News & Notes from the OpenDNS team

'Typosquatting' Posts

Why do we pay Internet Bad Guys?

by David Ulevitch on Sep 13th, 2006

Courtesy of Matt Marshall, I was asked to contribute an article to VentureBeat. You can read my article, “Why do we pay Internet Bad Guys?,” in its entirety over there or below. Matt has some really great stuff on VentureBeat, so go check it out!


David Ulevitch, OpenDNS CEO

Two weeks ago Auren wrote a dead-on post about the Black Hat Tax that really struck a chord with me. I’ve been paying the Tax for five years with my first company, EveryDNS, and for a few months now with my current start-up, OpenDNS. The problem has become much worse in the last few years. Why? Simply put, bad guys are getting paid. Moreover, the Tax is on users as much as its on businesses. Today we see phishing sites, malware and spyware sites growing at an astounding rate.

Consider the example I cite often when discussing the issue with friends: goggle.com (see image below; not providing a link, bad site), the site that might be the most insidious of all typo squatting and malware sites on the Internet. Goggle.com, an obvious typo of google.com, offers an anti-spyware product called SpyBouncer in addition to being filled with pop-up ads (nb: SpyBouncer claims the copyright on the bottom of goggle.com). The website makes a user believe that their computer is currently infected with spyware and that installing SpyBouncer will get rid of it. They say it’s free to try and the program conveniently finds spyware which it will remove for a price, of course.

Symantec and others all claim that this product is a total scam and that it neither detects nor repairs spyware with any accuracy. Thanks to the accidental traffic that lands on goggle.com by unsuspecting users, SpyBouncer has no incentive to make a good product, they can just fool a new batch of users everyday.

Thumbnail of goggle.com screenshot, a bad site. Click through for larger image.

Why does a site like goggle.com exist? Because crime pays, but that’s hardly news. Why it doesn’t get shut down by its webhost (DataPipe) is a good question for another time. What I do want to know is… why is SpyBouncer allowed to run Google ads on its Web site (as they do on the top)? Why are these kinds of abusive software programs allowed to purchase AdWords campaigns luring even more users into this trap? Why is Revenue.net paying SpyBouncer to show ads on goggle.com? Why is Google accepting money from fraudulent advertisers which continues the cycle of malware and spyware? This is why users react so negatively to online advertising. It’s not the relevant and unoffensive advertising that they bemoan, it’s the scams and tricks the advertisers and advertising networks spread around the seedier neighborhoods of the Internet.

These kinds of abuse are pretty bad, but what bothers me more is that much of it is being facilitated by companies I respect and admire. People like Ben Edelman have done a lot of research showing the connections between companies like Yahoo and fraudulent advertising practices but that’s not enough. There are so many layers and levels of misdirection that it becomes hard to tell who is paying who and why. As the CEO of a company operating on the Internet, I’m spending money dealing with Internet bad guys who are getting paid to annoy me, my employees and my users. Everyone is wasting their time dealing with this crap while the folks in the money trail keep taking their cut and passing on the buck. When I asked my users what they thought about goggle.com I saw a nearly unanimous response of outrage and frustration. Hundreds of users spoke out on our corporate blog and on sites like Digg.com venting at the absurdity of a site like goggle.com.

It’s time that ad networks cleaned up their act and started being more transparent about fraud and abuse. It’s time security companies started fighting the causes of network abuse and not simply the symptoms. There will always be a Black Hat Tax but right now legitimate companies are making it more expensive. That has to stop.

6 Comments | Filed in Google, Typosquatting, David, Media mentions, General

Cameroon turns wildcarding on (yet again)

by David Ulevitch on Aug 21st, 2006

Cameroon is at it again, wildcarding all of the .cm namespace so they can put advertisements up when you typo .com domains like http://www.google.cm. Since August 9, OpenDNS users have had the option to undo this change and decide how they want it handled. There is an option on our preferences page where you can decide how you want this dealt with for your computer or network.

As a reminder, if you do turn on .cm to .com wildcard filtering, all real .cm domains will still work!. That includes domains like airfrance.cm and others that we listed.

We don’t know why Cameroon (or its operator) is flip-flopping on this one, but I’d encourage you to turn this preference on and leave it on.

