TechnicianinaBox.com - Train to Become a Self Employed Computer Technician

  • Home
  • Members Area
  • The Team
  • Contact Us

How Misspelled Emails Can Create Security Loopholes

September 13, 2011 By Ryan Fanus Leave a Comment

Researchers have discovered a security loophole created by a missing dot in an email address.

It seems hackers can gain valuable information from companies online simply with grammar errors. With a mistyped email address a hacker can receive valuable information such as user names, passwords, and other corporate information despite any fraudulent misspelling. Such malicious domains are called “Doppelganger Domains” and are being used to create loopholes that will leave companies vulnerable to identity theft.

A Doppelganger Domain can resemble an existing domain or sub-domain but with the exception of a missing dot in the url. Despite the differences, Doppelganger Domains can receive information that would otherwise not be delivered. The process is quite simple. The person responsible can set buy a domain that resembles an actual domain from a company. This is called “Typosquatting”. The owner of the Doppelganger Domain can then configure an email server to receive all email addressed to that domain, regardless of its lack of authenticity. This type of configuration is called a “Catch-all Email Account.”

What make companies especially susceptible to this loophole is the way their email systems are set up. Though most have a single domain for their website, many use sub-domains for individual business units, regional offices or foreign subsidiaries. Dots used to separate the words in those sub domains. For example, a company could have “bank.com” as its main domain and and “uk.bank.com” as the sub-domain for one of its branches. In order to create a Doppelganger Domain resembling that of the company, one only requires to type one of the domains without the dot. For example, ukbank.com.

If it all still sounds to good to be true, researchers Peter Kim and Garrett Gee of GodaiGroup have recently proven this by setting up their own Doppelganger Domain to send and receive information with each Fortune 500 company. Shockingly, one Doppelganger Domain gained 20GB of data fromĀ 120,000 wrongly sent messages over a period of six months. From this, researchers have determined that About 30% of the top 500 companies in the US were vulnerable to this security shortcoming.

This is just the tip of the iceberg. The owner of the Doppelganger Domain can also send replies between the recipient and sender to gain more valuable information. By acting as a middleman, the owner of the Domain can create a malicious network to draw in more valuable information from several companies until they are exposed. the sky is the limit with this type of email fraud.

If you want to learn more about the email loophole, you can readĀ Peter Kim and Garrett Gee research paper here.

 

Filed Under: news Tagged With: Catch-all Email Account, Doppelganger Domain, email, email fraud, Garrett Gee, GodaiGroup, hacking, loophole, man in the middle, Peter Kim, security loophole, Typosquatting

Introduction to Microsoft Certification

Enter Email for further information

Would you like to start your own Microsoft Certified Computer Technician Business?
Don't like to study for years and pay a fortune going to University?
Join Technician In A Box and learn how to run a Microsoft computer services business from home.

Learn from experts to deliver services like
Microsoft Windows performance optimization
Microsoft Windows security
Microsoft Windows data wiping
Microsoft Windows computer cleaning
Microsoft Windows office applications
Microsoft Windows application development
Microsoft Windows network installation
Microsoft Windows broadband installation
Microsoft Xbox repair
with 24x7 support in our private forum and more.

Latest Posts

  • How To Become A Computer Forensics Technician
  • How To Protect Yourself From Scareware
  • New Trojan Virus Targets PC Motherboards
  • Teen Hacker Gets A Job At Microsoft For Attacking Them
  • How to Protect Customers From HTML Spam

Privacy Statement

Terms of Use

Licence Agreement

  • Using the Web to help you get a job. http://t.co/SSeRGOK65G #Careers #findajobonline #YWB #Bizitalk about 2 days ago
  • Indie Game Development Part 4: Stress Management http://t.co/JNqz7TVerg #business #Careers #YWB #Bizitalk about 2 days ago
  • How to Create a Quick, Easy and Good Looking Background Pattern http://t.co/NeoUav4kRj #Design #Background #YWB #Bizitalk about 4 days ago
  • Young Web Builder
Top of Page
Copyright © 2013 TechnicianinaBox.com - Train to Become a Self Employed Computer Technician · Sitemap