Misplaced Pages

Doppelganger domain

Article snapshot taken from Wikipedia with creative commons attribution-sharealike license. Give it a read and then ask your questions in the chat. We can research this topic together.
Form of domain name hijack
This article relies largely or entirely on a single source. Relevant discussion may be found on the talk page. Please help improve this article by introducing citations to additional sources.
Find sources: "Doppelganger domain" – news · newspapers · books · scholar · JSTOR (March 2023)

A doppelganger domain is a domain that is spelled identically to a legitimate fully qualified domain name (FQDN) but missing the dot between host/subdomain and domain, to be used for malicious purposes.

Typosquatting's traditional attack vector is through the web to distribute malware or harvest credentials. Other vectors such as email and remote access services such as SSH, RDP, and VPN also can be leveraged. In a whitepaper by Godai Group on doppelganger domains, they demonstrated that numerous emails can be harvested without anyone noticing.

For example, for email address "ktrout@fi­nance.corpu­dyne.com", the doppel­ganger domain would be "finance­corpu­dyne.com"; hence, an email acci­den­tally addressed to "ktrout@financecorpudyne.com" (i.e. with the dot between "finance" and "corpu­dyne" having acci­den­tally been omitted) would go to the doppel­ganger domain rather than to the legitimate user.

See also

References

  1. "Doppelganger Domain whitepaper". Godai Group. 6 Sep 2011.

External links

Domain name speculation and parking
General
Legal
Technical


Stub icon

This Internet-related article is a stub. You can help Misplaced Pages by expanding it.

Stub icon

This malware-related article is a stub. You can help Misplaced Pages by expanding it.

Categories: