NEWS / WEB SERVICES

Spelling mistakes can lead to online security breaches

13 Sep, 2011, 11:59 am IST | by Padmini Harchandrai | Web services

If you have a friend with a very complicated email address or even just a name you frequently misspell like mine, you have to be extra careful when typing out their addresses when you send them an email. Researchers have found that cyber thieves create commonly misspelled domains and usernames for email addresses. What this means is when you make a mistake in spelling the name of the intended recipient's email address, it could end up in the inbox of a cyber thief instead of just bouncing back to you. Investigators looking into this have grabbed 20GB from over 1,20,000 wrongly sent emails in the past six months. Of course, some of the intercepted emails contained private information like usernames and passwords, as well as private corporate information.

Make sure email addresses have no spelling mistakes

Make sure email addresses have no spelling mistakes

 

 

Usually, it's companies that fall victim to this practice. When a company has one domain for their website and multiple domains for their individual business units, they tend to differentiate between domains with the use of dots. So for instance, a multinational television company in the US would have the email address us.company.com, while in India they might have company.india.com. If a sender messes up the placement of the dots and the order of the words, chances are, the email will end up in the hands of thieves.

 

Some attackers that are actually clever will go unnoticed by being a middle man. The obvious way such a practice would be caught would be that recipients keep reporting that they're not receiving emails intended for them, but senders aren't getting emails bounced back. A clever thief would actually forward on the email to its intended sender. Of course, this means, that when the recipient hits reply and an email chain starts, that's more information that a thief receives. Mark Stockley wrote on the Sophos security firm's blog, "A determined attacker with a modest budget could easily afford to buy domains covering a vast range of organisations and typos."

Tags: Security , Privacy , Internet Security , Email , Email addresses , Sophos , Domains

RELATED STORIES

Mastermind behind Bredolab botnet sentenced to jail in Armenia

Mastermind behind Bredolab botnet sentenced to jail in Armenia

A man who was in command of the botnet, Bredolab, controlling some 30 million computers worldwide, has ...

Trend Micro takes top spot in TechNavio’s global market share report

Prepaid cards for Google Wallet temporarily disabled; Google says it is safe

Trend Micro gets new security solution to the Android platform

New McAfee Mobile Security aims to protect your beloved Android

McAfee announces Application Control software for enterprises

Chrome Beta loads web pages before user completes URL

Sophia Grace & Rosie's Security Mishap

17 May, 2012, 06:30 pm IST

Sophia Grace & Rosie's Security Mishap

Chris Geo Arrested By Homeland Security For Not Giving Up 4th Amendment

25 Aug, 2011, 11:05 am IST

Chris Geo Arrested By Homeland Security ...

Social Security vs. Private Retirement

02 May, 2012, 08:03 pm IST

Social Security vs. Private Retirement

Douglas Crockford_ Principles of Security

10 Apr, 2012, 03:34 am IST

Douglas Crockford_ Principles of Security

 

OPINIONS

Avinash Bali

Diablo III may be selling like hotcakes but do its sales really benefit the PC gaming industry?

MORE OPINIONS

Leaked Images, Availability, Pricing,
Specs, Pre-order

features

YouTube with a Twist

YouTube with a Twist

YouTube is the most preferred and undoubtedly the most popular video...

By Priyanka Tilve

Social Gifting: The next hot trend?

Social Gifting: The next hot trend?

Social networks have knitted the world too close, and everything one does

By Naina Khedekar

10 must-have Google Chrome extensions

10 must-have Google Chrome extensions

Despite Microsoft’s IE gaining its market share and numerous Mozilla...

By Naina Khedekar

MORE FEATURES