Researchers at Microsoft Corp. have blown the lid off a large-scale, typo-squatting scheme that uses multi-layer URL redirection to game Google's AdSense for domains program.
The scheme was uncovered when Redmond lab rats decided to extend its HoneyMonkey exploit detection system, a project that runs automatic and systematic Web scans to investigate the seedier side of the Internet.
With the new Strider Typo-Patrol System, the Microsoft Research Systems Management Research Group was able to track down a ring of typo-squatters registering misspelled domain names and generating traffic to serve advertising from Google.
Using five programmatic typo-generation models, the researchers pinpointed a series of domain-registration structures being used by "major typo-squatters" to steal traffic from some of the biggest Internet brands, including Amazon.com, Expedia.com and Mapquest.com.
The scheme was traced to Unasi Inc., a company registered in Panama. Almost all of the misspelled URLs found are parked with Oingo.com, a domain parking server owned by Google Inc.
According to data from Microsoft, domain names are being registered with deliberate missing-dot typos, character omission typos, character permutation typos, character replacement typos and character insertion typos.
For example, instead of the legitimate "www.microsoft.com," the domain "www.microsokft.com" has been registered and set up to redirect to another misspelled domain that currently serves up Google AdSense advertising for software products.
http://addict3d.org/index.php?page=viewarticle&type=news&ID=14860&title=Google%20to%20supports%20promoting%20scammers?!
The scheme was uncovered when Redmond lab rats decided to extend its HoneyMonkey exploit detection system, a project that runs automatic and systematic Web scans to investigate the seedier side of the Internet.
With the new Strider Typo-Patrol System, the Microsoft Research Systems Management Research Group was able to track down a ring of typo-squatters registering misspelled domain names and generating traffic to serve advertising from Google.
Using five programmatic typo-generation models, the researchers pinpointed a series of domain-registration structures being used by "major typo-squatters" to steal traffic from some of the biggest Internet brands, including Amazon.com, Expedia.com and Mapquest.com.
The scheme was traced to Unasi Inc., a company registered in Panama. Almost all of the misspelled URLs found are parked with Oingo.com, a domain parking server owned by Google Inc.
According to data from Microsoft, domain names are being registered with deliberate missing-dot typos, character omission typos, character permutation typos, character replacement typos and character insertion typos.
For example, instead of the legitimate "www.microsoft.com," the domain "www.microsokft.com" has been registered and set up to redirect to another misspelled domain that currently serves up Google AdSense advertising for software products.
http://addict3d.org/index.php?page=viewarticle&type=news&ID=14860&title=Google%20to%20supports%20promoting%20scammers?!














