MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
Welcome to MSMVPS.COM Sign in | Help
in Search

Harry Waldron - Microsoft MVP Blog

Security News and Best Practices for corporate and home users

Internet Domain Names - Five day grace period abused by malware developers

Lightning The Storm worm with it's fast flux server techniques and other malware are abusing the 5 day grace period associated with registering a new website name.  Based on recent trends, millions of domain names are being allocated and then deleted each month.  This is why folks need to be careful in going to sites questionable sites based on IP numerical addresses or unusually named sites.

http://www.avertlabs.com/research/blog/index.php/2008/01/24/is-it-domain-tasting-or-domain-misusing/

QUOTE: When a registrar registers a domain name, there is a five-day Add Grace Period (AGP) where he may cancel his request and receive a full credit for the registration fee from the registry. This trend has been gaining popularity since mid 2005, and although it was originally set up for avoiding mistakes, the practice now is frequently abused.

Beside the fact that some domainers use it to track names with a high potential to generate traffic and thus pay-per-click revenues, people who use the fast-flux and rockphish techniques, which we have already discussed here in detail, now use it in proportions that would be interesting to measure. Domain Tasting involves registering names only to release them very quickly and without paying for them. This practice exploded in 2007, and an incredible number of temporary domain names, having definitely been used to carry out malicious activities, were deleted at the end of this add-grace period.

MORE INFORMATION
http://www.avertlabs.com/research/blog/index.php/2007/12/03/from-fast-flux-to-rockphish-part-1/
http://www.avertlabs.com/research/blog/index.php/2007/12/03/from-fast-flux-to-rockphish-part-2/

Only published comments... Jan 29 2008, 01:52 PM by harry

Comments

 

Windows Vista News said:

Interesting point at msmvps.com

January 29, 2008 9:00 AM
 

Domaining - Information on Domains and Domaining » Internet Domain Names - Five day grace period abused by malware … said:

Pingback from  Domaining - Information on Domains and Domaining » Internet Domain Names - Five day grace period abused by malware …

January 29, 2008 9:50 AM

Leave a Comment

(required) 
(optional)
(required) 
Submit
Powered by Community Server (Commercial Edition), by Telligent Systems