Posted on

Typosquatted domains that exploit small typing errors

The difference between the right website and the wrong website can be one missing letter.

That is enough.

Typosquatting is the practice of registering a domain that resembles a familiar one closely enough to catch people who mistype the address or fail to notice a small change. Microsoft gives the simple example of a missing letter in a company name; ICANN’s security work describes the same problem with lookalike domains such as faceboook.com or goggle.com.

See Microsoft’s explanation of typosquatting and ICANN’s DNS security study.

The trick is effective because users usually recognize a domain as a shape, not as a forensic specimen.

Familiar enough is often enough

A mistyped address may lead to a harmless parking page full of ads. It can also lead to a copied login page, a fake store, or a malware download.

The attacker benefits from recognition already earned by somebody else. The colors, logo and layout can all imitate the legitimate service. The domain only needs to survive a glance.

The browser’s lock icon does not solve the problem. Encryption can protect the connection to the wrong site just as effectively as it protects the connection to the right one.

That means the useful question is not simply, “Is this connection encrypted?”

It is, “Who owns the address I actually reached?”

The visible address is evidence

Before entering a password, payment card, recovery code or other sensitive information, look at the registered domain itself rather than the page design.

A scammer can copy the page. The scammer cannot place a fake page at the genuine domain unless that domain has also been compromised.

Microsoft recommends using saved favorites for important banking, shopping and social sites instead of retyping the address each time. Modern browsers may also warn about common mistyped domains, but those protections are assistance rather than permission to stop looking.

The FBI makes the same general point in its phishing guidance: carefully examine URLs and spelling because scammers deliberately use small differences to gain trust.

See the FBI’s spoofing and phishing guidance.

Typosquatting is almost insultingly simple.

That is why it remains useful.

The attacker does not need to defeat the real website. The attacker only needs to stand one character away from it.