Finding WEIRD Typosquatting Websites

Поділитися
Вставка
  • Опубліковано 18 бер 2024
  • jh.live/flare || You can track down shady sellers, hunt for cybercrime, or manage threat intelligence and your exposed attack surface with Flare! Try a free trial and see what info is out there: jh.live/flare
    Free Cybersecurity Education and Ethical Hacking with John Hammond
    📧JOIN MY NEWSLETTER ➡ jh.live/email
    🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware
    🔥UA-cam ALGORITHM ➡ Like, Comment, & Subscribe!
    Music sourced from Artlist.io
    Alon Ohana - Parallel Room
    Stanley Gurvich - Sunny Days

КОМЕНТАРІ • 236

  • @memesfromtheforsakenworlwi9218
    @memesfromtheforsakenworlwi9218 Місяць тому +1386

    fun facts, most companies buy as much of those "typo domains" to make them redirect to the real site

    • @nadroj6381
      @nadroj6381 Місяць тому +96

      Ah, I was wondering why they kept redirecting to the real site. Cool!!

    • @Azuuraas
      @Azuuraas Місяць тому +53

      yup, i know for sure google did that

    • @GOOFLEr
      @GOOFLEr Місяць тому +12

      'Most'

    • @kuromiLayfe
      @kuromiLayfe 27 днів тому +56

      still check if you are on the real
      site.. as the scammers can spoof the address bar and status bar to show the official url (and of course also the titlebar and all links when using inspector). just takes 3ms to replace what is shown the moment the page or hover is activated.

    • @BillAnt
      @BillAnt 25 днів тому

      Cuz many type "goggle" when typing fast. lol

  • @kalicxingnjenga9657
    @kalicxingnjenga9657 Місяць тому +1608

    Please do a video showing what’s inside that APK.

    • @TomJacobW
      @TomJacobW Місяць тому +50

      hearted - neat! Looking forward to seeing that!

    • @infohazard
      @infohazard Місяць тому +35

      I was really annoyed that he didn't do it xD

    • @IDontModWTFz
      @IDontModWTFz Місяць тому

      Get APK tool and do it yourself, apks are really easy to re

    • @posifurg
      @posifurg Місяць тому +34

      Im going to do a vid showing the APK - ill post it when i can

    • @DEZXD1
      @DEZXD1 Місяць тому +2

      The apk says failed to download something

  • @kyokazuto
    @kyokazuto Місяць тому +577

    "I think that is the real google", he says looking at google from 10 years ago

    • @mordechajloooo
      @mordechajloooo 7 днів тому

      interesting

    • @Yadobler
      @Yadobler 5 днів тому +4

      I believe that some devices will result in the old version loading, probably for compatibility

    • @kyokazuto
      @kyokazuto 4 дні тому

      @@Yadobler I highly doubt that

  • @dinosaurgardening2401
    @dinosaurgardening2401 Місяць тому +562

    I know the guy who bought Google with 3 ooo's. He bought it in high-school because he was smart. He isn't a scammer.

    • @4rumani
      @4rumani Місяць тому +64

      Yeah very smart lol. Obvious WIPO violation, no legitimate interest, bad faith typosquatting

    • @Linkman8912
      @Linkman8912 Місяць тому

      ​@@4rumanichill

    • @justarandomchannel1319
      @justarandomchannel1319 28 днів тому +32

      Bro could prolly sell that for alot tho

    • @ihatenerds4689
      @ihatenerds4689 25 днів тому +102

      ​@@4rumaniyou are a sad being

    • @Limelaz23
      @Limelaz23 25 днів тому +29

      ​@@4rumani y so salty

  • @bdot02
    @bdot02 Місяць тому +195

    Personally like "guthib"

  • @wombatpandaa9774
    @wombatpandaa9774 Місяць тому +135

    Near the beginning I jokingly thought this was going to be an ad segment for Nord VPN but to my pleasant surprise it's an actually really useful FOSS tool. Love to see it.

  • @Gamerappa
    @Gamerappa Місяць тому +129

    14:34 google looks like this on certain user agents, it's their old design from 2011-2013

  • @Fluttergoat
    @Fluttergoat Місяць тому +91

    Isn't a $32/Month virtual server absolutely overpriced and overkill for this? Maybe I just don't know enough about the program or droplets so I'd be curious if there was a genuine reason it had to be that expensive.

    • @T1C
      @T1C Місяць тому +8

      Probably could get by on a $5 vps

    • @tbuk8350
      @tbuk8350 23 дні тому +4

      he could've probably done the same thing on oracle always free compute

  • @ExperiencersInternational
    @ExperiencersInternational Місяць тому +68

    It was funny seeing Goole as one of the screenshots 😂
    Had some fun with pronouncing it when driving past signs for that place on the motorway a few months ago

  • @adamn0
    @adamn0 23 дні тому +17

    please don’t go to the website at 19:40 i wish i wasn’t curious and went to it i think you should blur out that link or remove that part of the video it’s absolutely disgusting

    • @zixea3318
      @zixea3318 20 днів тому +1

      yeah there’s CP on there 🤢

    • @donaldud-deen7604
      @donaldud-deen7604 5 днів тому

      Bro whats in there?

    • @dan_loeb
      @dan_loeb 2 дні тому +1

      this is one of those things where it's best not to check at all. there is a really messed up image there.

    • @tankman5783
      @tankman5783 День тому +1

      ​@@dan_loebman just describe it i dont want the fbi knocking on my door

    • @dan_loeb
      @dan_loeb День тому

      @@tankman5783 the site has c.s.a.m. material and should not have made it in to the video period. If you don't know what that means it's often called cp. if you don't know what that means, I'm not going to describe it, as it violates yt policy and should be reported and avoided.

  • @unchained_jb
    @unchained_jb Місяць тому +184

    With adult sites it's even crazier

    • @dingusbrule5756
      @dingusbrule5756 Місяць тому +2

      Lmfao

    • @Nodsaibot
      @Nodsaibot Місяць тому

      zvideos

    • @oz_jones
      @oz_jones Місяць тому +19

      Stop watching corn.

    • @LeReubzRic
      @LeReubzRic Місяць тому +99

      ​@@oz_joneswhat about carrots

    • @kab43
      @kab43 Місяць тому

      ​@@LeReubzRicno. only peas and cilantro/coriander

  • @cybercub4367
    @cybercub4367 Місяць тому +198

    Please do reverse engineer that APK, we're bound to find something juicy there 😂

  • @pitche
    @pitche Місяць тому +108

    14:33 It's an old Google UI :)
    Thx for the likes 😆

  • @U20E0
    @U20E0 Місяць тому +78

    UA-cam actually owns the domain youtobe, apparently

    • @81gamer81
      @81gamer81 Місяць тому

      you to be, is actually how its meant to bee. Monkey see monkey do. They decide what you see, and what you do

  • @zixea3318
    @zixea3318 20 днів тому +22

    Linux users typing the entirety of their computer’s code into the command line just to make a new folder: 🤬🤬🤬

    • @thesoftone
      @thesoftone 20 днів тому +5

      ^ this user knows nothing about computers

    • @spaghetti5914
      @spaghetti5914 3 дні тому +8

      ​@@thesoftoneSalty linux user ^

    • @thesoftone
      @thesoftone 3 дні тому +1

      @@spaghetti5914 ^ GIGA cope

    • @spaghetti5914
      @spaghetti5914 3 дні тому +1

      @@thesoftone This user doesn't know I'm a linux user as well ^

    • @Shoegaze-
      @Shoegaze- 2 дні тому

      Lain pfp hating on Linux…
      Get off TikTok lol

  • @kiwipomegranate
    @kiwipomegranate Місяць тому +26

    Please make a part two I wanna see more about that "live (ph)fishing game" and the Amazon typosquat hijinks

  • @greenockscatman
    @greenockscatman Місяць тому +60

    I like the raw realism of the Linux experience at 17:30

  • @ThisIsJustADrillBit
    @ThisIsJustADrillBit Місяць тому +46

    Its such a fun rabbit hole watching malicious domains as they are registered. Weird how many of them sre hosted behind cloud flare these days... 🤔

    • @chigga5years173
      @chigga5years173 Місяць тому

      Why does cloudflare even support them?.. I recently got an sms scam of gettimg rich easily and upon scanning and tryim7to find vulnerabilities of those scammers.. I didn't get anything

    • @PazLeBon
      @PazLeBon Місяць тому +2

      cos cheap hosting is slow :)

    • @chrissametrinequartz9389
      @chrissametrinequartz9389 Місяць тому +2

      or it could also be (for whatever reason) that, thats what they are using to manage their domains or smth

  • @kidnamedfingor
    @kidnamedfingor Місяць тому +12

    Just to let u know, when i went on the googie website, there was some illegal content, if i were you i would cut that part out. I went on that domain i wish i could unsee what i saw.

    • @jjprisma3d
      @jjprisma3d 22 дні тому +1

      It’s really traumatizing.

