Cyberstudy
PDF p.46 In progress

Typosquatting

Open PDF at p.46 9 flashcards

Summary

PDF p.46

Typosquatting involves registering domain names similar to legitimate ones to trick users into thinking they are interacting with trusted sites. This technique is often used in phishing and pharming attacks to exploit user trust.

In plain words

Supplementary — not from your PDF

Typosquatting means registering a domain that looks almost like a real one (exannple.com instead of example.com), so people trust it by mistake. Attackers also abuse subdomains of big cloud providers to look legitimate.

Detailed explanation

PDF p.46
  • Impersonation in Phishing and Pharming
    • Dependence: Success relies on convincing the target that the message or site is from a trusted source.
    • Email Client Inconsistencies: Threat actors exploit how email clients display the "From" field, sometimes showing arbitrary values instead of actual email addresses.
  • Typosquatting
    • Definition: Registering domain names that are very similar to real ones (e.g., exannple.com).
    • Purpose: Trick users into thinking they are on a trusted site or receiving email from a known source.
    • Other Names: Cousin, lookalike, or doppelganger domains.
  • Hijacked Subdomains
    • Technique: Registering subdomains using the primary domain of a trusted cloud provider (e.g., onmicrosoft.com).
    • Example: A phishing message from example.onmicrosoft.com may appear trustworthy to users.

Important terms

taken from the text above
Dependence
Success relies on convincing the target that the message or site is from a trusted source.
Email Client Inconsistencies
Threat actors exploit how email clients display the "From" field, sometimes showing arbitrary values instead of actual email addresses.
Typosquatting
Registering domain names that are very similar to real ones (e.g., exannple.com).
Other Names
Cousin, lookalike, or doppelganger domains.

Examples & real-world scenarios

Supplementary — not from your PDF
  • micros0ft-support.com with a zero in place of the letter o.
  • A lookalike domain used as the 'From' address in phishing.
  • A message from a company name on a trusted cloud provider's subdomain.

Scenario

An invoice email comes from accounts@examp1e.com (with the number 1). The display name says 'Example Ltd Accounts'. Checking the real address reveals the lookalike domain.

Common mistakes

Supplementary — not from your PDF
  • Only reading the display name instead of the actual address.
  • Assuming a familiar cloud provider's domain in a link means the content is safe.

Practical skills

Supplementary — not from your PDF
  • Compare a suspicious domain with the real one, character by character.

What I should remember

Key Points PDF p.46
  • Impersonation in Phishing and Pharming
    • Dependence: Convincing targets of trustworthiness.
    • Email Client Inconsistencies: Exploiting "From" field display.
  • Typosquatting
    • Definition: Similar domain names to legitimate ones.
    • Purpose: Trick users into trusting the site or email.
    • Other Names: Cousin, lookalike, doppelganger domains.
  • Hijacked Subdomains
    • Technique: Using trusted cloud provider domains.
    • Example: Phishing from example.onmicrosoft.com.