb https://myfingerprint.example.com/unique_id_3b136c1cb, then embed https://myfingerprint.example.com https://myfingerprint.example.com in an iframe and see which request is made.)
- kqr 2y agoI'm not GP but a decade ago when I started out as a web developer I made the mistake of using 301s in production and at the time we never figured out how to get the browser to re-learn the responses for those pages without drastic measures. I still never use 301s for that reason. Things may have changed, but I dare not try!
- tracker1 2y agoI'd add canonical link elements to your html and http headers in order to reduce the chances of subversion somehow. The whole thing feels really weird to me.
- HenryBemis 2y agoBait and switch? Get users t bookmark the joinexample.com, and the others, and once they notice that people keep going to your side via their domain names, they will switch, make a fake "change password" and will be ripped off.
- naveensky 2y agoone another scenario is that if you open the domain from browser, they will do 301 redirect, but for traffic coming from Google/search engine, they will show their actual content.
- maltelandwehr 2y agoIf this is done with SEO in mind, at first they will also do a redirect for Google Bot. Then they build links to their domains. Once it has more backlinks than the real domain, the redirect is removed.
- welder 2y agoI'll add another scenario I've personally experienced: - Reaching out in good-faith with an offer to sell the domain to you. I've had that happen in the past and before receiving the email the person directed the domain to my official website to show good will. I purchased the domain and now own it. Not saying this is the case here, but just wanted to throw a legitimate scenario into the mix. They should have reached out by now if this was the case.
- xg15 2y agoJust speculating here, but would it be possible that the redirecting domains could actually overtake the original site in terms of search rank, etc? If yes, this could be preparation for a semi-targeted phishing campaign: 1) set up plausibly-named fake domains that redirect to example.com 2) ensure that the fake domains rank higher than the original domain for "example" searches. 3) after a while, people have gotten used to accessing the service through the fake domains or might even think those are the official domains. 4) pull up the net by replacing the redirect with phishing pages. Suddenly, everyone googling for the service will end up on a phishing site, without any obvious way to fix the situation. Phishers could also run this scheme for lots of sites in parallel, without needing to have some specific interest in any of them. Edit: Seems like the semantics of the 301 redirect should prevent this from working though.