866.936.7447    231.932.0411
Traverse Legal: Attorneys and Advisors - Global Representation of Business InterestsOur attorneys have represented, handled matters and litigated cases against companies located across the globe
Internet LawIntellectual PropertyDomain DisputesCorporate ServicesComplex LitigationHome | About Us | Contact 

« WIPO Decisions Under the UDRP For Feb 19, 2008 | Main | Data Shows That Phishing Attacks & Cybersquatting Abuse Continued to Rise Through 2007 »

2008.02.22

Typo-Domains Pose an Email Security Threat: Users Also Mistype Domains in Email Addresses

Companies and political organizations should put more effort into registering mis-typed versions of their primary domain, not only to protect visitors to their Web sites but also to prevent e-mails from accidentally leaking out, a security researcher said on Wednesday.

As part of his investigation, Friedrichs registered 124 domains consisting of common misspellings of the primary domains of candidates in the U.S. presidential election. In a strictly controlled experiment, Friedrichs used a mail server to count the number of e-mail messages sent to the misspelled domains, finding 1,121 connection attempts from 12 distinct IP addresses in a 24-hour period. Friedrichs stressed that he did not look at the e-mails and bounced the messages back to the sender to let them know they had misspelled the address.

"It is not clear what is going on here," Friedrichs told attendees. "But if someone sends an e-mail to that company, and makes a typo, the owner of the (fraudulent) domain is going to get the information."

Typosquatting has generally been considered more of a nuisance than a security threat. In 2003, VeriSign caused a stir when it started redirecting queries for nonexistent domain names, likely due to misspellings, to a page controlled by the company. Frausters frequently use domain names that have spellings close to that of a major brand to fool potential victims into believing that the fake site is legitimate.

More here and here.

Typosquatting, the registering of common misspellings of domain names, could be used by rivals in election campaigns as well as competing companies as a way of advertising to rivals' customers, Oliver Friedrichs, the director of emerging technologies at security firm Symantec, told attendees at the Black Hat DC 2008 security conference. (Symantec is the owner of SecurityFocus.) An investigation of the common misspellings of two defense contractors' names uncovered typosquatted domains registered in China and India, he said. While the domain registered in India did not have a Web server or mail server handling traffic to the misspelled domain, a mail server was set to receive e-mail sent to the domain registered in China.

"It is not clear what is going on here," Friedrichs told attendees. "But if someone sends an e-mail to that company, and makes a typo, the owner of the (fraudulent) domain is going to get the information."

As part of his investigation, Friedrichs registered 124 domains consisting of common misspellings of the primary domains of candidates in the U.S. presidential election. In a strictly controlled experiment, Friedrichs used a mail server to count the number of e-mail messages sent to the misspelled domains, finding 1,121 connection attempts from 12 distinct IP addresses in a 24-hour period. Friedrichs stressed that he did not look at the e-mails and bounced the messages back to the sender to let them know they had misspelled the address.

Typosquatting has generally been considered more of a nuisance than a security threat. In 2003, VeriSign caused a stir when it started redirecting queries for nonexistent domain names, likely due to misspellings, to a page controlled by the company. Frausters frequently use domain names that have spellings close to that of a major brand to fool potential victims into believing that the fake site is legitimate.

E-mail servers set up to server misspelled domain names could allow targeted e-mail attacks to be more convincing and could capture sensitive e-mail messages sent to a misspelled address, Friedrichs said.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d834208fd253ef00e5507940058834

Listed below are links to weblogs that reference Typo-Domains Pose an Email Security Threat: Users Also Mistype Domains in Email Addresses:

Comments

Typosquatting is a form of cybersquatting which relies on mistakes such as typographical errors when inputting a website address into the address bar of a web browser. This is also referred to as direct navigation.

hello there, I am interested in the Typosquatting matter. What's happened if I buy a misspelled domain of a company X and I redirect the domain to the affiliate program page of the X company having has result to forward the users to the same company page but getting a commission on eventual sales?

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

Recent Comments

Traverse Legal, PLC | 810 Cottageview Dr., G20, Traverse City, MI, 49684
(West Coast Office) 16830 Ventura Boulevard Suite 358, Los Angeles (Encino), CA 91436-1707
Maryland Office: 22776 Three Notch Rd. ,Suite 201, Lexington Park, MD.
231-932-0411 (phone) | 866-936-7447 (toll free) | 231-932-0636 (fax)
web site design by nielsen design group | architecture and implementation by leelanau.com