you are in:
Internetnews.com >> boston.internet.com >> News
7 day summary

internet.com

Newsletter Signup

Internet Daily

Boston News

DC News

NY News

SiliconValley News

select a newsletter above, type your email and click the arrow to sign up!

Events
OWASP 11/2

Newsletter Signup
DJ 309650.94-145.86
NASDAQ1564.74-30.52
S&P 5001032.70-17.20
02:41 PM
Market data delayed a minimum of 15 minutes

get quote

internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

Best Buy or Biggest Scam?
Senate Panel Overwhelmingly Passes Anti-Spam Bill
Spam Threatens Revenue, Kids
Online Scams Up, Credit Card Hacks Down
PayPal Scammers Getting Bolder, Better
Alleged Web Scammer Settles With SEC
Online Portals Won't Defeat Spam
For more stories on:
special reports
Down Yahoo's Transition Road

[ more ]
most popular
Google to Spread Social Tool Across The Web
MySpace Wins Record $230M Suit Against Spammer
Fedora 9: Linux Desktop Alive and Well at Red Hat
BlackBerry Goes Bold for Market Gold
The Big Board Goes Linux
XP Service Pack Rocky for Some, OK for Others
Linux File Systems: You Get What You Pay For
Microsoft's New Math on SMB Servers
Microsoft's Patch Day Targets Four Vulnerabilities
Why AMD Went the Multi-Chip Module Route
hot topics
Return of The Browser Wars
A Patent Battle on eBay Territory
SaaS in The Market
Ads And Their Influence
Whitepaper: HP StorageWorks All-in-One (AiO) Storage Systems and Microsoft Exchange Server 2007 Database Snapshots. Click here to open this PDF.

boston.internet.com

June 20, 2003
Cutesy Domain Names Making Online Fraud Easier
By Susan Kuchinskas

The sting that hit electronics retailer Best Buy on Wednesday hinged on a simple trick: e-mailing a link that seemed to go to the electronics retailer's site.

Instead, the click-through went to a phony look-alike where users were asked for vital personal information including credit card and social security numbers.

The debacle now has some concerned that online merchants make it even easier for fraudsters to hustle people with the redirect dodge by using odd domain names or using more than one. Best Buy's plight already has the sector rethinking their strategies.

"Businesses should stick with their key brand domain names," says Internet security expert Dave Nielsen, who operates the consumer information Website fightidentitytheft.com. "It's a bad idea to use cute domains for a promotion."

For example, Citibank uses the perfectly straightforward Citibank.com; however, its online marketing uses citicards.com - even though the user is automatically taken to Citibank.com.

Unfortunately, making changes is not so easy. A business may use an unfamiliar domain name because the most logical one is already taken, or because an outside company is handling registration or promotions, says content security consultant James Sinclair of Adhaero Technologies. He cites the example of United Airlines' Web site: www.ual.com. The airline owns United.com, but not united.biz nor united.net.

"They can't buy up every possible permutation," Sinclair told internetnews.com.

Still, Sinclair asks, does it have to redirect people who click on promotional offers to the very spammy-looking www.ua2go.com?

There's a similar dilemma with Sunnyvale, Calif.-based Internet media giant Yahoo!. Sinclair says Yahoo!'s practice of using naming conventions such as dailynews.yahoo.com and biz.yahoo.com is confusing enough that for the most part, users have easily accepted it as legitimate. While keeping domain name usage consistent may help, Sinclair says there are plenty of other tactics that can be used to deceive users. That is especially true when tricksters put the real business domain name in front of the @, followed by the IP address of the crooked site. When they see http://News.yahoo.com_:_daily_news@66.39.52.192, for example, Sinclair says many users assume they must be going to Yahoo's servers.

While there are hordes of vendors consulting on network security, merchants have few resources when it comes to finding the best practices for organizing their e-commerce, e-mail and online customer support operations.

The Internet Fraud Complaint Center, which lets victims file complaints electronically, has a single page of tips for consumers but no info at all for businesses. An FBI spokesperson did not return repeated calls, and a staffer at the FBI's press center could not identify any other resources available for merchants.

The non-profit Merchant Risk Council, established in 2000, (Its website whose URL doesn't match the organization's name) shows no evidence of activity by the group since early 2002, and it could not provide a spokesperson.

The leisurely pace of these organizations is no match for the speed of Internet hucksters, according to Nielsen and the response of businesses when they've been hit is often not much better.

"Something like [the Best Buy scam] only needs a day for the damage to be done," says Nielsen. "The old methods don't hit the mark."

Best Buy's e-mail warning to customers arrived in his inbox this morning, nearly two days after the company became aware of the problem. Nielsen calls that "weak."


News Archives


current headlines
Breaking News
Verizon a Partner on Linux Mobile OS
Internet Clips a Dilemma For Actors And Studios
Microsoft Makes it Clear on Yahoo

Business
Gates Sees Boom Ahead in Home, Business Touchscreens
HP Drags Down Dow
Jeff Raikes to Head Gates' Huge Charity

Developer
Alfresco's Latest ECM: Prying Open a Sector?
SaaS Tool Offers Custom Database Development

E-Commerce
MySpace Wins Record $230M Suit Against Spammer
FTC Tightens Up CAN-SPAM Rules
Q&A: Jules Polonetsky, Chief Privacy Officer, AOL

Enterprise
Greenplum Sees BI As Sweet Market
Autonomy 'Discovers' Virtualization
HP Targets Telecoms' Customer Data Needs

Government
House Democrats Try Again With Net Neutrality Bill
White House Fesses Up to Missing Data
House Takes Up Net Neutrality Debate

Hardware
Why are AMD Systems Prone to SP3 Problems?
Gates Sees Boom Ahead in Home, Business Touchscreens
IBM's Cell Chip Moves Out From Gaming's Shadow

Networking
Asterisk Going Carrier-Grade?
Apeer Has an Eye for Media Collaboration
House Democrats Try Again With Net Neutrality Bill

Mobility
BlackBerry Goes Bold for Market Gold
Motorola Looking to Lure Dev Talent
Mobile Ads to Kids? FTC Opens Debate

Search
Google's Enterprise Search Gets a Helping Hand
Is Microsoft Weaker After Failed Takeover Bid?

Security
CA: Role-Playing Needs Security Test
MySpace Wins Record $230M Suit Against Spammer
Protecting Desktops With a ForceField

Software
Gates Provides More Windows 7 Details
Gates Sees Boom Ahead in Home, Business Touchscreens
The Big Board Goes Linux

Storage
Seagate Disk Gets NSA's Security Seal of Approval
Dedupe Player Stakes Out New Domain
IBM Seeks Greater Slice of Virtual Tape Library Pie

Web Content
Andreessen Knocks Would-Be Google Competitors
Google to Spread Social Tool Across The Web
Apeer Has an Eye for Media Collaboration

Wireless
Apple's iPhone SDK Off to The Races
Sales Data, New Challengers Don't Bode Well For Moto
iPhone Grabs Market Share, But Not Yet in The Enterprise

xSP
IDC: Microsoft's Yahoo Deal Could be a Big Hit
Ballmer Fills in 'Software-Plus-Services' Plan
Report: Enterprise Search Will Top $1 Billion by 2010





JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES