Researchers flag phony domains in e-mail security study

Sep 11, 2011 by Nancy Owano weblog

( -- A paper released this week shows how an e-mail scoffing technique picks up personal employee information, company secrets and passwords almost effortlessly with just the setting up of domain and e-mail server. The researchers discovered business invoices, employee personal identifying information, network diagrams, user names, passwords, and trade secrets were part of the treasure trove of e-mail information that was captured by phony domains set up for the experiment.

The paper is titled "Doppelganger Domains," and as its title suggests the technique involves an e-mail address that at first glance looks identical to the real address but is missing a dot between subdomain and domain. While "typo-squatting" is nothing new, doppelganger domains are a troublesome variant. They are troublesome because the involved error is so easy to make and so easy not to instantly recognize. A no-dot omission instead of a misspelling can do considerable damage. As The Register phrased it, it is a case where "executive butterfingers get slurped by honeypots" just because of the sender missing the dot between host/subdomain and domain. An attacker's "" versus the "correct" is an example. Attackers could configure their email server to vacuum up email addressed to that real domain. Corporate giants are easy targets, with their heavy usage of , accompanied by the likelihood of mis-sent e-mails.

The study's authors, Peter Kim and Garrett Gee from the Godai Group, a , found that 30 percent (151) of the Fortune 500 companies profiled were potentially vulnerable in a six-month waiting period, where they had set up doppelganger domains to see what they would get. What they did get were 120,000 e-mails that innocent people had mistakenly sent to the phony missing-dot domains.

Types of Fortune 500 industries listed as susceptible to doppelganger domains in the test included telecom, technology, aerospace and defense, banks, food and consumer products. While the test was an experiment, the researchers say real-world doppelganger domains exist, as they found no-dot domains of this nature in China. Some of those domains are already known for phishing.

Kim and Gee recommend ways to avoid the interception of e-mails through doppelganger domains. Their recommendations, among others, include (1) finding out if a doppelganger domain is already in use and if so then filing a dispute known as a Uniform Domain Dispute Resolution Policy (2) configuring the mail server not to allow outbound e-mails to doppelganger domains. While another recommendation might appear too obvious to mention, it is of practical value: Tell others to be careful. "Communicate the attack vector to your internal users, customers, and business partners."

Explore further: Twitter blocks two accounts on its Turkish network

More information: Press release

Related Stories

New Internet domain suffixes seen as benefit

Jun 14, 2011

Small businesses trying to find new ways to market themselves online may soon tap new branding opportunities, if the organization that regulates Internet domain names expands its offering beyond the traditional dot-com suffix.

Domain registry on the rise

Apr 27, 2006

Internet domain names may become as ubiquitous as Social Security numbers one day, according to Dotster Inc.

Downadup Worm Hits Over 3.5 Million Computers

Jan 16, 2009

( -- Security firm F-Secure has advised that the Downadup worm has spread to more than 3.5 million computers by exploiting a vulnerability Microsoft patched last October. This is achieved by trying ...

Recommended for you

LinkedIn membership hits 300 million

Apr 18, 2014

The career-focused social network LinkedIn announced Friday it has 300 million members, with more than half the total outside the United States.

Researchers uncover likely creator of Bitcoin

Apr 18, 2014

The primary author of the celebrated Bitcoin paper, and therefore probable creator of Bitcoin, is most likely Nick Szabo, a blogger and former George Washington University law professor, according to students ...

White House updating online privacy policy

Apr 18, 2014

A new Obama administration privacy policy out Friday explains how the government will gather the user data of online visitors to, mobile apps and social media sites. It also clarifies that ...

User comments : 0

More news stories

TCS, Mitsubishi to create new Japan IT services firm

India's biggest outsourcing firm Tata Consultancy Services (TCS) and Japan's Mitsubishi Corp said Monday they are teaming up to create a Japanese software services provider with annual revenues of $600 million.

Finnish inventor rethinks design of the axe

( —Finnish inventor Heikki Kärnä is the man behind the Vipukirves Leveraxe, which is a precision tool for splitting firewood. He designed the tool to make the job easier and more efficient, with ...

Atom probe assisted dating of oldest piece of earth

( —It's a scientific axiom: big claims require extra-solid evidence. So there were skeptics in 2001 when University of Wisconsin-Madison geoscience professor John Valley dated an ancient crystal ...