Your IP:

News & Notes from the OpenDNS team

'Typosquatting' Posts

The Domain Name System was developed more than 30 years ago as a way to ensure that the brilliant network we now know as the Internet could scale and see adoption. Before the DNS existed, Internet users would need to remember the IP address for every website on the Internet. Research has shown that seven digits tends to be the capacity for human memory (think phone numbers, sans area code) and IP addresses can be twelve — more now with IPv6. The DNS is part of the Internet’s infrastructure, earning it the somewhat unflattering analogy of the plumbing of the Internet. But in truth, its primary role has traditionally been that.

Recently ICANN, the global body that oversees the Internet and authors its policies, announced a plan to make available a throng of new top-level domains. Preexisting TLDs include .com, .net, .org, .co.uk, among many others. Twenty-two in total. The new ones are seemingly designed primarily to help businesses and spur economic activity. The new domains can be grouped into two classifications:

- .xxx: Designated for websites that include pornographic content as a way to easily differentiate them from non-pornographic sites.

- Generic TLDs, or “gTLDs”: Basically turns any brand or term into its own TLD. .Pepsi, .Apple, .Football or .Money, for example.

The release of both new groups of TLDs raises interesting issues for OpenDNS. Today we are the largest recursive DNS provider in the world, with more than 30 million people using our service. (Nearly doubling our traffic in the past 1.5 years.) We’re the innovator in the DNS space, as we introduced the concept of building security directly into the Domain Name System. Phishing protection came first, followed by typo-correction that helps people route around typo-squatting. Then Conficker protection and most recently, the most game-changing malware-blocking service, available to users to OpenDNS Enterprise.

But as we’ve seen countless times, with more ground to cover comes more fraud and crime. Many critics of ICANN’s move to add more domains see the potential for more:

- Cyber squatting, which is the practice of registering a domain using a trademarked brand that doesn’t belong to you. Highly annoying to Internet users and costly to brands.

- Typo squatting, which is like cyber squatting, but using a typo’d variation of the trademarked brand. Also highly annoying to Internet users and costly to brands.

- And generally more cyber crime and confusion among Internet users created by a change to the way domains are structured.

We’ve often said that the bad guys on the Internet tend to be one step ahead of the good guys, making the task of delivering an effective security service both very challenging and in a constant state of evolution. So when supporters of ICANN’s move argue that ICANN has no intention of allowing the new domains to act as a platform for crime, we can appreciate the perspective, but have little confidence that will ultimately be the case. Cyber squatting and cyber crime account for more than $1B in revenue annually, and when that kind of money is at stake, the bad guys find a way to be effective. Scott Pinzon, director of marketing and outreach at ICANN offers the perspective that, “new gTLDs represent a platform for innovation.” And goes on to say, “no one can predict what smart people will do with them. Lots of new business models will be invented. Some will work. Some won’t.” We agree with Scott, but also have a front row seat to the counterpart, sophisticated criminal activity that follows innovation.

Some of you will remember when the country of Cameroon was opportunistically assigned the .cm TLD and wildcarded all .cm domains. The country made a nice profit, but it confused masses of Internet users who’d accidentally made a typo when trying to get to a .com. We acted swiftly and delivered a feature that automatically redirected you to .com when you typed .cm.

In relation to the recent ICANN changes, there’s a great deal we can do as your DNS service to help ensure the Internet remains a safe place for you and yours to browse. It’s unclear at this point how successful these new domains will be and how much traction they’ll see, especially because at an upfront fee of $185k, the new gTLDS are not accessible to everyone.

Have thoughts on the topics above? Agree, or passionately disagree? Predictions for what kind of repercussions the Internet will see? We’d love to hear them in the comments.

How to Block .xxx Using OpenDNS:

In the immediate term, users of OpenDNS services with content filtering that want to block all .xxx domains on their networks can follow a few simple steps. Simply locate your “always block” or blacklist and add “xxx” (without the dot). Hit save and the change will take effect.

8 Comments | Filed in ccTLDs, DNS, General, Typos, Typosquatting

One of the many reasons more than 30 million people around the world choose OpenDNS is a feature called automatic typo correction.  It works by automatically redirecting common typos in top-level domains (.com, .net, .edu, etc.) to the right place, so if you type www.google.cmo, and that domain doesn’t exist, we just automatically take you to www.google.com.

