iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > F-Secure Dings Registrars Over Fake Domains
Search:
[ insider_reports_insider ]

F-Secure Dings Registrars Over Fake Domains



David Utter
Staff Writer
2006-12-07

SecurityProNews: Insider Reports Insider Reports RSS Feed


Dropping a well-known and trademarked name like "eBay" into a domain name registration should cause registrars to give them a glance and make sure they aren't being purchased by someone who is not entitled to use the term.

F-Secure Dings Registrars Over Fake Domains
Keeping phishers at bay

Mikko Hypponen of Helsinki-based F-Secure sees phishing URLs regularly as the company deals with various threats to its customers' electronic assets. In his view, maybe there should not be as many phony domains permitted to go live as there are today.

In an open letter to domain registrars everywhere, Hypponen asked why they blithely permit every application to go through the process unreviewed. "Even when the name is obviously going to be used for phishing?" he wondered.

Using the example of a newly-registered domain that blatantly misuses eBay's trademark, signin-ebay-c.com, and running a phishing site, Hypponen suggests that registrars take more responsibility for registrations beyond collecting their fee:

This fake site asks users for their eBay login names and passwords and then uses an unsecured email form at www.statesmanjournal.com to send the details via email to the attacker's email address: maildeusere@gmail.com.

Wouldn't it make sense for a registrar to filter such obvious registrations and have a real person review and approve them before they go through? At least check who the domain is being registered to in case it's obviously an imaginary person?

If registrars started doing this, it would shift the burden of responsibility from the registrant of a name to them. Lawsuits would definitely take place, and perhaps it's a bit surprising that here in the litigation-happy US of A we haven't seen someone who's been phished go after a registrar in court.

---
Tag:

Add to Del.icio.us | Digg | Reddit | Furl

Get all the updates -





About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds