Re: Phishing detection from FQDN's as prefixes
Anne van Kesteren <[email protected]> Thu, 10 Aug 2017 09:25:49 +0200
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CADnb78jRzqAwEj+8zXs=N0SenXyCoOa5oddE=XMwLji4_c+cag@mail.gmail.com> |
On Thu, Aug 10, 2017 at 2:57 AM, Francois Marier <[email protected]> wrote: > On 09/08/17 03:04 PM, Adam Shannon wrote: >> Has anyone looked into what some use cases are for using a FQDN as a prefix >> in a hostname? (Or even how common such names in use are?) I could imagine >> setting up a proxy or archival service with such a scheme: >> >> www.google.com.corp.com/search?q=flowers >> >> www.myblog.net.proxy.com?rev=2017-08-09 >> >> If a large percentage of hostnames with a FQDN prefix are phishing related >> it might be an initial pool for further research by agencies. > > These researchers have looked at a similar idea: > > https://dl.acm.org/citation.cfm?doid=1314389.1314391 It seems a variant of the UX I propose in https://bugzilla.mozilla.org/show_bug.cgi?id=1376641 could also help to alert the user of these type of attacks. -- https://annevankesteren.nl/