Hacker News new | ask | show | jobs
by rainsil 1757 days ago
I didn't think typosquatting actually worked. I wonder if there's a general way to figure out the most common misspellings of a given domain name...
4 comments

Easier to just do bitsquatting: register all the domains that are one cosmic ray induced bit flip away from a common domain name, e.g. https://www.bleepingcomputer.com/news/security/hijacking-tra...
We did this for a customer and to see what leaks. It’s very surprising and sometimes very bad from a security perspective on popular and high traffic domains of service providers.
I remember when this hit HN a few months(?) back, for me it was the first time learning about this and I assumed this might be an obscure thing.

I ran the python script against my (very large) employer's domain name and was pleasantly surprised to see we owned all the bitsquatted versions already (there were maybe 10?)

I recall reading a story about someone who became legendary among squatters because he somehow managed to negotiate the rights to commercialize Colombia's TLD (.co), meaning he positioned himself to take a cut of every .com -> .co typosquat ever.

Here's the guy himself talking about it in a NYT article[0]

[0] https://www.nytimes.com/2012/07/01/jobs/from-dot-com-to-dot-...

Oh god, this sounds like it could be an interview question
Put each misspelling on top of a round hole and see if it falls in.
I could see this being a leetcode medium/hard level backtracking question.
it worked for that person because gmail.com is a hugely popular domain and they had gail.com before gmail was even created. nowadays much more competitive