This happens more than people admit. I run a small windows-based hosting setup and found interserver.net instead of interserver.net serving fake login pages for my customers I only noticed because a customer emailed the wrong domain and got phished. The registrar took 4 days to respond to the abuse report. Their whois privacy made it harder Has anyone actually gotten a fast takedown
Someone registered a domain one letter off mine
Have you tried restarting it?
What worked for me last time:
- Screenshot everything before they change it
- Landing page
- Whois history
- DNS records
- File with both registrar and hosting provider
- Hosting provider usually faster
- Registrar drags feet on privacy
- Check for more variants
- Common misspellings
- Homoglyphs
- Hyphen additions
- Set up alerts for new registrations
- I use a script against rdap
- Catches them in hours not days
Not work? Is there a tool for this or you just guess
IPv4, IRC, and irssi — fight me
nina64 said:
Check for more variants
It is possible to automate this? I am not very good with script lol mdr
The Vultr support they say "not our problem contact registrar" very fast to say this
Vive la résistance... électrique
The graphs do not lie: typosquatting detection is a monitoring problem
I run checks every four hours against thirty-six variant patterns. Current false positive rate is 2.3 percent. Last year I caught eleven active phishing domains before they served a single victim
registrar response times vary from six hours to nine days. Median is thirty-one hours. Plan accordingly
436 days. reboot is surrender.