Phish-friendly domain registry ".top" put on notice
krebsonsecurity.com
krebsonsecurity.com
A few days later we started putting together a web page, and I noticed that .zip actually is available as a TLD. Impulsively I bought the domain, https://3dgs.zip/, launched it and printed it on a few shirts before heading off to a conference. Felt a bit weird that there is a .zip TLD, but I was in a rush and I didn’t ponder its existence any further.
But strange things started happening: setting up the domain for a GitHub page worked, but in the process downloaded a 0 Byte file called “3dgs.zip”, when submitting content one of the GitHub.com forms. And a few days later colleagues told me they had trouble accessing the site. After some DNS sleuthing and then some back-and-forth with our IT dept, it turned out that our organization has blocked the whole TLD - for every Windows user, out of phishing concerns of people being confused.
I’m no security person, so the reasoning felt a bit weird to me, as I guess the .zip TLD can’t hurt anybody; downloading a .zip might, which you can attach to any link name? But in any case I wasn’t able to find any .zip URL with a purpose, but lots of Reddit posts of angry sysadmins who bemoaned the influx of terrible TLDs with mostly phishing use and vowed to block them all. So they probably have a point in downright blocking the whole TLD.
Now I’m sitting here with my .zip url. Had to revert the page to use github.io, so people in my organization (and similarly thinking ones) would be able to access it. Guess I’m cured for a while, won’t be using any novelty TLDs anytime soon…
There are dozens of unique opens per week.
I'm very curious how an executable would do, but I'm not trying to cause any problems.
https://en.wikipedia.org/wiki/ILOVEYOU
:D
Demo for ZorusTech DNS blocker: https://www.youtube.com/watch?v=MeubLoEHW9E
The problem is auto-linkification. It is extremely common in forum posts or emails to refer to attached filenames. Most forum softwares or email clients are helpful it automatically turning obvious URLs (doesn't start with a protocol:// but ends in a .tld) into clickable links. Anybody's reference to a zip filename is now a clickable link, only waiting to be registered for phishing attempts.
I don't know if you can say the same about zip files, an average user they might encounter someone mentioning a zip filename a handful of times in a year and they might click on the link expecting to get that zip file.
And you're someone who's tech-savvy.
Most people are going to see ".com" and think "Website" not "Program". So if suddenly a .com file is downloaded there's at least a chance they might stop and wonder what's going on.
I run into this issue all the time - We get Bug bounty reports constantly because $SecurityResearcher put "example.com" into the "Company Name" field, and we sent them an email saying "Thanks for signing up. We hope you find $OurProduct useful at $CompanyName. "
When the email turns up in their Gmail inbox, Gmail "helpfully" turns the plain text "example.com" into a link to https://example.com - so $SecurityResearcher reports it to us as a vulnerability in our platform because "we" are linking to example.com - except we never did, and we have no way to tell Gmail, or Outlook, or any other platform to stop doing that.
Services we pay for, directly, also do this - Notion and Slack are two I can think of immediately. I have to fight them to stop turning my mention of some file into a link to a random domain. (e: Maybe Slack has stopped doing this, perhaps - in testing it didn't do automatic linkifying for messages to myself)
This was bad enough with .cs, .ts, .js., .json and so forth - but having a .zip link appear in the middle of documentation on how to do something with a zip file is a recipe for disaster.
I've had a document saying "please download package.zip from the build artifacts site" - which was then auto linked to https://package.zip - and anyone not paying attention might expect that it was a link to the build artifacts site.
If that domain is "important-banking-info.zip" then people are less likely to be suspicious if their browser happens to download a file of the same name.
[0] https://en.wikipedia.org/wiki/COM_file#Malicious_usage_of_th...
MZ is the magic number at the start of the file.
Although gp probably meant a PE executable [0] which (typically) start with a stub MZ executable telling DOS users to run it under Windows. Because of this they still have a MZ magic number.
I have recently been working on a command line tool and the windows version is called mz.exe. On Linux it is just 'mz', just a coincidence. I was concerned this name collision might cause problems, but that is fine.
And had to have people point out to me that they don’t want to click on that, because they don’t want to download a big file.
Who's auto-linkifying .zip domains?
Turn of all of your developer knowledge for a minute.
You click on a link "very-trustworthy-ceo-information.zip" in a mail, since you want to download this very important information from your CEO. Sure, your browser pops up, but it does that all the time so who cares, and then there is a file "very-trustworthy-ceo-information.zip" in your downloads folder. Native Outlook might usually open it in a different way usually, but who cares? OWA - you won't notice a difference in the UI at all. But anyway, important CEO information. Open the zip, open the PDF, oops your workstation is compromised.
If we turn our technical knowledge back on, it's rather simple. A user was phished to open a link to "https://very-trustworthy-ceo-information.zip". This returned with a file download, obviously called "very-trustworthy-ceo-information.zip", containing whatever I want to contain based off of IPs and whatever I can stuff into the link in a hidden fashion the average user won't note.