Although this feature helps with a tremendous amount of typing mistakes and enables people to stay on-course online, an increasingly popular phenomenon called typosquatting means there are still typos we can’t fix, some of which are much more precarious than a dead end.  Typosquatting is what happens when someone registers a domain that’s nearly identical to that of a popular brand: Twtter.com and Twitter.com, for example. It banks on the idea that a fast-fingered typist may not notice that she’s arrived at the unintended site due to an omitted “i”. And since the typo exists in a real, registered domain, we don’t interfere.

Screenshot
Twtter.com is a particularly tricky example. In the case of this site, the typo — an omitted “i” — might not even be apparent at first glance.  The people who run this site are clearly trying to capture typo traffic destined for Twitter.com.  And regardless of the fact that the site has a URL redirect (the domain in the address bar changes after the site has been resolved), the blatant use of Twitter’s well-known design themes prove the site is aiming to fool people into thinking it’s the real website of Twitter.

Typosquatting is not new, but this sort of high-polish, branded version seems to be on the rise.  In the case of Twtter.com, the Twitter.com imposter, the site’s entire function is to get your contact information. A very appealing offer is presented to answer two survey questions and get what is, by all accounts, an awesome prize: an iPad2. It’s unclear what will happen with your personal information once it’s in the wrong hands — it could range anywhere from being used to send SMSs to your cell phone that you get charged for or simply selling your email address.

As with any online threat, protecting yourself and those people using the networks you manage starts with education.  Here are three tips for outsmarting typosquatting:

1. Use OpenDNS:  It’s the only service that will automatically correct common typos in TLDs, and help ensure you end up at the website you want.  OpenDNS solves a large portion of the problem, and also automatically blocks phishing websites.

2. Watch the address bar:  Legit websites rarely do redirections like Twtter.com does.  Keep an eye on what the site is doing and note suspicious redirects.  Also simply note the URL of the website you’re visiting after you’ve been taken there. Is the site the one you wanted? Did you make a typo?

3. Don’t share your personal information:  If a website offers you a chance to win a prize, simply for providing personal information or taking a survey, be skeptical.  You should never share your personal information online unless you’re on an extremely trusted website.

For businesses, schools and households alike, online safety is of the utmost importance. And it’s all about education.  Know what to look for and you can outsmart much of the bad stuff.  And use OpenDNS and tell others to do the same.

We’d love to hear your thoughts:  We’re considering an opt-in service that would let people avoid these kinds of unintended redirections.  Even in cases like that of Twtter.com, where technically it’s a real, registered website.  What do you think?  Would you use such a service?

29 Comments | Filed in General, privacy, Security, Twitter, Typos, Typosquatting

At last week’s Workshop on the Economics of Information Security — an annual conference held at Harvard — new research (PDF) was presented showing the link between pornography and malicious online practices. When the study’s researchers surveyed adult websites, they found that many were aimed at “manipulating and misleading a visitor to perform actions that result in an economic profit” for the Web site. Free sites used these tactics 34 percent of the time, while paid sites used them 11 percent of the time. What types of tactics are we talking about? According to the study, methods include:

  1. Javascript catchers that hijack the user’s browser, making it difficult to leave a site.
  2. Blind and hidden links that prevent an address from being displayed in a web browser’s status bar. This can be used to mask malicious activities, like cross site scripting or cross site request forgery attempts.
  3. Redirection scripts that redirect users to different websites. This occurs on a server, so there’s no way for a user to know it might happen until they click.
  4. Malware that triggers malicious behavior including “code execution, registry changes, or executable downloads.”

In addition to misleading activity, the level of malware found on adult Web sites was surprising to the researchers too; almost 3.5 percent of adult websites had this type of behavior, compared with previous studies that found less than one percent as malicious. Spyware and Trojan downloads were the most popular types of malware.

The good news is, it’s simple to block adult content and pornography with OpenDNS. In a couple of steps, you can nip the issue in the bud by blocking content you know causes issues on your computer and network. To block adult content, navigate to the Settings page and select the network you wish to manage. You’ll then see a Choose Your Filtering Level option under Content Filtering. To block all adult content, make sure to block the following five categories: Adult themes, Nudity, Sexuality, Pornography, and Tasteless.

Since we already block malware for all OpenDNS users (Enterprise users get more comprehensive coverage), blocking pornography is just one more step you can take to protect users on your network from coming in contact with malicious tactics online.