3 Comments | Filed in Typosquatting, ccTLDs, DNS, General

.cm no longer a typo

by John Roberts on Aug 10th, 2006

Update: August 21, 2006 - Policies changed back for the .cm ccTLD. Read “Cameroon turns wildcarding on (yet again)” for more. We’re not going to keep updating this post with the status.

Earlier today, Cameroon (or the company acting on their behalf) turned off the wildcarding of non-registered domains within the .cm ccTLD. We’re still learning what’s going on, but at least for the moment, .cm domains resolve as they did before last Friday, August 4, 2006.

The OpenDNS preference introduced yesterday for filtering the .cm wildcarding still works, and will not disrupt any valid domain, whether or not wildcarding is active.

2 Comments | Filed in Typosquatting, ccTLDs, General

Cameroon takes the 'o' out of .com

by David Ulevitch on Aug 9th, 2006

Update: August 21, 2006 - Policies changed back for the .cm ccTLD. Read "Cameroon turns wildcarding on (yet again)" for more. We're not going to keep updating this post with the status.

Update: August 10, 2006 - Policies changed for the .cm ccTLD. Read ".cm is no longer a typo" for more.

Cameroon, a country on the western coast of Africa recently decided to put a wildcard entry in .cm, their IANA assigned Country-Code Top Level Domain (ccTLD). CNET has a pretty good article covering what they did.

Around the blogosphere people have asked us what we could do to fix it for them. I'm annoyed we have to deal with this, but happy that users are starting to realize that they need the ability to manage their DNS as a part of managing their network. The Cameroonian ccTLD operators (or the business they've outsourced this service to) makes the argument that they are "helping you" find what you're looking for. If they wanted to help you they'd just correct .cm to .com for all domains that didn't exist in the .cm namespace, or do nothing at all.

Some users have asked us how many .cm domains there are and what they might be. We have published a complete list (as of yesterday) of all .cm domains. We've gone through and shown that for such a small ccTLD they've already had quite a few parked domains in their zone. This list is at the bottom of this post. (This data is all public information, don't worry.)

How to act

Decide for yourself how you want .cm to work. With OpenDNS, you have a choice.

  • Already using OpenDNS? Head to the Account page.
  • Not yet using OpenDNS? Take two minutes and Get Started today.

Mini FAQ

Are you going to show me ads just like the .cm operator does?

No! We're doing this because you shouldn't be punished or distracted because you forgot to type an 'o' when surfing the net. We will seamlessly correct the full URL for you with no ads, popups, or page in the middle. By enabling the feature you know exactly what's going to happen: google.cm is going to take you to google.com.

Will I still get to real .cm domains if I turn on .cm wildcard filtering?

Yes! We will not filter real .cm domains such as www.airfrance.cm and others. It should also be noted we've never filtered any real domains, even with typo correction. The only exception is phishing sites that you've asked us to block.

Will you do this for other wildcarded ccTLDs like .ws, .ph and .cd?

You tell us. We are offering the fix for .cm because our users appreciate that we transparently correct mistyped domains like google.cm to google.com. For other wildcarded ccTLDs, we'll be listening to our users and offering useful choices based on those requests.

What if there are new valid .cm domains? Will those work?

Of course!

What happens if I turn off typo-correction and turn on .cm wildcard filtering?

If you turn off typo correction and turn on .cm wildcard filtering you will get an RCODE=3 DNS response (commonly called NXDOMAIN) as if the wildcard didn't exist. In your browser you'd get the default behavior which is probably either an MSN search page on IE, or a "host not found" page with Firefox.

Again, if you are already using OpenDNS just head to the Account page or take two minutes and Get Started today.

A listing of all .cm domains

Legend

Regular .cm Domain
Wildcard Of Entire Zone
Parked Page w/ Ads
Broken Or Misconfigured Zone

All domains in the Cameroon ccTLD “.cm”

(List accurate as of Tuesday, August 8, 2006)