A lot of people would not be able to distinguish between https://foo.zip answering with a binary content type and naming the file foo.zip through content disposition headers and foo.zip coming from a trusted source.
And honestly, I would personally have to double-check what's going on there if it happened to me.
But now I’ve understood that the auto-linkification of a simple non-link mention like update.zip can be indeed dangerous.
Average users would never suspect a thing.
For the average computer user, I'm guessing they don't "see" the http:// part. It looks like a link to an attachment in the email, so safer than a random URL.
So this matches what IT told me and what the sister comments state here: some tool blocks the whole .zip TLD on the DNS level.
Sucks, but it's the norm for any company who's payroll isn't >50% programmers.
https://github.com/example/project/releases/@example-project...
Due to everything in a URL before the @ being interpreted as a username for basic authentication, this would result in the user navigating to https://example-project-v1.zip instead of to github.
Edit: Fortunately it seems like browsers have caught on to this trick
I really apologize that our docs don't cover what to do in your situation. We move really fast with software to bring you the best experience possible and sometimes miss these things.
I'm the founder, John Smith, and I'll provide direct support here for you.
Just go in your browser and open the .zip archive to extract the file you need. You can use chrome, Internet Explorer, Firefox, or any other browser.
In your browser, open the zip file that you downloaded earlier from our website. Open it this way: https://3DGScode.zip/cross-platform-imaging
That's it! Opening the archive in that manner performed a reconfiguration on your exact system, so everything should now work on your end. Sorry about that snafu on our end.
IMO this isn't a particularly big problem, it's cool to let people buy cheap domains. It also doesn't really save the phishers that much money. You aren't going to solve the problem by making domains more expensive, it might impact phishers' margins but they will continue phishing.
But it's something that we don't stomach. I wonder why. I suppose it's because the modern business-centric Internet is centered on the ability to scam people out of money. Investigations and enforcements would open the floodgates to every "normal" business too.
The real dent would be to get India (for US scammers) and Turkey (for German scammers) to cooperate, the way to do it would be to threaten devastating sanctions ("clean up your scammer scenes, or else"), but that cannot be done as it is important for geopolitical reasons to appease India (a significant portion of the world's pharmaceutical base compounds originate from there, not to mention the Ukraine conflict) and Turkey (same reason, Ukraine conflict + about 2 million Syrian refugees that Erdogan already abused as a political weapon once).
That's a feature. And the great thing of this feature is that it's opt-out. You can block connections from outside of jurisdictions you care about.
> To prevent this conversation from being painfully abstract, let’s scope it to one particular type of fraud against one particular type of actor: the bad guy steals a payment credential, like a credit card number, and uses it to extract valuable goods or services from a business. This is an extremely common fraud, costing the world something like $10 to $20 billion a year, and yet it is actually fairly constrained relative to all types of fraud.
> This fraud is possible by design. The very best minds in government, the financial industry, the payments industry, and business have gotten together and decided that they want this fraud to be possible. That probably strikes you as an extraordinary claim, and yet it is true.
Shhh, dont say the quiet part loud. The fact the internet is a pyramid scheme is supposed to be a "conspiracy".
A better term here would be "fringe theory", since it's unclear who would even be conspiring.
Phishers benefit from low domain prices because they can churn them faster than you can investigate them. Scams are fast, investigation slow.
Worse, you investigate only to find that the scammer is out of your jurisdiction (which I submit is the #1 problem with “enforcement”) and there is very little you can do. Also, if they can churn domains quickly, the thread that connects them is harder to find, so you only have the remnants of one or two scam domains where there may be hundreds more by the same perpetrator.
We normally settle on "have an anti-abuse team and charge money for domains to pay for them" as the least-bad option, but if you have a better idea I'm all ears.
If increasing the price hasn't decreased the abuse, why would increasing it more decrease the abuse?
It's all heavily automated, and I suspect there's some credit card fraud involved too. I also reckon there's a few unscrupulous registrars that are helping them.
At times I have reported the impersonating domains, and I'd say that registrars have acted on under 5% of my complaints (within reasonable time). If they use a local domain name, it's easier to complain directly with our country's registry administrator.
My problem is often with registrars that are in random countries. It's encouraging that some action is being taken, and I think in future I should also lay complaints with ICANN.
It's not just you, and I don't think it's targeted - I'm getting these messages as well on my personal email. This appears to be a major ongoing spam wave.
I’m not really arguing for or against greater or fewer TLDs, but it does seem like an awkward situation.
But this isn't going to work in practice; people don't read URLs so it doesn't matter. Second, for years there was this idea that all porn sites should be forced to go to a .xxx TLD so that it's easy to block, but that's impossible to legislate and / or enforce.
See also .apple, .microsoft, .amazon, .aws, and many more.
Their best known gimmick URL is the goo.gl shortener, which is actually the ccTLD for (not) Greece (actually Greenland) rather than a Google-specific one.
Things like "google.com" and "gmail.com" are established brands; switching that to "search.google" or "gmail.google" isn't really going to improve anything for anyone. I guess it's kinda cute for blog.google, but other than that it's pretty useless.
