TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Something Wicked This Way .coms: this sure seems like a big hole in the web

1 pointsby code_Whispererover 8 years ago
Here&#x27;s the TL;DR of an earlier post: I accidentally mistyped a domain name configuration value while updating a website and found what I feel is a phishing op. If you take any .com domain, and add a second.com to the end (I do NOT recommend actually trying this unless you know what you are doing) you will see what appears to be a typo phishing operation.<p>My question: is this well known? Because I&#x27;ve never seen it written up before when I peruse web security stuff. For the full write-up of my experience and an associated screenshot check out: http:&#x2F;&#x2F;www.oldirtyhacker.com&#x2F;something-wicked-this-way-coms

2 comments

smt88over 8 years ago
It is well-known. uBlock blocks anything ending in &quot;.com.com&quot; by default. It&#x27;s on most badware block lists.<p>It&#x27;s not a hole in the web any more than people accidentally typing &quot;fcaebook.com&quot; is a hole in the web. It&#x27;s just someone exploiting user error, not unlike domain squatting. If you hit &quot;CTRL+ENTER&quot; in most browsers&#x27; address bars, they used to blindly append &quot;.com&quot; onto the domain name. If you typed &quot;facebook.com&quot; and then hit CTRL+ENTER, you&#x27;d get to facebook.com.com. As far as I know, all browsers have fixed that.<p>This isn&#x27;t actually phishing (as far as I know) because it&#x27;s not trying to trick you into thinking you&#x27;ve gone to the correct website. It&#x27;s just a malware distribution page.<p>I believe OpenDNS also blocks this, for the record.
评论 #12508813 未加载
detaroover 8 years ago
uBlock&#x27;s Badware list blocks it, and via its documentation page I found these two links:<p><a href="https:&#x2F;&#x2F;isc.sans.edu&#x2F;diary&#x2F;.COM.COM+Used+For+Malicious+Typo+Squatting&#x2F;20019" rel="nofollow">https:&#x2F;&#x2F;isc.sans.edu&#x2F;diary&#x2F;.COM.COM+Used+For+Malicious+Typo+...</a><p><a href="https:&#x2F;&#x2F;www.whitehatsec.com&#x2F;blog&#x2F;why-com-com-should-scare-you&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.whitehatsec.com&#x2F;blog&#x2F;why-com-com-should-scare-yo...</a><p>Seems like this has been going on for a while...
评论 #12508585 未加载