Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom Domains

, , , , & Nepal, Surya (2024) Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom Domains. In WWW '24: Proceedings of the ACM on Web Conference 2024. Association for Computing Machinery (ACM), New York, NY, 1724–1733.

[img]
Preview
Published Version (PDF 1MB)
156616756.
Available under License Creative Commons Attribution 4.0.

Open access copy at publisher website

Description

Web users often follow hyperlinks hastily, expecting them to be correctly programmed. However, it is possible those links contain typos or other mistakes. By discovering active but erroneous hyperlinks, a malicious actor can spoof awebsite or service, impersonating the expected content and phishing private information. In typosquatting, misspellings of common domains are registered to exploit errors when users mistype a web address. Yet, no prior research has been dedicated to situations where the linking errors of web publishers (i.e. developers and content contributors) propagate to users. We hypothesize that these hijackable hyperlinks exist in large quantities with the potential to generate substantial traffic. Analyzing largescale crawls of the web using high-performance computing, we show the web currently contains active links to more than 572 000 dot-com domains that have never been registered, what we term phantom domains. Registering 51 of these, we see 88% of phantom domains exceeding the traffic of a control domain, with up to 10 times more visits. Our analysis shows that these links exist due to 17 common publisher error modes, with the phantom domains they point to free for anyone to purchase and exploit for under $20, representing a low barrier to entry for potential attackers.

Impact and interest:

6 citations in Scopus
Search Google Scholar™

Citation counts are sourced monthly from Scopus and Web of Science® citation databases.

These databases contain citations from different subsets of available publications and different time periods and thus the citation count from each is usually different. Some works are not in either database and no count is displayed. Scopus includes citations from articles published in 1996 onwards, and Web of Science® generally from 1980 onwards.

Citations counts from the Google Scholar™ indexing service can be viewed at the linked Google Scholar™ search.

Full-text downloads:

303 since deposited on 29 Jan 2024
91 in the past twelve months

Full-text downloads displays the total number of times this work’s files (e.g., a PDF) have been downloaded from QUT ePrints as well as the number of downloads in the previous 365 days. The count includes downloads for all files if a work has more than one.

ID Code: 245862
Item Type: Chapter in Book, Report or Conference volume (Conference contribution)
ORCID iD:
Ramachandran, Gowriorcid.org/0000-0001-5944-1335
Jurdak, Rajaorcid.org/0000-0001-7517-0782
Measurements or Duration: 10 pages
Event Title: International World Wide Web Conference
Event Dates: 2024-05-13 - 2024-05-17
Event Location: Singapore, Singapore
Additional URLs:
Keywords: common crawl, crawling, domains, hijackable, hijacking, hyperlinks, links, phantom domains, phishing, spoofing, typosquatting, vulnerabilities, web
DOI: 10.1145/3589334.3645510
ISBN: 979-8-4007-0171-9
Pure ID: 156616756
Divisions: ?? 1469440 ??
Current > QUT Faculties and Divisions > Faculty of Science
Current > Schools > School of Computer Science
Funding Information: The work has been supported by the Cyber Security Research Centre Limited whose activities are partially funded by the Australian Government's Cooperative Research Centres Programme.
Copyright Owner: 2024 Contact the authors
Copyright Statement: This work is covered by copyright. Unless the document is being made available under a Creative Commons Licence, you must assume that re-use is limited to personal use and that permission from the copyright owner must be obtained for all other uses. If the document is available under a Creative Commons License (or other specified license) then refer to the Licence for details of permitted re-use. It is a condition of access that users recognise and abide by the legal requirements associated with these rights. If you believe that this work infringes copyright please provide details by email to qut.copyright@qut.edu.au
Deposited On: 29 Jan 2024 15:18
Last Modified: 14 Sep 2026 16:41