Typosquatting - Fake Domains from Misspelled URLs
About 2 min read
Typosquatting is an attack technique in which an attacker registers a confusingly similar domain to that of a legitimate website and lures users to a fake site by exploiting their typing mistakes. As with "gogle.com" or "googel.com" against "google.com", fake domains are created by swapping, omitting, or adding a single character. The consequences of a typo differ sharply between a browser and a package manager. A mistyped URL causes no harm unless the user goes on to enter something on the fake site, whereas a mistyped dependency name pulls in code that then runs as part of the build or the application itself, so a single character can lead to code execution that never passes through the user's judgment.
What It Takes to Tell Similar Names Apart
When considering the harm done by confusable names, the underlying question is where the material for telling them apart is located. First, a wrong name is not produced by mistyping alone. Once an error has been written down somewhere, it is copied again and again through procedure documents, notes shared internally, transcriptions from explanatory articles, and history left behind as input suggestions. A mistype ends there, but a copied error is used repeatedly in the same form. Fixing the place where it was pulled in does not stop the same name from arriving again from wherever the original wording remains, so the unit of repair is not the destination but the places where the name is written. Second, the only material available to the receiving side for making a judgment is the appearance of the name. Judging that something is similar only holds if the correct name is known, and without a list of correct names there is no way to distinguish an unfamiliar name from a correct name being used for the first time. Even when a pair of similar names is found, which one is the original is not settled by comparing the names; it is decided using other material such as breadth of use or the time of registration. Third, what remains at the moment of noticing is not only the name. Where the mechanism runs processing as part of pulling something in, removing the name from a list and removing what that processing left behind are separate tasks. Saved copies, distributions replicated elsewhere, and content written out as a record of the intake each remain independently, so the scope of removal is not determined by following the name alone.
Attack Methods and Objectives
Typosquatting serves a wide range of objectives. These include cases of stealing login credentials by posing as a phishing site, cases of displaying parking pages to earn advertising revenue, and cases of distributing malware. "Package typosquatting", which involves publishing malicious packages with names resembling popular ones in programming language package managers (npm, PyPI), has also become a problem.
Countermeasures
Individual users can prevent damage by using bookmarks, checking the URL bar, and relying on the browser's autocomplete feature. For organizations, effective measures include preemptively registering domains similar to their own brand (defensive registration) and using a domain monitoring service to detect newly registered look-alike domains. It is also important to prevent email spoofing by configuring DMARC, SPF, and DKIM, and to strengthen DNS security. Protect your domain management account with a strong random password to prevent unauthorized domain transfers.
Was this article helpful?