Typosquatting
   HOME

TheInfoList



OR:

Typosquatting, also called URL hijacking, a sting site, or a fake URL, is a form of
cybersquatting Cybersquatting (also known as domain squatting) is the practice of registering, trafficking in, or using an Internet domain name, with a bad faith intent to profit from the goodwill of a trademark belonging to someone else. The term is derived ...
, and possibly
brandjacking Brandjacking is an activity whereby someone acquires or otherwise assumes the online identity of another entity for the purposes of acquiring that person's or business's brand equity. The term combines the notions of 'branding' and ' hijacking', a ...
which relies on mistakes such as
typos A typographical error (often shortened to typo), also called a misprint, is a mistake (such as a spelling mistake) made in the typing of printed (or electronic) material. Historically, this referred to mistakes in manual type-setting (typography). ...
made by Internet users when inputting a website address into a
web browser A web browser is application software for accessing websites. When a user requests a web page from a particular website, the browser retrieves its files from a web server and then displays the page on the user's screen. Browsers are used o ...
. Should a user accidentally enter an incorrect website address, they may be led to any URL (including an alternative website owned by a cybersquatter). The typosquatter's URL will usually be one of five kinds, all ''similar to'' the victim site address: *A common misspelling, or foreign language spelling, of the intended site *A misspelling based on a typographical error *A plural of a singular domain name *A different
top-level domain A top-level domain (TLD) is one of the domains at the highest level in the hierarchical Domain Name System of the Internet after the root domain. The top-level domain names are installed in the root zone of the name space. For all domains in ...
: (i.e. .com instead of .org) *An abuse of the
Country Code Top-Level Domain A country code top-level domain (ccTLD) is an Internet top-level domain generally used or reserved for a country, sovereign state, or dependent territory identified with a country code. All ASCII ccTLD identifiers are two letters long, and all ...
(ccTLD) (.cm, .co, or .om instead of .com) Similar abuses: *Combosquatting - no misspelling, but appending an arbitrary word that appears legitimate, but that anyone could register. *
Doppelganger domain A doppelganger domain is a domain spelled identical to a legitimate fully qualified domain name (FQDN) but missing the dot between host/subdomain and domain, to be used for malicious purposes. Overview Typosquatting's traditional attack vector is ...
- omitting a period or inserting an extra period *Appending terms such as ''sucks'' or -' to a domain name Once in the typosquatter's site, the user may also be tricked into thinking that they are in fact in the real site, through the use of copied or similar logos, website layouts, or content. Spam emails sometimes make use of typosquatting URLs to trick users into visiting malicious sites that look like a given bank's site, for instance. Magniber
ransomware Ransomware is a type of malware from cryptovirology that threatens to publish the victim's personal data or permanently block access to it unless a ransom is paid off. While some simple ransomware may lock the system without damaging any files, ...
are being distributed in a typosquatting method that exploits typos made when entering domains, targeting mainly Chrome and Edge users.


Motivation

There are several different reasons for typosquatters buying a typo domain: *In order to try to sell the typo domain back to the brand owner *To monetize the domain through
advertising Advertising is the practice and techniques employed to bring attention to a product or service. Advertising aims to put a product or service in the spotlight in hopes of drawing it attention from consumers. It is typically used to promote a ...
revenues from direct navigation misspellings of the intended domain *To redirect the typo-traffic to a competitor *To redirect the typo-traffic back to the brand itself, but through an affiliate link, thus earning commissions from the brand owner's affiliate program. *As a
phishing Phishing is a type of social engineering where an attacker sends a fraudulent (e.g., spoofed, fake, or otherwise deceptive) message designed to trick a person into revealing sensitive information to the attacker or to deploy malicious softwa ...
scheme to mimic the brand's site, while intercepting passwords which the visitor enters unsuspectingly *To install drive-by
malware Malware (a portmanteau for ''malicious software'') is any software intentionally designed to cause disruption to a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, depr ...
or revenue generating
adware Adware, often called advertising-supported software by its developers, is software that generates revenue for its developer by automatically generating online advertisements in the user interface of the software or on a screen presented to the ...
onto the visitors' devices *To harvest misaddressed e-mail messages mistakenly sent to the typo domain *To express an opinion that is different from the intended website's opinion *By legitimate site owners: to block malevolent use of the typo domain by others *To annoy users of the intended site