5 Comments | Filed in Adult site blocking, Domain Blocking, Phishing, Security, Typosquatting

Why do we pay Internet Bad Guys?

by David Ulevitch, Founder/CEO on Sep 13th, 2006

Courtesy of Matt Marshall, I was asked to contribute an article to VentureBeat. You can read my article, “Why do we pay Internet Bad Guys?,” in its entirety over there or below. Matt has some really great stuff on VentureBeat, so go check it out!


David Ulevitch, OpenDNS CEO

Two weeks ago Auren wrote a dead-on post about the Black Hat Tax that really struck a chord with me. I’ve been paying the Tax for five years with my first company, EveryDNS, and for a few months now with my current start-up, OpenDNS. The problem has become much worse in the last few years. Why? Simply put, bad guys are getting paid. Moreover, the Tax is on users as much as its on businesses. Today we see phishing sites, malware and spyware sites growing at an astounding rate.

Consider the example I cite often when discussing the issue with friends: goggle.com (see image below; not providing a link, bad site), the site that might be the most insidious of all typo squatting and malware sites on the Internet. Goggle.com, an obvious typo of google.com, offers an anti-spyware product called SpyBouncer in addition to being filled with pop-up ads (nb: SpyBouncer claims the copyright on the bottom of goggle.com). The website makes a user believe that their computer is currently infected with spyware and that installing SpyBouncer will get rid of it. They say it’s free to try and the program conveniently finds spyware which it will remove for a price, of course.

Symantec and others all claim that this product is a total scam and that it neither detects nor repairs spyware with any accuracy. Thanks to the accidental traffic that lands on goggle.com by unsuspecting users, SpyBouncer has no incentive to make a good product, they can just fool a new batch of users everyday.

Thumbnail of goggle.com screenshot, a bad site. Click through for larger image.

Why does a site like goggle.com exist? Because crime pays, but that’s hardly news. Why it doesn’t get shut down by its webhost (DataPipe) is a good question for another time. What I do want to know is… why is SpyBouncer allowed to run Google ads on its Web site (as they do on the top)? Why are these kinds of abusive software programs allowed to purchase AdWords campaigns luring even more users into this trap? Why is Revenue.net paying SpyBouncer to show ads on goggle.com? Why is Google accepting money from fraudulent advertisers which continues the cycle of malware and spyware? This is why users react so negatively to online advertising. It’s not the relevant and unoffensive advertising that they bemoan, it’s the scams and tricks the advertisers and advertising networks spread around the seedier neighborhoods of the Internet.

These kinds of abuse are pretty bad, but what bothers me more is that much of it is being facilitated by companies I respect and admire. People like Ben Edelman have done a lot of research showing the connections between companies like Yahoo and fraudulent advertising practices but that’s not enough. There are so many layers and levels of misdirection that it becomes hard to tell who is paying who and why. As the CEO of a company operating on the Internet, I’m spending money dealing with Internet bad guys who are getting paid to annoy me, my employees and my users. Everyone is wasting their time dealing with this crap while the folks in the money trail keep taking their cut and passing on the buck. When I asked my users what they thought about goggle.com I saw a nearly unanimous response of outrage and frustration. Hundreds of users spoke out on our corporate blog and on sites like Digg.com venting at the absurdity of a site like goggle.com.

It’s time that ad networks cleaned up their act and started being more transparent about fraud and abuse. It’s time security companies started fighting the causes of network abuse and not simply the symptoms. There will always be a Black Hat Tax but right now legitimate companies are making it more expensive. That has to stop.

7 Comments | Filed in David, General, Google, Media mentions, Typosquatting

Cameroon turns wildcarding on (yet again)

by David Ulevitch, Founder/CEO on Aug 21st, 2006

Cameroon is at it again, wildcarding all of the .cm namespace so they can put advertisements up when you typo .com domains like http://www.google.cm. Since August 9, OpenDNS users have had the option to undo this change and decide how they want it handled. There is an option on our preferences page where you can decide how you want this dealt with for your computer or network.

As a reminder, if you do turn on .cm to .com wildcard filtering, all real .cm domains will still work!. That includes domains like airfrance.cm and others that we listed.

We don’t know why Cameroon (or its operator) is flip-flopping on this one, but I’d encourage you to turn this preference on and leave it on.

