Most Parked Domains Now Serving Malicious Content (krebsonsecurity.com) 37
An anonymous reader quotes a report from KrebsOnSecurity: Direct navigation -- the act of visiting a website by manually typing a domain name in a web browser -- has never been riskier: A new study finds the vast majority of "parked" domains -- mostly expired or dormant domain names, or common misspellings of popular websites -- are now configured to redirect visitors to sites that foist scams and malware. When Internet users try to visit expired domain names or accidentally navigate to a lookalike "typosquatting" domain, they are typically brought to a placeholder page at a domain parking company that tries to monetize the wayward traffic by displaying links to a number of third-party websites that have paid to have their links shown.
A decade ago, ending up at one of these parked domains came with a relatively small chance of being redirected to a malicious destination: In 2014, researchers found (PDF) that parked domains redirected users to malicious sites less than five percent of the time -- regardless of whether the visitor clicked on any links at the parked page. But in a series of experiments over the past few months, researchers at the security firm Infoblox say they discovered the situation is now reversed, and that malicious content is by far the norm now for parked websites. "In large scale experiments, we found that over 90% of the time, visitors to a parked domain would be directed to illegal content, scams, scareware and anti-virus software subscriptions, or malware, as the 'click' was sold from the parking company to advertisers, who often resold that traffic to yet another party," Infoblox researchers wrote in a paper published today.
A decade ago, ending up at one of these parked domains came with a relatively small chance of being redirected to a malicious destination: In 2014, researchers found (PDF) that parked domains redirected users to malicious sites less than five percent of the time -- regardless of whether the visitor clicked on any links at the parked page. But in a series of experiments over the past few months, researchers at the security firm Infoblox say they discovered the situation is now reversed, and that malicious content is by far the norm now for parked websites. "In large scale experiments, we found that over 90% of the time, visitors to a parked domain would be directed to illegal content, scams, scareware and anti-virus software subscriptions, or malware, as the 'click' was sold from the parking company to advertisers, who often resold that traffic to yet another party," Infoblox researchers wrote in a paper published today.
scum all day (Score:5, Insightful)
A lot of people think that social networks are the lowest form of shit on the internet, but in fact it's domain squatters. The practice should be illegal, punishable by both fines and being forced to sell the domain in an open auction for whatever the market will bear or relinquish it without recompense within 30 days.
Re: (Score:3)
So you're just going to seize somebody's because you've decided that you don't like how they're using it?
No, they're going to sell it to the highest bidder. You're going to need a tune-up on your translation software, Ivan.
Re: scum all day (Score:2)
So the picture I'm getting is that the anti rsilvergun trolls are paid Russians. Weird.
Re: (Score:2)
Sure dummy. China good, Russia bad, go figure.
Point to where I said China good, troll.
Re:scum all day (Score:4, Informative)
No, they're going to seize a domain because it's being used *to commit a crime*. That's a big difference.
Re: (Score:2)
At the very least, being an attractive nuisance, where even if the initial ad placement is legal, it serves illegal content enough to be a problem.
Re: (Score:3)
If you're selling (or just giving away) copyrighted content, they will seize your domain, and then go about trying to sue or arrest you.
So it's just who did you offend. You and me, getting malware because we tried an old site? Feh, as if they care. Sports league, yeah, we gonna hunt you. Movie studio, cut your Internet access off, suer you for billions, can we put you in jail?
It's just who you offend. And it's not just about the Internet...
Re: (Score:2)
Actually, it's domain registrars who 'park' domains and sell the access to scum.
Re: (Score:2)
Actually, it's domain registrars who 'park' domains and sell the access to scum.
ACKTUALLY they are far from the only offenders.
Re: (Score:2)
Being one of many does not make you less guilty.
Re: (Score:2)
Being one of many does not make you less guilty.
What it does is make your statement false and reveal your ignorance.
Re: scum all day (Score:2)
And I live rent free in your head. Honestly, is that all there is for you?
Re: (Score:2)
It's amazing how enthusiastically you miss the point over and over again. It's almost like you're stupid.
Re: scum all day (Score:2)
And all this time I thought the point was you were trying to prove how clever you were, how stupid I am, how I don't get it, and how you are just superior. Which of course you don't think I get because I don't believe you. Why would I? Why would you believe me if I said the same things to you? We all think we're right. And in the end it's all a big whoosh.