All domains in .cmNameservers
*.cm. A 72.51.27.58
ac3l.cm.NSns1.premierspas.biz. ns2.premierspas.biz.
adsnet.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
afrique-france2001.cm.NSkim.camnet.cm. nina.afrique-france2001.cm.
airfrance.cm.NSwebaf1.airfrance.fr. lasvegas.airfrance.fr.
alizes.cm.NSpcsakon.alizes.cm.
amadeus.cm.NSns1.amadeus.cm. ns2.amadeus.cm.
amitybank.cm.NSns.amitybank.cm. ns2.iccnet.cm.
annuairecamtel.cm.NSkim.camnet.cm. mbam.camnet.cm.
anuel.cm.NSns1.infomaniak.ch. ns2.infomaniak.ch.
armp.cm.NSkim.camnet.cm. mbam.camnet.cm.
art.cm.NSdns1.creolink.com. dns2.creolink.com.
artac.cm.NSkim.camnet.cm. mbam.camnet.cm.
assemblee-nationale.cm.NSns1.cm.refer.org. aupelf.refer.org.
avis.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
bdanet.cm.NSkim.camnet.cm. sanaga.camnet.cm.
bicec.cm.NSbenoue.camnet.cm. sanaga.camnet.cm.
bosch.cm.NSgwa.fe.bosch.de. gwa2.fe.bosch.de.
britishcouncil.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
bureaulumiere.cm.NSkim.camnet.cm. mbam.camnet.cm.
cam-educ.cm.NSkim.camnet.cm. mbam.camnet.cm.
cameroon-tribune.cm.NSweb.cameroon-tribune.cm. ns1.iccnet2000.com.
cameroonfertilizers.cm.NSkim.camnet.cm. mbam.cmanet.cm.
cameroonhealthresearch.cm.NSns1.lnhi.net. ns2.lnhi.net.
cameroonscience.cm.NSns.cybernum.org. ns1.cybernum.org.
cami.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
camnet.cm.NSkim.camnet.cm. mbam.camnet.cm. benoue.camnet.cm. sanaga.camnet.cm.
camnet2.cm.NSns1.camnet2.cm.
camnet3.cm.NSns1.camnet3.cm.
campusvert.cm.NSns1.infomaniak.ch. ns2.infomaniak.ch.
camrail.cm.NSappolo.c-si.fr. ariane.c-si.fr.
camtel.cm.NSkim.camnet.cm. mbam.camnet.cm.
camteldla.cm.NSserver.camteldla.cm.
cbm.cm.NSkim.camnet.cm. netfinityyde.cbm.cm.
cenadi.cm.NSkim.camnet.cm. netstar.cenadi.cm. cenadim1.cenadi.cm.
cenet.cm.NSkim.camnet.cm. admin.cenet.cm.
cerac.cm.NSkim.camnet.cm. svrcerac.cerac.cm.
cfaogroup.cm.NSkim.camnet.cm. mbam.camnet.cm.
cheaptickets.cm.NSns.rackspace.com. ns2.rackspace.com.
cigate.cm.NScenadi.cigate.cm.
leslions.cm.cm.NSkim.camnet.cm. mbam.camnet.cm.
cnosc.cm.NSkim.camnet.cm. mbam.camnet.cm.
cnps.cm.NSfusih.cnps.cm.
fusih.cnps.cm.NS195.24.201.7.cm.
co.cm.NSkim.camnet.cm. tchad.co.cm.
congresrdpc.cm.NSlinsvr.congresrdpc.cm.
connect.cm.NSkim.camnet.cm. sanaga.camnet.cm.
corenofi.cm.NSkim.camnet.cm. sanaga.camnet.cm.
cpdmcongress.cm.NSlinsvr.cpdmcongress.cm.
credit-suisse-trust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
credit-swiss.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
creditlyonnais.cm.NSdns1.creolink.com. dns2.creolink.com.
creditsuisse-trust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
creditsuissetrust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
creditswiss.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
creolink.cm.NSdns1.creolink.cm. dns2.creolink.com.
crtv.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
cs-group.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
cs-life.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
cs-trust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
csam.cm.NSns-1.csfb.com. ns-2.csfb.com.
csfb.cm.NSns-1.csfb.com. ns-2.csfb.com.