5 Comments | Filed in ccTLDs, DNS, General, Typosquatting

.cm no longer a typo

by John Roberts on Aug 10th, 2006

Update: August 21, 2006 – Policies changed back for the .cm ccTLD. Read “Cameroon turns wildcarding on (yet again)” for more. We’re not going to keep updating this post with the status.

Earlier today, Cameroon (or the company acting on their behalf) turned off the wildcarding of non-registered domains within the .cm ccTLD. We’re still learning what’s going on, but at least for the moment, .cm domains resolve as they did before last Friday, August 4, 2006.

The OpenDNS preference introduced yesterday for filtering the .cm wildcarding still works, and will not disrupt any valid domain, whether or not wildcarding is active.

2 Comments | Filed in ccTLDs, General, Typosquatting

Cameroon takes the ‘o’ out of .com

by David Ulevitch, Founder/CEO on Aug 9th, 2006

Update: August 21, 2006 - Policies changed back for the .cm ccTLD. Read "Cameroon turns wildcarding on (yet again)" for more. We're not going to keep updating this post with the status.

Update: August 10, 2006 - Policies changed for the .cm ccTLD. Read ".cm is no longer a typo" for more.

Cameroon, a country on the western coast of Africa recently decided to put a wildcard entry in .cm, their IANA assigned Country-Code Top Level Domain (ccTLD). CNET has a pretty good article covering what they did.

Around the blogosphere people have asked us what we could do to fix it for them. I'm annoyed we have to deal with this, but happy that users are starting to realize that they need the ability to manage their DNS as a part of managing their network. The Cameroonian ccTLD operators (or the business they've outsourced this service to) makes the argument that they are "helping you" find what you're looking for. If they wanted to help you they'd just correct .cm to .com for all domains that didn't exist in the .cm namespace, or do nothing at all.

Some users have asked us how many .cm domains there are and what they might be. We have published a complete list (as of yesterday) of all .cm domains. We've gone through and shown that for such a small ccTLD they've already had quite a few parked domains in their zone. This list is at the bottom of this post. (This data is all public information, don't worry.)

How to act

Decide for yourself how you want .cm to work. With OpenDNS, you have a choice.

  • Already using OpenDNS? Head to the Account page.
  • Not yet using OpenDNS? Take two minutes and Get Started today.

Mini FAQ

Are you going to show me ads just like the .cm operator does?

No! We're doing this because you shouldn't be punished or distracted because you forgot to type an 'o' when surfing the net. We will seamlessly correct the full URL for you with no ads, popups, or page in the middle. By enabling the feature you know exactly what's going to happen: google.cm is going to take you to google.com.

Will I still get to real .cm domains if I turn on .cm wildcard filtering?

Yes! We will not filter real .cm domains such as www.airfrance.cm and others. It should also be noted we've never filtered any real domains, even with typo correction. The only exception is phishing sites that you've asked us to block.

Will you do this for other wildcarded ccTLDs like .ws, .ph and .cd?

You tell us. We are offering the fix for .cm because our users appreciate that we transparently correct mistyped domains like google.cm to google.com. For other wildcarded ccTLDs, we'll be listening to our users and offering useful choices based on those requests.

What if there are new valid .cm domains? Will those work?

Of course!

What happens if I turn off typo-correction and turn on .cm wildcard filtering?

If you turn off typo correction and turn on .cm wildcard filtering you will get an RCODE=3 DNS response (commonly called NXDOMAIN) as if the wildcard didn't exist. In your browser you'd get the default behavior which is probably either an MSN search page on IE, or a "host not found" page with Firefox.

Again, if you are already using OpenDNS just head to the Account page or take two minutes and Get Started today.