    • @kidnamedfingor
      @kidnamedfingor 22 дні тому

      @@jjprisma3d cant believe he actually let it slip into this video

    • @jjprisma3d
      @jjprisma3d 22 дні тому +1

      @@kidnamedfingor Atleast he blurred it.

    • @jjprisma3d
      @jjprisma3d 22 дні тому +2

      @@kidnamedfingor And also, whoever's chid was that. I feel bad for the parents. The person who did that shoud be ashamed.

    • @kidnamedfingor
      @kidnamedfingor 22 дні тому

      @@jjprisma3d I translated the Chinese and it said that it was the dad who did it

  • @circuitgamer7759
    @circuitgamer7759 Місяць тому +12

    I would love to see you doing this more, it's just really fun to watch you have fun with it :) Also looking forward to you looking through those files :)

  • @WebDesignerAmy
    @WebDesignerAmy Місяць тому +16

    This was a great utility to learn about John! Def found some permutations of some domains I own and those for another creator that came up. ty!

  • @AtlasBit
    @AtlasBit Місяць тому +15

    I love your videos. Thank you for your efforts to raise awareness.

  • @uuu12343
    @uuu12343 Місяць тому +1

    This is genuinely amazing for Typosquat monitoring and intelligence gathering

  • @AKABeestYT
    @AKABeestYT 15 днів тому +3

    I love the typos for regularly nsfw sites that redirect to sites that ask you to repent and fix your ways

  • @Noctuu
    @Noctuu Місяць тому +15

    Loved this video, u should do more “unserious” funny videos, either here or on a secondary channel

  • @skelkankaos
    @skelkankaos Місяць тому +3

    Really enjoyed this video because it's a topic that's interesting and you let it be interesting on its own merits instead of overly sensationalizing it

  • @bokrayoomjdeed
    @bokrayoomjdeed Місяць тому +1

    loved this thanks JOHN ;)

  • @purplepeak8575
    @purplepeak8575 Місяць тому +7

    Trying this back on Windows 95-Windows XP days is a guaranteed PC destroyer.

    • @WALLE1D1W
      @WALLE1D1W День тому +1

      Funnily enough, today it's probably safe to do this on the MS-DOS based Windows 9x versions of Windows, as they're too old to be a worthwhile target for malware. All the viruses that you might encounter naturally expect XP and later. At least, according to MattKC's video on the subject.

  • @k1ngslay3r41
    @k1ngslay3r41 Місяць тому +12

    lol I never noticed you owned a whole island of dinosaurs that's AWESOME!

  • @nrhowe84
    @nrhowe84 Місяць тому +3

    That is such a cool tool, would love to see a video on what is inside that apk file. Great video keep up the great work that you do.

  • @user-cd4bx6uq1y
    @user-cd4bx6uq1y Місяць тому +13

    16:59 that's master Rama isn't it? The cult
    Edit: 19:41 amazing reaction

    • @monkepog3236
      @monkepog3236 23 дні тому

      theres even illegal content on it, jail for at least 30 years for hosting it

  • @februalist4686
    @februalist4686 19 днів тому

    WE NEED a continue of this series

  • @rocket01666
    @rocket01666 Місяць тому +45

    Crack open that APK next PLEASE!

  • @dannydetonator
    @dannydetonator 25 днів тому +1

    As someone not well versed in IT, coding and html, i just learned a bunch of new words here. Typosquatting just made me think of my poor-ass unaccomodated seasonal-worker (initially) eurotrip.

  • @lordvgames
    @lordvgames Місяць тому +1

    should do more dnstwist shenanigans, really fun to see what you find

  • @oz_jones
    @oz_jones Місяць тому +8

    Youtubs - for all your Jacuzzi needs!

  • @iBridgee
    @iBridgee Місяць тому +21

    Who knew typosquatting could be so bizarre? 😅

  • @milentiusgaming
    @milentiusgaming Місяць тому +2

    looking forward to THE video of the breakdown of the APK, maybe there was more to the "nothing" in the empty text file....

  • @aidi4886
    @aidi4886 Місяць тому

    I choose you John. Make me smart!!!

  • @CainXVII
    @CainXVII 21 день тому

    This was great. Would have loved to see some other websites too. And what was actually in that fish file....

  • @ricestrange
    @ricestrange 25 днів тому +3

    The true video begins somewhere at 13:00

  • @BrimmFate
    @BrimmFate Місяць тому +1

    Adversaries is a funny way of describing scammer. Like calling them enemies

  • @bokrayoomjdeed
    @bokrayoomjdeed Місяць тому

    Hilarious maaan daamn! nice video bro really thanks.

