Mistyped URLs can land you in hot water
(08/01/2009)
Just when you thought you were on top of the risks online another threat presents itself. Twenty years ago we learnt that infected floppy disks could spread viruses so we learned how to deal with that. Then we got used to social engineering techniques and stopped clicking on every link or file we were sent. But the evolution of threats didn’t stop there and we have since been learning to deal with spam, phishing and other online scams, to make sure that our personal information is not being targeted. However, that’s not the end of it as even our own spelling errors can land us in trouble, with typosquatters just waiting for us to make mistakes.
Typosquatting is the term used to describe how malicious-minded Internet fiends out there prey on those of us who mistype web addresses, registering common misspellings of popular domain names and products to then redirect those who make mistakes to alternative websites. In fact, a typical person misspelling a popular URL has a 1 in14 chance of landing at a typo-squatter site.
These sites – run by the typosquatters – then generate click-through advertising revenue, lure unsuspecting consumers into scams, harvest email addresses in order to flood unsuspecting Internet users with unwanted email and can even result in malware infections. This just goes to show that when it comes to keeping yourself secure on the Internet, it’s an ever-moving target and there is a real need to continuously question the validity of sites and sources in order to maintain your Internet safety.
The use of URLs that look like the real thing but are in fact far from it should come as no real surprise. Just as phishing emails replicate valid messages from banks and the perpetrators of malware attempt to make you download a file by claiming it is something that will appeal to you, the bad guys out there know what the average Internet user is interested in and what will appeal to the greatest number of surfers.
This tactic is no different to physical retailers trying to pass off fake goods as something altogether more legitimate. It’s important to learn what to look out for, as at worst, typosquatting can lead to innocent computer users becoming the victims of online scams or “get rich quick” tricks.
If your business has an online presence, the danger is that your customers may unwittingly be lured from your site to one that may well look similar at first glance but is far from it. A recent example of a brand that has been targeted by typosquatters is the iPhone – although it was released fairly late in 2007, it was predicted that by the end of that year there would be approximately 8,000 URLs using “iPhone”. Gaming sites and airline sites also emerged as being highly squatted.
So with they way that online villains constantly change approach to try to trick us, how can we maintain good security and protect our identity? Well the reality is that those bad guys are always trying to stay one step ahead of us but we don’t need to let them. The bottom line is that you’re not sure of the URL you’re looking for, you’re far safer using a search engine than trying to make a guess. If we stay alert, are careful with the information we share and the websites we visit, and also use security technology to block or highlight risks, there is no reason why we can’t continue to get the most out of the Internet. With the right approach, the Internet can continue to play a pivotal role in our lives and we can protect our friends and families from those who will continue to try to trick us.
McAfee International Ltd is exhibiting at Infosecurity Europe 2009, on the 28th – 30th April 2009 in Earls Court, London, www.infosec.co.uk
Related topics: Computer and PC Security Internet and Web security
Print version |
Email to a friend |
Related articles
Data breaches: Trends, costs and best practices gives you all the latest information on securing personal and corporate data, key recommendations for immediate action to improve data security, and how to respond to data breaches.
Other Security news and resources
Security News
Suppliers Directory
Jobs forum
Classifieds
Knowledge base
White papers
Research library
Security books
Special reports
Security interviews
Security companies
Security events
Security links
Security market
Product channels
Access Control Biometrics CCTV Intruder Alarms IT Security Manned Guarding Perimeter Protection Physical Security Remote Monitoring Security Services Fire, Health & Safety Other Security Products
IT Security white papers and research library
Access Control Authentication Data Management Data Security Digital Signatures Email Security Identity Management Internet Security Intrusion Prevention Network Security Remote access security Security Management Security Policies Security Software Security Threats Virus Detection Software Virus Protection VPN Vulnerability Assessment Wireless Security
Security books, guides, standards and toolkits
RFID and Smart Cards books, guides and reference documents Biometric books, guides and reference documents CCTV books, guides and reference documents Intruder alarms and intrusion detection systems books, guides and reference documents Monitoring and surveillance books, guides and reference documents IT Governance, ISO 27001 ISO 17799 and BS 7799 toolkits Fire, Health & Safety books, guides and reference documents


