Typosquatting (Firefox 74)
   HOME

TheInfoList



OR:

Typosquatting, also called URL hijacking, a sting site, or a fake URL, is a form of
cybersquatting Cybersquatting (also known as domain squatting) is the practice of registering, trafficking in, or using an Internet domain name, with a bad faith intent to profit from the goodwill of a trademark belonging to someone else. The term is derived ...
, and possibly brandjacking which relies on mistakes such as
typos A typographical error (often shortened to typo), also called a misprint, is a mistake (such as a spelling mistake) made in the typing of printed (or electronic) material. Historically, this referred to mistakes in manual type-setting (typography). ...
made by Internet users when inputting a website address into a
web browser A web browser is application software for accessing websites. When a user requests a web page from a particular website, the browser retrieves its files from a web server and then displays the page on the user's screen. Browsers are used o ...
. Should a user accidentally enter an incorrect website address, they may be led to any URL (including an alternative website owned by a cybersquatter). The typosquatter's URL will usually be one of five kinds, all ''similar to'' the victim site address: *A common misspelling, or foreign language spelling, of the intended site *A misspelling based on a typographical error *A plural of a singular domain name *A different
top-level domain A top-level domain (TLD) is one of the domains at the highest level in the hierarchical Domain Name System of the Internet after the root domain. The top-level domain names are installed in the root zone of the name space. For all domains in ...
: (i.e. .com instead of .org) *An abuse of the
Country Code Top-Level Domain A country code top-level domain (ccTLD) is an Internet top-level domain generally used or reserved for a country, sovereign state, or dependent territory identified with a country code. All ASCII ccTLD identifiers are two letters long, and all ...
(ccTLD) (.cm, .co, or .om instead of .com) Similar abuses: *Combosquatting - no misspelling, but appending an arbitrary word that appears legitimate, but that anyone could register. * Doppelganger domain - omitting a period or inserting an extra period *Appending terms such as ''sucks'' or -' to a domain name Once in the typosquatter's site, the user may also be tricked into thinking that they are in fact in the real site, through the use of copied or similar logos, website layouts, or content. Spam emails sometimes make use of typosquatting URLs to trick users into visiting malicious sites that look like a given bank's site, for instance. Magniber ransomware are being distributed in a typosquatting method that exploits typos made when entering domains, targeting mainly Chrome and Edge users.


Motivation

There are several different reasons for typosquatters buying a typo domain: *In order to try to sell the typo domain back to the brand owner *To
monetize Monetization (American and British English spelling differences, also spelled monetisation) is, broadly speaking, the process of converting something into money. The term has a broad range of uses. In banking, the term refers to the process of co ...
the domain through
advertising Advertising is the practice and techniques employed to bring attention to a product or service. Advertising aims to put a product or service in the spotlight in hopes of drawing it attention from consumers. It is typically used to promote a ...
revenues from direct navigation misspellings of the intended domain *To redirect the typo-traffic to a competitor *To redirect the typo-traffic back to the brand itself, but through an affiliate link, thus earning commissions from the brand owner's affiliate program. *As a
phishing Phishing is a type of social engineering where an attacker sends a fraudulent (e.g., spoofed, fake, or otherwise deceptive) message designed to trick a person into revealing sensitive information to the attacker or to deploy malicious softwa ...
scheme to mimic the brand's site, while intercepting passwords which the visitor enters unsuspectingly *To install drive-by malware or revenue generating
adware Adware, often called advertising-supported software by its developers, is software that generates revenue for its developer by automatically generating online advertisements in the user interface of the software or on a screen presented to the ...
onto the visitors' devices *To harvest misaddressed e-mail messages mistakenly sent to the typo domain *To express an opinion that is different from the intended website's opinion *By legitimate site owners: to block malevolent use of the typo domain by others *To annoy users of the intended site