Examples

Many companies, including
Verizon Verizon Communications Inc., commonly known as Verizon, is an American multinational telecommunications conglomerate and a corporate component of the Dow Jones Industrial Average. The company is headquartered at 1095 Avenue of the Americas ...
,
Lufthansa Deutsche Lufthansa AG (), commonly shortened to Lufthansa, is the flag carrier of Germany. When combined with its subsidiaries, it is the second- largest airline in Europe in terms of passengers carried. Lufthansa is one of the five founding ...
, and
Lego Lego ( , ; stylized as LEGO) is a line of plastic construction toys that are manufactured by The Lego Group, a privately held company based in Billund, Denmark. The company's flagship product, Lego, consists of variously colored interlocki ...
, have gained reputations for aggressively chasing down typosquatted names. Lego, for example, has spent roughly US$500,000 on taking 309 cases through UDRP proceedings. Celebrities have also frequently pursued their domain names. Prominent examples include basketball player Dirk Nowitzki's UDRP of DirkSwish.com and actress Eva Longoria's UDRP of EvaLongoria.org. Goggle, a typosquatted version of
Google Google LLC () is an American Multinational corporation, multinational technology company focusing on Search Engine, search engine technology, online advertising, cloud computing, software, computer software, quantum computing, e-commerce, ar ...
, was the subject of a mid-2000s web safety promotion by McAfee, which depicted the significant amounts of malware installed through drive-by downloads upon accessing the site at the time. Later the URL redirected to google.com; a 2018 check revealed it to redirect users to
adware Adware, often called advertising-supported software by its developers, is software that generates revenue for its developer by automatically generating online advertisements in the user interface of the software or on a screen presented to the ...
pages, and a 2020 attempt to access the site through a private DNS resolver hosted by
AdGuard Developed by AdGuard Software Limited, AdGuard offers open-source, free, and shareware products. AdGuard's DNS app supports Microsoft Windows, Linux, macOS, Android and iOS. AdGuard is also available as a browser extension. AdGuard Softw ...
resulted in the page being identified as
malware Malware (a portmanteau for ''malicious software'') is any software intentionally designed to cause disruption to a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, depr ...
and blocked for the user's
security" \n\n\nsecurity.txt is a proposed standard for websites' security information that is meant to allow security researchers to easily report security vulnerabilities. The standard prescribes a text file called \"security.txt\" in the well known locat ...
. By mid-2022, it had been turned into a political blog. Another example of corporate typosquatting is ''yuube.com'', targeting
YouTube YouTube is a global online video sharing and social media platform headquartered in San Bruno, California. It was launched on February 14, 2005, by Steve Chen, Chad Hurley, and Jawed Karim. It is owned by Google, and is the second mo ...
users by programming that URL to redirect to a malicious website or page that asks users to add a malware "security check extension". Similarly, ''www.
airfrance Air France (; formally ''Société Air France, S.A.''), stylised as AIRFRANCE, is the flag carrier of France headquartered in Tremblay-en-France. It is a subsidiary of the Air France–KLM Group and a founding member of the SkyTeam global air ...
.com'' has been typosquatted by ''www.arifrance.com'', diverting users to a website peddling discount travel (although it now redirects to a warning from AirFrance about malware). Other examples are ''Equifacks.com'' (
Equifax Equifax Inc. is an American multinational consumer credit reporting agency headquartered in Atlanta, Georgia and is one of the three largest consumer credit reporting agencies, along with Experian and TransUnion (together known as the "Big Th ...
.com), ''Experianne.com'' (
Experian Experian is an American–Irish multinational data analytics and consumer credit reporting company. Experian collects and aggregates information on over 1 billion people and businesses including 235 million individual U.S. consumers and more ...
.com), and ''TramsOnion.com'' (
TransUnion TransUnion is an American consumer credit reporting agency. TransUnion collects and aggregates information on over one billion individual consumers in over thirty countries including "200 million files profiling nearly every credit-active consume ...
.com); these three typosquatted sites were registered by comedian John Oliver for his show ''
Last Week Tonight A last is a mechanical form shaped like a human foot. It is used by shoemakers and cordwainers in the manufacture and repair of shoes. Lasts typically come in pairs and have been made from various materials, including hardwoods, cast iron, an ...
''. Over 550 typosquats related to the 2020 U.S. presidential election were detected in 2019.