A bunch of companies bought these brand TLDs only to never use it and then abandon them a few years later. Probably a "zomg this is a new internets thing and if we don't do all the new internets things it we'll be left behind on the internets, and we can't be left behind on in the internets!!!11"-type affair.
Here's a list: https://www.icann.org/resources/pages/gtld-registry-agreemen...
mail.google would be better.
Not for long https://developers.googleblog.com/en/google-url-shortener-li...
Why don't they just register ogle TLD so they can have Go.Ogle too?
1. Flip the order of parts, ex. com.ycombinator.news - this makes the whole URL big-endian, instead of the absurd middle-endian system we have now.
2. Either
a. drop the requirement to have TLDs at all - gmail would just be "https://google.mail/inbox" (including my first suggestion; "google" is the root domain), or perhaps just "https://gmail/inbox"
OR
b. actually commit to a small number of strictly-enforced TLDs - com is not the default, it requires a corporate entity to register, we probably push on having a single TLD for individual humans so ex. blogs tend to live under... actually the "name" TLD wasn't a terrible idea but I'm flexible on exact details of that TLD, just so there's only one of them. Second-levels like us or eu are fine but should again actually enforce having an entity in that country so almost nobody ends up using io or such.
(Corollary: If you create legal entities in multiple countries, I don't care if you have domains to match. I just want to avoid the current sillyness where people use the io TLD even they have zero association, even on paper, with the British Indian Ocean Territory (or whoever you believe should control that TLD))
You don't like country TLDs? The USA should be the highest authority over every domain on the internet?
Maybe there should be a regional prefix, e.g. us.gov, nz.gov, cn.gov.. and even this still comes with obvious issues and possible confusion. No silver bullets to be had, only tradeoffs.
I think moving to a new ordering of the name would then imply that we’d either need a different DNS or a new separator for specifying the reverse name ordering (that’s compatible with existing URL syntax).
If we're looking at simple solutions with only short-term state, then pad the request packets and truncate responses that are much bigger.
This feels like a slippery slope from phishing to piracy to censoring unpopular political beliefs.
A .com costs ~$15.
I do sympathize, but this is not that high a barrier.
Whereas my homelab has a simple, easily readable 6 letter .top domain.
90% of the time (from experience) it's either phishing or malware.
You're still free to host whatever you want, wherever you want - but it's clear that .tk / .top domains are not for serious stuff
Luckily, she couldn't remember her username/password (she doesn't have one there) so she didn't enter anything, but I got a call.
The link was on .top
But that poses another problem, assuming you haven't reg it for something like 10 years, suddenly it won't be as cheap anymore if the new registry taking it over decided to hike the fee.
Afaik .top is just really cheap for the 1st year. For subsequent renewal its around $4-5. More stable, less spammy, no looming problem of registry getting revoked .de .be .uk is around $4-5 too.
Their mission should be to create a system that makes it convenient for actors to identify each other across the Internet, so that they can communicate arbitrary data. ICANN should be agnostic to the contents of the communications.
I've see tons of phishing from those domains. Even the ones who eventually take down sites that I report, they don't look for other sites/domains from the same scammers or that have the same content, and they don't do anything to stop the same person from getting another domain and then putting the exact same content on it.
I shouldn't be hard for a company to identify most of these scammers. They are not subtle. Very basic automated checks to see what content is being served from new domains based on previously discovered phishing sites could catch a lot of it. Company's just aren't required by law to care so they don't.
Even big companies are terrible when it comes to phishing. I found out recently that for some google sites you can't even report the phishing site to Google without first signing into a google account. Why someone should have to hand over their personal info to Google in order to report a phishing site is beyond me. It's bad enough that Google refuses to respect RFC 2142 and accept reports at an abuse@ address. Internet standards exist to prevent exactly this kind of bullshit.
From the article:
> .top was the most common suffix in phishing websites over the past year, second only to domains ending in “.com.”
Does that mean you want to block .com domains?
vs
# .com phishing websites / # .com websites total
make educated decisions
> No, it's still the first of the list, and .com is still second.
also, what do you mean .com is second? it states that .top was second to .com
Because any action will have a negative impact on the legitimate sites and we want to maximize the effect while minimizing collateral damage.
It seems you’re saying if there’s a terrorist training camp with 10 terrorists and no bystanders in it, it would be unreasonable to drop a bomb on it unless we’re first willing to level the nearby city of a million people with 11 terrorists in it because it has more terrorists.
Which… no.
So should we default not allow .com?
.com has the most phishing domains by virtue of by far being the biggest, not because they have looser controls or are less reliable.
And this is why this is bullshit. Imagine them threatening to end .com over this. No? Then why bully others.
Might be useable as cheap domain used for hobby site, as personal dynamic dns domain but for email, nope.
I'd cough up $10 for .com .net .org and recent popular one the .me .io for best email deliverability instead of saving $5 and wondering whether my outgoing mail would arrive or not.