A listing of all .cm domains

Legend

Regular .cm Domain
Wildcard Of Entire Zone
Parked Page w/ Ads
Broken Or Misconfigured Zone

All domains in the Cameroon ccTLD “.cm”

(List accurate as of Tuesday, August 8, 2006)

All domains in .cmNameservers
*.cm. A 72.51.27.58
ac3l.cm.NSns1.premierspas.biz. ns2.premierspas.biz.
adsnet.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
afrique-france2001.cm.NSkim.camnet.cm. nina.afrique-france2001.cm.
airfrance.cm.NSwebaf1.airfrance.fr. lasvegas.airfrance.fr.
alizes.cm.NSpcsakon.alizes.cm.
amadeus.cm.NSns1.amadeus.cm. ns2.amadeus.cm.
amitybank.cm.NSns.amitybank.cm. ns2.iccnet.cm.
annuairecamtel.cm.NSkim.camnet.cm. mbam.camnet.cm.
anuel.cm.NSns1.infomaniak.ch. ns2.infomaniak.ch.
armp.cm.NSkim.camnet.cm. mbam.camnet.cm.
art.cm.NSdns1.creolink.com. dns2.creolink.com.
artac.cm.NSkim.camnet.cm. mbam.camnet.cm.
assemblee-nationale.cm.NSns1.cm.refer.org. aupelf.refer.org.
avis.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
bdanet.cm.NSkim.camnet.cm. sanaga.camnet.cm.
bicec.cm.NSbenoue.camnet.cm. sanaga.camnet.cm.
bosch.cm.NSgwa.fe.bosch.de. gwa2.fe.bosch.de.
britishcouncil.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
bureaulumiere.cm.NSkim.camnet.cm. mbam.camnet.cm.
cam-educ.cm.NSkim.camnet.cm. mbam.camnet.cm.
cameroon-tribune.cm.NSweb.cameroon-tribune.cm. ns1.iccnet2000.com.
cameroonfertilizers.cm.NSkim.camnet.cm. mbam.cmanet.cm.
cameroonhealthresearch.cm.NSns1.lnhi.net. ns2.lnhi.net.
cameroonscience.cm.NSns.cybernum.org. ns1.cybernum.org.
cami.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
camnet.cm.NSkim.camnet.cm. mbam.camnet.cm. benoue.camnet.cm. sanaga.camnet.cm.
camnet2.cm.NSns1.camnet2.cm.
camnet3.cm.NSns1.camnet3.cm.
campusvert.cm.NSns1.infomaniak.ch. ns2.infomaniak.ch.
camrail.cm.NSappolo.c-si.fr. ariane.c-si.fr.
camtel.cm.NSkim.camnet.cm. mbam.camnet.cm.
camteldla.cm.NSserver.camteldla.cm.
cbm.cm.NSkim.camnet.cm. netfinityyde.cbm.cm.
cenadi.cm.NSkim.camnet.cm. netstar.cenadi.cm. cenadim1.cenadi.cm.
cenet.cm.NSkim.camnet.cm. admin.cenet.cm.
cerac.cm.NSkim.camnet.cm. svrcerac.cerac.cm.
cfaogroup.cm.NSkim.camnet.cm. mbam.camnet.cm.
cheaptickets.cm.NSns.rackspace.com. ns2.rackspace.com.
cigate.cm.NScenadi.cigate.cm.
leslions.cm.cm.NSkim.camnet.cm. mbam.camnet.cm.
cnosc.cm.NSkim.camnet.cm. mbam.camnet.cm.
cnps.cm.NSfusih.cnps.cm.
fusih.cnps.cm.NS195.24.201.7.cm.
co.cm.NSkim.camnet.cm. tchad.co.cm.
congresrdpc.cm.NSlinsvr.congresrdpc.cm.
connect.cm.NSkim.camnet.cm. sanaga.camnet.cm.
corenofi.cm.NSkim.camnet.cm. sanaga.camnet.cm.
cpdmcongress.cm.NSlinsvr.cpdmcongress.cm.
credit-suisse-trust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
credit-swiss.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
creditlyonnais.cm.NSdns1.creolink.com. dns2.creolink.com.
creditsuisse-trust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
creditsuissetrust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
creditswiss.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
creolink.cm.NSdns1.creolink.cm. dns2.creolink.com.
crtv.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
cs-group.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
cs-life.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
cs-trust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
csam.cm.NSns-1.csfb.com. ns-2.csfb.com.
csfb.cm.NSns-1.csfb.com. ns-2.csfb.com.
csg.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
csgroup.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
cslife.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
cspb.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
cstrust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
ctpl.cm.NSkim.camnet.cm. mbam.camnet.cm.
cyberix.cm.NSns13.zoneedit.com. ns18.zoneedit.com.
dgre.cm.NSkim.camnet.cm. dgresvr.dgre.cm.
dictionary.cm.NSns.rackspace.com. ns2.rackspace.com.
diplocam.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
download.cm.NSns.rackspace.com. ns2.rackspace.com.
dpcminat.cm.NSkim.camnet.cm. mbam.camnet.cm.
dsx.cm.NSns1.douala1.com.
esstic-uy2.cm.NSdns1.esstic-uy2.cm.
europcar.cm.NSindom10.indomco.com. indom20.indomco.net.
fayadort.cm.NSkim.camnet.cm. mbam.camnet.cm.
fcb.cm.NSns.univerdi.com. ns1.univerdi.com.
finances.cm.NSminefi.finances.cm.
flowers.cm.NSns.rackspace.com. ns2.rackspace.com.
fne.cm.NSkim.camnet.cm. mbam.camnet.cm.
fonds-routier.cm.NSdns1.creolink.com. dns2.creolink.com.
france-cam.cm.NSkim.camnet.cm. aupelf.refer.org. serveur.cm.refer.org.
freshdelmonte.cm.NSns1.zodns.com. ns1.lanechange.net.
games.cm.NSns.rackspace.com. ns2.rackspace.com.
gcnet.cm.NSdja.gcnet.cm. kim.camnet.cm.
/*geocities.cm.NSns.levonline.com.
/*geocities.cm.NSns2.levonline.com.
/*geocities.cm.NSns3.levonline.com.*/.cm.
globalnet.cm.NSdns1.globalnet.cm. dns2.globalnet.cm.
gov.cm.NSkim.camnet.cm. mbapit.gov.cm.
minpostel.gov.cm.NSnyos.minpostel.gov.cm.
hgy.cm.NSweb.hgy.cm. mail.cameroun-online.com.
holcim.cm.NSns01ch.holcim.com. ns01us.holcim.com.
hotelsawa.cm.NSpartenariat.sni.cm.
hotjobs.cm.NSns1.ny.genx.net. ns2.ny.genx.net.
iccnet.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
icrafon.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
impots.cm.NSdi.impots.cm.
infotel.cm.NSdns1.globalnet.cm.
intelcam.cm.NSkim.camnet.cm. paatchi.intelcam.cm.
its.cm.NSits-smsserveur.its.cm.
joker.cm.NSbow.scm.cm. rva.fcr.francetelecom.fr.
kpmg-cmr.cm.NSsfacc.kpmg-cmr.cm.
lasvegas.cm.NSns.rackspace.com. ns2.rackspace.com.
lifttel.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
maetur.cm.NSns1.dnsjunction.com. ns2.dnsjunction.com.
messinaline.cm.NSdns1.fastweb.it.
microlog.cm.NSmississipi.microlog.cm.
minader.cm.NSserveur.minader.cm.
minef.cm.NSforest.minef.cm.
minepat.cm.NSsoo.minepat.cm. sanaga.minepat.cm.
minsante.cm.NSns1.dnsjunction.com. ns2.dnsjunction.com.
mobilis.cm.NSbow.scm.cm. rva.fcr.francetelecom.fr.
monster.cm.NSns.rackspace.com. ns2.rackspace.com.
mtn.cm.NSNs1.jev.co.za. Ns2.jev.co.za.
mtnns.cm.NSdns1.globalnet.cm. dns2.globalnet.cm.
navitrans.cm.NSdns1.fastweb.it.
netshop.cm.NSkim.camnet.cm. ops.netshop.cm.
oapi.cm.NSkim.camnet.cm. linux.oapi.cm.
oit.cm.NSkim.camnet.cm. sanaga.camnet.cm.
oms.cm.NSdns1.creolink.com. mailer.oms.cm.
onr.cm.NSkim.camnet.cm. mbam.camnet.cm.
onu.cm.NSinet01.cm.undp.org.
orange.cm.NSns0.orange.cm.
orangemail.cm.NSns0.orange.cm.
orangeworld.cm.NSns0.orange.cm.
paradis.cm.NSbenoue.camnet.cm. sanaga.camnet.cm.