Examples

Many companies, including
Verizon Verizon Communications Inc., commonly known as Verizon, is an American multinational telecommunications conglomerate and a corporate component of the Dow Jones Industrial Average. The company is headquartered at 1095 Avenue of the Americas ...
, Lufthansa, and Lego, have gained reputations for aggressively chasing down typosquatted names. Lego, for example, has spent roughly US$500,000 on taking 309 cases through
UDRP The Uniform Domain-Name Dispute-Resolution Policy (UDRP) is a process established by the Internet Corporation for Assigned Names and Numbers (ICANN) for the resolution of disputes regarding the registration of internet domain names. The UDRP curren ...
proceedings. Celebrities have also frequently pursued their domain names. Prominent examples include basketball player Dirk Nowitzki's UDRP of DirkSwish.com and actress Eva Longoria's UDRP of EvaLongoria.org. Goggle, a typosquatted version of
Google Google LLC () is an American Multinational corporation, multinational technology company focusing on Search Engine, search engine technology, online advertising, cloud computing, software, computer software, quantum computing, e-commerce, ar ...
, was the subject of a mid-2000s web safety promotion by
McAfee McAfee Corp. ( ), formerly known as McAfee Associates, Inc. from 1987 to 1997 and 2004 to 2014, Network Associates Inc. from 1997 to 2004, and Intel Security Group from 2014 to 2017, is an American global computer security software company head ...
, which depicted the significant amounts of malware installed through
drive-by downloads Drive-by download is of two types, each concerning the unintended download of computer software from the Internet: # Authorized drive-by downloads are downloads which a person has authorized but without understanding the consequences (e.g. down ...
upon accessing the site at the time. Later the URL redirected to google.com; a 2018 check revealed it to redirect users to
adware Adware, often called advertising-supported software by its developers, is software that generates revenue for its developer by automatically generating online advertisements in the user interface of the software or on a screen presented to the ...
pages, and a 2020 attempt to access the site through a private DNS resolver hosted by
AdGuard Developed by AdGuard Software Limited, AdGuard offers open-source, free, and shareware products. AdGuard's DNS app supports Microsoft Windows, Linux, macOS, Android and iOS. AdGuard is also available as a browser extension. AdGuard Soft ...
resulted in the page being identified as malware and blocked for the user's
security" \n\n\nsecurity.txt is a proposed standard for websites' security information that is meant to allow security researchers to easily report security vulnerabilities. The standard prescribes a text file called \"security.txt\" in the well known locat ...
. By mid-2022, it had been turned into a political blog. Another example of corporate typosquatting is ''yuube.com'', targeting
YouTube YouTube is a global online video sharing and social media platform headquartered in San Bruno, California. It was launched on February 14, 2005, by Steve Chen, Chad Hurley, and Jawed Karim. It is owned by Google, and is the second mo ...
users by programming that URL to
redirect Redirect and its variants (e.g., redirection) may refer to: Arts, entertainment, and media * ''Redirect'', 2012 Christian metal album and its title track by Your Memorial * ''Redirected'' (film), a 2014 action comedy film Computing * ICMP R ...
to a malicious website or page that asks users to add a malware "security check extension". Similarly, ''www. airfrance.com'' has been typosquatted by ''www.arifrance.com'', diverting users to a website peddling discount travel (although it now redirects to a warning from AirFrance about malware). Other examples are ''Equifacks.com'' ( Equifax.com), ''Experianne.com'' ( Experian.com), and ''TramsOnion.com'' (
TransUnion TransUnion is an American consumer credit reporting agency. TransUnion collects and aggregates information on over one billion individual consumers in over thirty countries including "200 million files profiling nearly every credit-active consume ...
.com); these three typosquatted sites were registered by comedian
John Oliver John William Oliver (born 23 April 1977) is a British-American comedian, writer, producer, political commentator, actor, and television host. Oliver started his career as a stand-up comedian in the United Kingdom. He came to wider attention ...
for his show '' Last Week Tonight''. Over 550 typosquats related to the 2020 U.S. presidential election were detected in 2019.


In United States law

In the United States, the 1999
Anticybersquatting Consumer Protection Act The Anticybersquatting Consumer Protection Act (ACPA), 15 U.S.C. § 1125(d),(passed as part of ) is a U.S. law enacted in 1999 that established a cause of action for registering, trafficking in, or using a domain name confusingly similar to, or di ...
(ACPA) contains a clause (Section 3(a), amending 15 USC 1117 to include sub-section (d)(2)(B)(ii)) aimed at combatting typosquatting. On April 17, 2006, evangelist Jerry Falwell failed to get the U.S. Supreme Court to review a decision allowing Christopher Lamparello to use www.fallwell.com. Relying on a plausible misspelling of Falwell's name, Lamparello's gripe site presents misdirected visitors with scriptural references that are intended to counter the fundamentalist preacher's scathing rebukes against
homosexuality Homosexuality is romantic attraction, sexual attraction, or sexual behavior between members of the same sex or gender. As a sexual orientation, homosexuality is "an enduring pattern of emotional, romantic, and/or sexual attractions" to pe ...
. In '' Lamparello v. Falwell'', the high court let stand a 2005
Fourth Circuit The United States Court of Appeals for the Fourth Circuit (in case citations, 4th Cir.) is a federal court located in Richmond, Virginia, with appellate jurisdiction over the district courts in the following districts: * District of Maryland ...
opinion that "the use of a mark in a domain name for a gripe site criticizing the markholder does not constitute cybersquatting."


WIPO resolution procedure

Under the
Uniform Domain-Name Dispute-Resolution Policy The Uniform Domain-Name Dispute-Resolution Policy (UDRP) is a process established by the Internet Corporation for Assigned Names and Numbers (ICANN) for the resolution of disputes regarding the registration of internet domain names. The UDRP curren ...
(UDRP),
trademark A trademark (also written trade mark or trade-mark) is a type of intellectual property consisting of a recognizable sign, design, or expression that identifies products or services from a particular source and distinguishes them from othe ...
holders can file a case at the
World Intellectual Property Organization The World Intellectual Property Organization (WIPO; french: link=no, Organisation mondiale de la propriété intellectuelle (OMPI)) is one of the 15 specialized agencies of the United Nations (UN). Pursuant to the 1967 Convention Establishi ...
(WIPO) against typosquatters (as with cybersquatters in general). The complainant has to show that the registered domain name is identical or confusingly similar to their trademark, that the registrant has no legitimate interest in the domain name, and that the domain name is being used in bad faith.


See also

* * (DNS) * * * (for similar attacks on vanity
toll-free telephone number A toll-free telephone number or freephone number is a telephone number that is billed for all arriving calls. For the calling party, a call to a toll-free number from a landline is free of charge. A toll-free number is identified by a dialing pre ...
phoneword Phonewords are mnemonic phrases represented as alphanumeric equivalents of a telephone number. In many countries, the digits on the telephone keypad also have letters assigned. By replacing the digits of a telephone number with the correspondin ...
s) * * *


References


External links

*Jim Giles
Typos may earn Google $500m a year
New Scientist ''New Scientist'' is a magazine covering all aspects of science and technology. Based in London, it publishes weekly English-language editions in the United Kingdom, the United States and Australia. An editorially separate organisation publish ...
, 17 February 2010 (reporting research by Ben Edelman and Tyler Moore
Measuring Typosquatting Perpetrators and Funders
* * * * Nation Squid
How One Typo Destroyed Thousands of Computers
{{Domain parking Cybercrime Network addressing Nonstandard spelling Trademark law URL