  • @ownmicelio
    @ownmicelio Місяць тому +1

    Please do a part 2

  • @lancemarchetti8673
    @lancemarchetti8673 Місяць тому

    Brilliant

  • @abdoudicko5352
    @abdoudicko5352 Місяць тому

    You are the best

  • @DerMarkus1982
    @DerMarkus1982 Місяць тому

    Let's see if Jason will feature John Hammond in a clip compilation soon 😁

  • @ErichSchulz
    @ErichSchulz Місяць тому +1

    It seems to have a domain name size limit when using the web interface.

  • @VaibhavShewale
    @VaibhavShewale Місяць тому +1

    well moost of them showing old version and some just ads all over the page

  • @joebambanchannel
    @joebambanchannel Місяць тому

    The best,👍

  • @scykol
    @scykol 8 днів тому +2

    domain expansion: typo

  • @blakeeey27
    @blakeeey27 16 днів тому

    i love the term typosquatting sm

    • @cormarcormar
      @cormarcormar 10 днів тому

      the phishers are just squattin on that typo

  • @pollywops9242
    @pollywops9242 Місяць тому

    Super useful tool

  • @JohnDoe-bd1qe
    @JohnDoe-bd1qe Місяць тому +1

    Now I see the true meaning of the minor spelling mistake meme.

  • @thesoftone
    @thesoftone 20 днів тому

    kinda makes me want to try live booting Kali maybe, cool vid

  • @mattnaylor29
    @mattnaylor29 Місяць тому +3

    There is a bank in the uk called first direct. My 80+ year old family went to fist direct, it was a fisting porn site.

  • @sucra0710
    @sucra0710 Місяць тому +2

    Dnstwist it, bop it, pull it

  • @mattsadventureswithart5764
    @mattsadventureswithart5764 Місяць тому +1

    Based on the one guy I met with that first name, its pronounced "Mar cheen" with the "mar" being the same as "mark" without the k, and "cheen" being the same as "cheese", with an n instead of the z sound.

  • @yewo.m
    @yewo.m 7 днів тому

    This gave me "hacking in movies" vibes

  • @PegasusEpsilon
    @PegasusEpsilon День тому

    "sudo" is short for "do as superuser" - "sue due", not "sue dough" - sudo is not a martial art.

  • @gurukuappannadora8982
    @gurukuappannadora8982 Місяць тому

    Excellent stuff but we are missing actually what you are explaining kindly explain your experience in slow motion I feel it something like something that computation is going here

  • @stefanjohansson2373
    @stefanjohansson2373 Місяць тому +2

    16:50 Never seen this?!

  • @YTInnovativeSolution
    @YTInnovativeSolution Місяць тому +2

    Daily Dose of Internet is one of the best channels ever made. Thanks for your daily dose Mr. H.

  • @cherno6592
    @cherno6592 Місяць тому

    that fishing live game is advertising as that one gambling game or application, it on Indonesian language

  • @abdelhay.
    @abdelhay. Місяць тому +1

    WE WANT MOOORE OF MALWARE ANALYSIS VIDEOS PLEASE.

  • @The_hot_blue_fire_guy
    @The_hot_blue_fire_guy Місяць тому

    Is there a program like that website detecting thing for people who use normal operating system like windows or Mac OS and not those hacker OSs like Linux. You know, normal software for normal people that actually exist in the real world.

  • @UltimatePerfection
    @UltimatePerfection Місяць тому

    Marcin is (roughly) pronounced as Martzin.

  • @Ilikeflowers22
    @Ilikeflowers22 25 днів тому

    Unrelated, but i really like your hair :)

  • @Karman7
    @Karman7 6 днів тому

    I actually made a typosquatting website that i obviously took down but i was trying to cause drama with other kids at my school at the time. I was copying a website at my school and i talked about the real website talking bad about it saying it was the fake. Then i blamed it on a innocent kid not in the drama... Lets name him Dave. Then i told the Actual creators of the real website saying that Dave stole your website. And thats when they confronted Dave and i was just laughing the whole time... Now i know it is very evil... So then i just decided to take down the website because thats when i realized that i was evil...

  • @harrylumsdon6773
    @harrylumsdon6773 Місяць тому

    Chrome and edge has the safe search option??