pasteur.cm.NSns1.satwise.com. ns2.satwise.com.
pmuc.cm.NSbonanjo01.pmuc.cm. bonanjo02.pmuc.cm.
pr-gervaismendoze.cm.NSkim.camnet.cm. mbam.camnet.cm.
prc.cm.NSkim.camnet.cm. mbam.camnet.cm. lionsvr1.prc.cm. lionsvr2.prc.cm.
prcs.cm.NSkim.camnet.cm. sgpr-serv.prcs.cm.
presbyterian-church.cm.NSalpha2.officeco.ch. alpha3.officeco.ch.
radius.cm.NSdja.radius.cm.
razel.cm.NSkim.camnet.cm. ns1.razel.cm.
rdpcpdm.cm.NSrdpcserv.rdpcpdm.cm.
rdpcserv.rdpcpdm.cm.NSkim.camnet.cm.
realtor.cm.NSns.rackspace.com. ns2.rackspace.com.
refinance.cm.NSns.rackspace.com. ns2.rackspace.com.
rent.cm.NSns.rackspace.com. ns2.rackspace.com.
restaurants.cm.NSkim.camnet.cm. mbam.camnet.cm.
ric.cm.NSdns1.creolink.com.
rolex.cm.NSns1.gva.ch.colt.net. ns1.zrh1.ch.colt.net.
sabc.cm.NSns1.sabc.cm. ns2.sabc.cm.
scb-creditlyonnais.cm.NSkim.camnet.cm. scbclc.scb-creditlyonnais.cm.
scm.cm.NSbow.scm.cm. rva.fcr.francetelecom.fr.
sdnp.cm.NSkim.camnet.cm. tangmbo.sdnp.cm.
seanet.cm.NSns3.schlund.de. ns4.schlund.de. seanets.de.
sgbc.cm.NSns2.domicile.fr. ns3.domicile.fr.
sho-cameroun.cm.NSns1.douala1.com. ns2.douala1.com. ns3.douala1.com.
side.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
sigmakalon.cm.NSns2.iccnet.cm. ns30787.ovh.net.
simpay.cm.NSns2.lovellsnames.org. ns3.lovellsnames.org.
sinpay.cm.NSns2.lovellsnames.org. ns3.lovellsnames.org.
snac.cm.NSns3.slconseil.com. romeo.hebergement-discount.com. juliette.hebergement-discount.com.
snh.cm.NSkim.camnet.cm. snhnet.snh.cm.
sni.cm.NSns2.iccnet.cm. partenariat.sni.cm.
snv.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
socada.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
socapalm.cm.NSns2.iccnet.cm.
sodecoton.cm.NSns1.sodecoton.cm. ns2.sodecoton.cm.
sogecam.cm.NSns.fr.socgen.com. ns.socgen.com. dns.cadinet.ma.
sonara.cm.NSns1.sonara.cm. ns1.lanechange.net.
stanchart.cm.NSns.domainnetwork.se. ns2.domainnetwork.se.
standard-chartered.cm.NSns.domainnetwork.se. ns2.domainnetwork.se.
standardchartered.cm.NSns.domainnetwork.se. ns2.domainnetwork.se.
standardcharteredbank.cm.NSns.domainnetwork.se. ns2.domainnetwork.se.
statistics-cameroon.cm.NSkim.camnet.cm. mbamcamnet.cm.
sumoca.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
superdoll.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
synopsys.cm.NSauth50.ns.uu.net. asbestos.lmc.com. dnsmaster.synopsys.com. dnsmaster2.synopsys.com.
ticad-it.cm.NSns.ticad-it.cm.
tmc.cm.NSdns2.creolink.com.
total.cm.NSkim.camnet.cm. sanaga.camnet.cm.
tourisme.cm.NSns1.dnsjunction.com. ns2.dnsjunction.com.
creditsuisse.trust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
u-douala.cm.NSdns2.creolink.com.
ub.cm.NSns1.lanechange.net. ns2.lanechange.net. dns1.creolink.com. yaounde2.un.cm.
unilex.cm.NSbenoue.camnet.cm. sanaga.camnet.cm.
uninet.cm.NSdiamond.uninet.cm.
uy2-soa.cm.NSemergency.uy2-soa.cm. cum-uy2-soa.cm.
viasim.cm.NSns2.lovellsnames.org. ns3.lovellsnames.org.
worldbank.cm.NSdns1.worldbank.cm.
wwf.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
yahoo.cm.NSns1.yahoo.com. ns5.yahoo.com.

11 Comments | Filed in ccTLDs, DNS, General, Typosquatting

Subscribe

Get email updates:

Most Recent Posts

Search

OpenDNS Button

Use OpenDNS

Use this button on your site!

Archives

Categories