Английская Википедия:Doppelganger domain

Материал из Онлайн справочника
Перейти к навигацииПерейти к поиску

Шаблон:Short description Шаблон:One source A doppelganger domain is a domain spelled identical to a legitimate fully qualified domain name (FQDN) but missing the dot between host/subdomain and domain, to be used for malicious purposes.

Overview

Typosquatting's traditional attack vector is through the web to distribute malware or harvest credentials. Other vectors such as email and remote access services such as SSH, RDP, and VPN also can be leveraged. In a whitepaper by Godai Group on doppelganger domains, they demonstrated that numerous emails can be harvested without anyone noticing.[1]

Example

For email address "ktrout@fiШаблон:Shynance.corpuШаблон:Shydyne.com", the doppelШаблон:Shyganger domain would be "financeШаблон:ShycorpuШаблон:Shydyne.com"; hence, an email acciШаблон:ShydenШаблон:Shytally addressed to "ktrout@financecorpudyne.com" (i.e.Шаблон:Nbswith the dot between "finance" and "corpuШаблон:Shydyne" having acciШаблон:ShydenШаблон:Shytally been omitted) would go to the doppelШаблон:Shyganger domain rather than to the legitimate user.

See also

References

Шаблон:Reflist

External links

Шаблон:Domain parking


Шаблон:Internet-stub Шаблон:Malware-stub