In United States law

In the United States, the 1999 Anticybersquatting Consumer Protection Act (ACPA) contains a clause (Section 3(a), amending 15 USC 1117 to include sub-section (d)(2)(B)(ii)) aimed at combatting typosquatting. On April 17, 2006, evangelist
Jerry Falwell Jerry Laymon Falwell Sr. (August 11, 1933 – May 15, 2007) was an American Baptist pastor, televangelism, televangelist, and conservatism in the United States, conservative activist. He was the founding pastor of the Thomas Road Baptist Church, ...
failed to get the U.S. Supreme Court to review a decision allowing Christopher Lamparello to use www.fallwell.com. Relying on a plausible misspelling of Falwell's name, Lamparello's gripe site presents misdirected visitors with scriptural references that are intended to counter the fundamentalist preacher's scathing rebukes against
homosexuality Homosexuality is Romance (love), romantic attraction, sexual attraction, or Human sexual activity, sexual behavior between members of the same sex or gender. As a sexual orientation, homosexuality is "an enduring pattern of emotional, romant ...
. In '' Lamparello v. Falwell'', the high court let stand a 2005 Fourth Circuit opinion that "the use of a mark in a domain name for a gripe site criticizing the markholder does not constitute cybersquatting."


WIPO resolution procedure

Under the Uniform Domain-Name Dispute-Resolution Policy (UDRP),
trademark A trademark (also written trade mark or trade-mark) is a type of intellectual property consisting of a recognizable sign, design, or expression that identifies products or services from a particular source and distinguishes them from ot ...
holders can file a case at the
World Intellectual Property Organization The World Intellectual Property Organization (WIPO; french: link=no, Organisation mondiale de la propriété intellectuelle (OMPI)) is one of the 15 specialized agencies of the United Nations (UN). Pursuant to the 1967 Convention Establishi ...
(WIPO) against typosquatters (as with cybersquatters in general). The complainant has to show that the registered domain name is identical or confusingly similar to their trademark, that the registrant has no legitimate interest in the domain name, and that the domain name is being used in
bad faith Bad faith (Latin: ''mala fides'') is a sustained form of deception which consists of entertaining or pretending to entertain one set of feelings while acting as if influenced by another."of two hearts ... a sustained form of deception which ...
.


See also

* * (DNS) * * * (for similar attacks on vanity
toll-free telephone number A toll-free telephone number or freephone number is a telephone number that is billed for all arriving calls. For the calling party, a call to a toll-free number from a landline is free of charge. A toll-free number is identified by a dialing pre ...
phonewords) * * *


References


External links

*Jim Giles
Typos may earn Google $500m a year
New Scientist ''New Scientist'' is a magazine covering all aspects of science and technology. Based in London, it publishes weekly English-language editions in the United Kingdom, the United States and Australia. An editorially separate organisation publish ...
, 17 February 2010 (reporting research by Ben Edelman and Tyler Moore
Measuring Typosquatting Perpetrators and Funders
* * * * Nation Squid
How One Typo Destroyed Thousands of Computers
{{Domain parking Cybercrime Network addressing Nonstandard spelling Trademark law URL