  • @EmanuelLopesS2
    @EmanuelLopesS2 Місяць тому +1

    Thx f9r letting me know about new adult sites 😅

    • @Lu14355
      @Lu14355 День тому +1

      One of those apparently has cp on it so your comment sounds extremely weird now

  • @MFoster392
    @MFoster392 Місяць тому +1

    Very Cool :)

  • @Lo-Sir
    @Lo-Sir Місяць тому +6

    thirteen whole minutes of bullshitting to get to the real video

  • @attilazimler1614
    @attilazimler1614 Місяць тому

    Looks like from the gy start for youtube that it is having a base assumption that the keyboard layout is English.

  • @oussemabenayech2345
    @oussemabenayech2345 Місяць тому +4

    every jhon hammond should get into a fight and see who will earn the name

    • @PazLeBon
      @PazLeBon Місяць тому

      not a fight, even a dummy can win a fight

  • @SilentOnion
    @SilentOnion 21 день тому

    14:33 is not really "strange" google its just the old design from like the late 2000s.

  • @AmCanTech
    @AmCanTech 28 днів тому

    The site that redirects to aliexpress is likely a 3rd party that outputs their affiliate kink so they earn a commission... even if you dint shop via that link directly, a refer cookie is likely stored such that if you end up shopping within X amount of time they get credit for the sale.

  • @malka1762
    @malka1762 7 днів тому

    gotta hand it to the fishing "devs", they're kinda transparent when you think abt it 😂

  • @purplesam2609
    @purplesam2609 Місяць тому

    I wanted to go to the SpongeBob website as an 8 year old kid on my grandma's laptop and I found a site with a photo of some random man with a typo

  • @rob-890
    @rob-890 Місяць тому +1

    He's doing the thing where he repeats synonyms over and over again 😂😂😂😂

  • @Ramonatho
    @Ramonatho 24 дні тому

    Wait. Hang on. I noticed something about that slots game with the automatic download. On the section that says "The New One" it mentions Bob Slots, a youtube channel I watch, who has never promoted this app. That means they're scraping ultra specific small slots youtubers and saying they're promoting their game. Bob isn't a big channel. This is truly weird stuff.

  • @scrungles7853
    @scrungles7853 28 днів тому

    I have no idea what you're talking about, nice!

  • @RandomGeometryDashStuff
    @RandomGeometryDashStuff Місяць тому

    12:43 why didn't it understand --screenshots -t as save screenshots in directory named -t

  • @torrtoise
    @torrtoise Місяць тому +2

    alternative title: linux working as intended

  • @methical__
    @methical__ Місяць тому

    Interesting you don't know plesk, is this a europe hosting thing?

  • @gamernikan
    @gamernikan Місяць тому

    cool (there is not your ip at 15:48)

  • @half-faust
    @half-faust 19 днів тому

    Ah, the eternal internet nemesis: people with the same full name as you.

  • @Breecheesegeez
    @Breecheesegeez Місяць тому

    i've seen roblox typosquatting websites before

  • @STLPhil
    @STLPhil Місяць тому +1

    Shameless Plug for John's side Real Estate business

  • @v.adithya1768
    @v.adithya1768 Місяць тому

    Hi, When i run the --phash command, I get this error even though selenium is already present in /usr/lib/python3/dist-packages
    dnstwist: error: missing Selenium Webdriver

  • @davidetl8241
    @davidetl8241 Місяць тому

    Cool

  • @kizi86
    @kizi86 Місяць тому +3

    before browsers started to block physing sites, i bought shitton of domains that were typos of google and youtube, and for about a year, i gained a lot of money from ads 😅 but then on a single day, all my passive income stopped sadge

  • @eric_d
    @eric_d Місяць тому

    Are you saying TACK when you mean dash or hyphen? That's the weirdest thing I've ever heard!

  • @aryaroxanne3225
    @aryaroxanne3225 Місяць тому

    wow that apk. funny stuff

  • @theappealtoheaven
    @theappealtoheaven Місяць тому

    Please more of this, also please install the apk. 😂

  • @megafoxatron3rd521
    @megafoxatron3rd521 Місяць тому

    the guy can't figure that google is one of the top searches without doing a google search

  • @Steve60638
    @Steve60638 15 днів тому

    1jt+ means 1 million plus.

  • @dytra_io
    @dytra_io Місяць тому

    that apk is a betting app

  • @deimantasle4881
    @deimantasle4881 Місяць тому +4

    actual content of the video starts at 13:00

  • @Nitroband
    @Nitroband Місяць тому +1

    I hope you were running a VPN, your IP Address got dropped by one of those pages.

    • @wombatpandaa9774
      @wombatpandaa9774 Місяць тому

      I'm pretty sure that was the digital ocean ip and not his host

    • @Nitroband
      @Nitroband Місяць тому +1

      @wombatpandaa9774 Okay, that's good then!