csg.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
csgroup.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
cslife.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
cspb.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
cstrust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
ctpl.cm.NSkim.camnet.cm. mbam.camnet.cm.
cyberix.cm.NSns13.zoneedit.com. ns18.zoneedit.com.
dgre.cm.NSkim.camnet.cm. dgresvr.dgre.cm.
dictionary.cm.NSns.rackspace.com. ns2.rackspace.com.
diplocam.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
download.cm.NSns.rackspace.com. ns2.rackspace.com.
dpcminat.cm.NSkim.camnet.cm. mbam.camnet.cm.
dsx.cm.NSns1.douala1.com.
esstic-uy2.cm.NSdns1.esstic-uy2.cm.
europcar.cm.NSindom10.indomco.com. indom20.indomco.net.
fayadort.cm.NSkim.camnet.cm. mbam.camnet.cm.
fcb.cm.NSns.univerdi.com. ns1.univerdi.com.
finances.cm.NSminefi.finances.cm.
flowers.cm.NSns.rackspace.com. ns2.rackspace.com.
fne.cm.NSkim.camnet.cm. mbam.camnet.cm.
fonds-routier.cm.NSdns1.creolink.com. dns2.creolink.com.
france-cam.cm.NSkim.camnet.cm. aupelf.refer.org. serveur.cm.refer.org.
freshdelmonte.cm.NSns1.zodns.com. ns1.lanechange.net.
games.cm.NSns.rackspace.com. ns2.rackspace.com.
gcnet.cm.NSdja.gcnet.cm. kim.camnet.cm.
/*geocities.cm.NSns.levonline.com.
/*geocities.cm.NSns2.levonline.com.
/*geocities.cm.NSns3.levonline.com.*/.cm.
globalnet.cm.NSdns1.globalnet.cm. dns2.globalnet.cm.
gov.cm.NSkim.camnet.cm. mbapit.gov.cm.
minpostel.gov.cm.NSnyos.minpostel.gov.cm.
hgy.cm.NSweb.hgy.cm. mail.cameroun-online.com.
holcim.cm.NSns01ch.holcim.com. ns01us.holcim.com.
hotelsawa.cm.NSpartenariat.sni.cm.
hotjobs.cm.NSns1.ny.genx.net. ns2.ny.genx.net.
iccnet.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
icrafon.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
impots.cm.NSdi.impots.cm.
infotel.cm.NSdns1.globalnet.cm.
intelcam.cm.NSkim.camnet.cm. paatchi.intelcam.cm.
its.cm.NSits-smsserveur.its.cm.
joker.cm.NSbow.scm.cm. rva.fcr.francetelecom.fr.
kpmg-cmr.cm.NSsfacc.kpmg-cmr.cm.
lasvegas.cm.NSns.rackspace.com. ns2.rackspace.com.
lifttel.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
maetur.cm.NSns1.dnsjunction.com. ns2.dnsjunction.com.
messinaline.cm.NSdns1.fastweb.it.
microlog.cm.NSmississipi.microlog.cm.
minader.cm.NSserveur.minader.cm.
minef.cm.NSforest.minef.cm.
minepat.cm.NSsoo.minepat.cm. sanaga.minepat.cm.
minsante.cm.NSns1.dnsjunction.com. ns2.dnsjunction.com.
mobilis.cm.NSbow.scm.cm. rva.fcr.francetelecom.fr.
monster.cm.NSns.rackspace.com. ns2.rackspace.com.
mtn.cm.NSNs1.jev.co.za. Ns2.jev.co.za.
mtnns.cm.NSdns1.globalnet.cm. dns2.globalnet.cm.
navitrans.cm.NSdns1.fastweb.it.
netshop.cm.NSkim.camnet.cm. ops.netshop.cm.
oapi.cm.NSkim.camnet.cm. linux.oapi.cm.
oit.cm.NSkim.camnet.cm. sanaga.camnet.cm.
oms.cm.NSdns1.creolink.com. mailer.oms.cm.
onr.cm.NSkim.camnet.cm. mbam.camnet.cm.
onu.cm.NSinet01.cm.undp.org.
orange.cm.NSns0.orange.cm.
orangemail.cm.NSns0.orange.cm.
orangeworld.cm.NSns0.orange.cm.
paradis.cm.NSbenoue.camnet.cm. sanaga.camnet.cm.
pasteur.cm.NSns1.satwise.com. ns2.satwise.com.
pmuc.cm.NSbonanjo01.pmuc.cm. bonanjo02.pmuc.cm.