Re: (Score:2)
I wasn't trying to prove anything, I was commenting on your exchange and making an observation about your deliberate disingenuousness and/or inability to focus.
Re: (Score:2)
That was not the argument.
When you can maintain a train of thought long enough to have a meaningful one, come on back and I'll make it obvious you're clueless without having to feel bad about it.
how'd it take this long? (Score:4, Interesting)
What shocks me here is how long it took to become such a popular thing? Parking domains isn't that expensive, but certainly isn't free, especially in large numbers. The people doing the parking are basically squatting on property they speculate will have value down the road. They may as well collect a little "rent" on them while they squat?
I can remember when "domain tasting" first became a thing, I looked at it and thought, "This is a TERRIBLE idea, it's going to make it more expensive for people to start up their own web site and 'interesting' domains are going to be unobtainable by the average person just because some squatter thinks they're parked on gold." No random person is going to pay thousands of dollars for a domain name they fancy just for a hobby, so it's just going to stifle small private sites.
I don't know how it currently works, but back when it started you could "taste" a domain for months almost for free, and there was nothing stopping you from "tasting" it again the instant your current taste expired, So you could squat domains for an unlimited time almost for free. "gee, nobody would ever abuse that!"
Though now with the explosion of TLDs, it's widened the market so far that the squatters are finding it hard to cover all the bases. Raise their rent! (and make the price go up exponentially to KEEP it parked) Watch the squatters scurry away like the cockroaches they are!
Happened to me yesterday (Score:2)
Internet advertising meets malware (Score:2)
You will never find a more wretched hive of scum and villainy. We must be cautious.
Root of the problem (Score:1)
Its people typing in domains, and going to random websites, yeah that's the problem! /sarc. More like its that the world wide web has become a transfer of executables, such that you can basically run an OS https://www.windows93.net/ [windows93.net] just think of the possibilities of running that level of code over just a basic document like how things used to be
Re: (Score:2)
Agreed. What's needed is a way to do essentially the same thing as AJAX without any client JS. There would be more latency with the processing happening on the server side, but that's an acceptable tradeoff for many purposes where it doesn't matter much.
My research supports their conclusions (Score:5, Interesting)
It's really that bad. And it's going to stay that bad, because everyone involved -- ICANN, registrars, hosts -- is making a fortune off this.
Defending against this is difficult, but one useful tactic is to use DNS RPZ to block resolution of entire TLDs, e.g.,
Re: (Score:2)
Though we shouldn't have to. Companies like GoDaddy need to get up off their asses.
Re: (Score:2)
Companies like GoDaddy need to get up off their asses.
Companies like GoDaddy got up off their asses and sold domains as they were permitted to do. They aren't required to do any diligence beyond recording ostensible contact information which they aren't required to verify.
Re: (Score:2)
Nevermind registrars used to provide domain parkers with heads up notices that an expired domain will be coming up so they can grab them first instead of letting them expire and someone else grabbing them. This includes domains by other domain parkers, so you end up a domain changing hands as each gives it a try to "win the jackpot".
I've seen some sites that were parked because they expired, and they wanted like $1250 for it. Not sure how they came up with that figure, as it was a relatively obscure domain
Indeed. Look at sun.com (Score:5, Funny)
Takes you to Oracle!
Re: (Score:2)
Re: (Score:2)
Whoooosssh....
All on Google (Score:2)
Funny how Google's role is basically a footnote at the end of Krebs' article. "Infoblox also pointed out that recent policy changes by Google may have inadvertently increased the risk"
Over 20-25 years Google pushed for and normalized a system which prevented domain owners from having any control over the content on their parked sites. That was marginally acceptable when it was Google controlling the sites, but now that they're gone it leaves the doors wide open to abusive actors.
Google bought Oingo over 20
A DNS redo is waaaay overdue ... (Score:2)
... as is a redo of the Web itself. We need decoupled namecoin/blockchain bases DNS combined with some WebFS-style offline capable thing. Perhaps even a redo of HTML and Web renderers themselves, they are a historically grown mess. Most of the Web and E-Mail (over 90%) these days is just trackers, scam and juck-ridden garbage.