Security Experts Disclose How ISPs' Typo-Domain Ad Systems are Major Security Holes

By CircleID Reporter

Seeking to make money from mistyped domains, some of the United States' largest ISPs instead created a massive security hole that allowed hackers to use domain names of eBay, PayPal, Google and Yahoo, and virtually any other large site. The vulnerability was a dream scenario for phishers and cyber attackers looking for convincing platforms to distribute fake websites or malicious code.

The hole was quickly and quietly patched last Friday after IOActive security researcher Dan Kaminsky reported the issue to Earthlink and its technology partner, a British ad company called Barefruit. Earthlink users, and some Comcast subscribers, were at risk.

Read Full Story: Wired News

See Related Topics: DNS, Domain Names, Security

This has been a featured post from CircleID Reporter. To stay updated with CircleID via Email, RSS, Mobile Handsets or Twitter, visit the CircleID Extras page.

Comments