pr-gervaismendoze.cm.NSkim.camnet.cm. mbam.camnet.cm.
prc.cm.NSkim.camnet.cm. mbam.camnet.cm. lionsvr1.prc.cm. lionsvr2.prc.cm.
prcs.cm.NSkim.camnet.cm. sgpr-serv.prcs.cm.
presbyterian-church.cm.NSalpha2.officeco.ch. alpha3.officeco.ch.
radius.cm.NSdja.radius.cm.
razel.cm.NSkim.camnet.cm. ns1.razel.cm.
rdpcpdm.cm.NSrdpcserv.rdpcpdm.cm.
rdpcserv.rdpcpdm.cm.NSkim.camnet.cm.
realtor.cm.NSns.rackspace.com. ns2.rackspace.com.
refinance.cm.NSns.rackspace.com. ns2.rackspace.com.
rent.cm.NSns.rackspace.com. ns2.rackspace.com.
restaurants.cm.NSkim.camnet.cm. mbam.camnet.cm.
ric.cm.NSdns1.creolink.com.
rolex.cm.NSns1.gva.ch.colt.net. ns1.zrh1.ch.colt.net.
sabc.cm.NSns1.sabc.cm. ns2.sabc.cm.
scb-creditlyonnais.cm.NSkim.camnet.cm. scbclc.scb-creditlyonnais.cm.
scm.cm.NSbow.scm.cm. rva.fcr.francetelecom.fr.
sdnp.cm.NSkim.camnet.cm. tangmbo.sdnp.cm.
seanet.cm.NSns3.schlund.de. ns4.schlund.de. seanets.de.
sgbc.cm.NSns2.domicile.fr. ns3.domicile.fr.
sho-cameroun.cm.NSns1.douala1.com. ns2.douala1.com. ns3.douala1.com.
side.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
sigmakalon.cm.NSns2.iccnet.cm. ns30787.ovh.net.
simpay.cm.NSns2.lovellsnames.org. ns3.lovellsnames.org.
sinpay.cm.NSns2.lovellsnames.org. ns3.lovellsnames.org.
snac.cm.NSns3.slconseil.com. romeo.hebergement-discount.com. juliette.hebergement-discount.com.
snh.cm.NSkim.camnet.cm. snhnet.snh.cm.
sni.cm.NSns2.iccnet.cm. partenariat.sni.cm.
snv.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
socada.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
socapalm.cm.NSns2.iccnet.cm.
sodecoton.cm.NSns1.sodecoton.cm. ns2.sodecoton.cm.
sogecam.cm.NSns.fr.socgen.com. ns.socgen.com. dns.cadinet.ma.
sonara.cm.NSns1.sonara.cm. ns1.lanechange.net.
stanchart.cm.NSns.domainnetwork.se. ns2.domainnetwork.se.
standard-chartered.cm.NSns.domainnetwork.se. ns2.domainnetwork.se.
standardchartered.cm.NSns.domainnetwork.se. ns2.domainnetwork.se.
standardcharteredbank.cm.NSns.domainnetwork.se. ns2.domainnetwork.se.
statistics-cameroon.cm.NSkim.camnet.cm. mbamcamnet.cm.
sumoca.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
superdoll.cm.NSns1.delta-informatique.com. douala.adsnet.cm.
synopsys.cm.NSauth50.ns.uu.net. asbestos.lmc.com. dnsmaster.synopsys.com. dnsmaster2.synopsys.com.
ticad-it.cm.NSns.ticad-it.cm.
tmc.cm.NSdns2.creolink.com.
total.cm.NSkim.camnet.cm. sanaga.camnet.cm.
tourisme.cm.NSns1.dnsjunction.com. ns2.dnsjunction.com.
creditsuisse.trust.cm.NSns-1.credit-suisse.com. ns-2.credit-suisse.com.
u-douala.cm.NSdns2.creolink.com.
ub.cm.NSns1.lanechange.net. ns2.lanechange.net. dns1.creolink.com. yaounde2.un.cm.
unilex.cm.NSbenoue.camnet.cm. sanaga.camnet.cm.
uninet.cm.NSdiamond.uninet.cm.
uy2-soa.cm.NSemergency.uy2-soa.cm. cum-uy2-soa.cm.
viasim.cm.NSns2.lovellsnames.org. ns3.lovellsnames.org.
worldbank.cm.NSdns1.worldbank.cm.
wwf.cm.NSns2.iccnet.cm. ns3.iccnet.cm.
yahoo.cm.NSns1.yahoo.com. ns5.yahoo.com.

10 Comments | Filed in Typosquatting, ccTLDs, DNS, General

Subscribe

RSS Feed

Get email updates:

Most Recent Posts

Search

OpenDNS Button

Use OpenDNS

Use this button on your site!

Archives

Categories