A doppelganger domain is a domain that is spelled identically to a legitimate fully qualified domain name (FQDN) but missing the dot between host/subdomain and domain, to be used for malicious purposes.

Overview

Typosquatting's traditional attack vector is through the web to distribute malware or harvest credentials. Other vectors such as email and remote access services such as SSH, RDP, and VPN also can be leveraged. In a whitepaper by Godai Group on doppelganger domains, they demonstrated that numerous emails can be harvested without anyone noticing.[1]

Example

For email address "ktrout@fi­nance.corpu­dyne.com", the doppel­ganger domain would be "finance­corpu­dyne.com"; hence, an email acci­den­tally addressed to "ktrout@financecorpudyne.com" (i.e. with the dot between "finance" and "corpu­dyne" having acci­den­tally been omitted) would go to the doppel­ganger domain rather than to the legitimate user.

See also

  • Anticybersquatting Consumer Protection Act (ACPA)
  • Domain Name System (DNS) – System to identify resources on a network
  • Phishing – Form of social engineering
  • Uniform Domain-Name Dispute-Resolution Policy (UDRP) – Process of dispute resolution

References

  1. "Doppelganger Domain whitepaper". Godai Group. 6 Sep 2011.


This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.