Hacker News new | past | comments | ask | show | jobs | submit login

Easier to just do bitsquatting: register all the domains that are one cosmic ray induced bit flip away from a common domain name, e.g. https://www.bleepingcomputer.com/news/security/hijacking-tra...



We did this for a customer and to see what leaks. It’s very surprising and sometimes very bad from a security perspective on popular and high traffic domains of service providers.


I remember when this hit HN a few months(?) back, for me it was the first time learning about this and I assumed this might be an obscure thing.

I ran the python script against my (very large) employer's domain name and was pleasantly surprised to see we owned all the bitsquatted versions already (there were maybe 10?)




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: