Finding WEIRD Typosquatting Websites

Поделиться
HTML-код
  • Опубликовано: 18 мар 2024
  • jh.live/flare || You can track down shady sellers, hunt for cybercrime, or manage threat intelligence and your exposed attack surface with Flare! Try a free trial and see what info is out there: jh.live/flare
    Free Cybersecurity Education and Ethical Hacking with John Hammond
    📧JOIN MY NEWSLETTER ➡ jh.live/email
    🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware
    🔥RUclips ALGORITHM ➡ Like, Comment, & Subscribe!
    Music sourced from Artlist.io
    Alon Ohana - Parallel Room
    Stanley Gurvich - Sunny Days

Комментарии • 330

  • @memesfromtheforsakenworlwi9218
    @memesfromtheforsakenworlwi9218 3 месяца назад +2568

    fun facts, most companies buy as much of those "typo domains" to make them redirect to the real site

    • @madloudnoises
      @madloudnoises 3 месяца назад +214

      Ah, I was wondering why they kept redirecting to the real site. Cool!!

    • @Azuuraas
      @Azuuraas 2 месяца назад +98

      yup, i know for sure google did that

    • @GOOFLEr
      @GOOFLEr 2 месяца назад +21

      'Most'

    • @kuromiLayfe
      @kuromiLayfe 2 месяца назад +125

      still check if you are on the real
      site.. as the scammers can spoof the address bar and status bar to show the official url (and of course also the titlebar and all links when using inspector). just takes 3ms to replace what is shown the moment the page or hover is activated.

    • @BillAnt
      @BillAnt 2 месяца назад

      Cuz many type "goggle" when typing fast. lol

  • @kalicxingnjenga9657
    @kalicxingnjenga9657 3 месяца назад +2568

    Please do a video showing what’s inside that APK.

    • @TomJacobW
      @TomJacobW 3 месяца назад +84

      hearted - neat! Looking forward to seeing that!

    • @IDontModWTFz
      @IDontModWTFz 3 месяца назад

      Get APK tool and do it yourself, apks are really easy to re

    • @posifurg
      @posifurg 3 месяца назад +66

      Im going to do a vid showing the APK - ill post it when i can

    • @DEZXD1
      @DEZXD1 3 месяца назад +5

      The apk says failed to download something

    • @adventureman6997
      @adventureman6997 3 месяца назад +2

      Yes

  • @bdot02
    @bdot02 3 месяца назад +537

    Personally like "guthib"

  • @AKABeestYT
    @AKABeestYT 2 месяца назад +411

    I love the typos for regularly nsfw sites that redirect to sites that ask you to repent and fix your ways

    • @fruitynyanko7316
      @fruitynyanko7316 Месяц назад +25

      How did you find out about such sites 🤨📸

    • @AKABeestYT
      @AKABeestYT Месяц назад

      @@fruitynyanko7316 twas simply a passing thought

    • @spimbles
      @spimbles Месяц назад +103

      ​@@fruitynyanko7316by being a normal human being and watching porn, if i had to take a total shot in the dark

    • @dubplater
      @dubplater Месяц назад +27

      @@spimblesthats not normal

    • @johanmikkael6903
      @johanmikkael6903 Месяц назад +38

      ​​@@dubplaterI guess cavemen drawing NSFW art back then are also not normal either, but then again, being black in America was considered not normal in the 19th century so the definition of "normal" is kinda relative.

  • @kyokazuto
    @kyokazuto 3 месяца назад +1069

    "I think that is the real google", he says looking at google from 10 years ago

    • @mordek_original
      @mordek_original 2 месяца назад +6

      interesting

    • @Yadobler
      @Yadobler Месяц назад +41

      I believe that some devices will result in the old version loading, probably for compatibility

    • @kyokazuto
      @kyokazuto Месяц назад +2

      @@Yadobler I highly doubt that

    • @rosenette11
      @rosenette11 Месяц назад +21

      @@Yadobler You're right, my Vita loads exactly this ver of google

    • @aloedg3191
      @aloedg3191 Месяц назад

      "I highly doubt that" -🤡​@@kyokazuto

  • @dinosaurgardening2401
    @dinosaurgardening2401 3 месяца назад +1147

    I know the guy who bought Google with 3 ooo's. He bought it in high-school because he was smart. He isn't a scammer.

    • @4rumani
      @4rumani 3 месяца назад +99

      Yeah very smart lol. Obvious WIPO violation, no legitimate interest, bad faith typosquatting

    • @Linkman8912
      @Linkman8912 3 месяца назад

      ​@@4rumanichill

    • @justarandomchannel1319
      @justarandomchannel1319 2 месяца назад +65

      Bro could prolly sell that for alot tho

    • @ihatenerds4689
      @ihatenerds4689 2 месяца назад +215

      ​@@4rumaniyou are a sad being

    • @Limelaz23
      @Limelaz23 2 месяца назад +60

      ​@@4rumani y so salty

  • @wombatpandaa9774
    @wombatpandaa9774 3 месяца назад +251

    Near the beginning I jokingly thought this was going to be an ad segment for Nord VPN but to my pleasant surprise it's an actually really useful FOSS tool. Love to see it.

  • @Gamerappa
    @Gamerappa 3 месяца назад +206

    14:34 google looks like this on certain user agents, it's their old design from 2011-2013

  • @kidnamedfingor
    @kidnamedfingor 2 месяца назад +164

    Just to let u know, when i went on the googie website, there was some illegal content, if i were you i would cut that part out. I went on that domain i wish i could unsee what i saw.

    • @jjprisma3d
      @jjprisma3d 2 месяца назад +10

      It’s really traumatizing.

    • @kidnamedfingor
      @kidnamedfingor 2 месяца назад +12

      @@jjprisma3d cant believe he actually let it slip into this video

    • @jjprisma3d
      @jjprisma3d 2 месяца назад +7

      @@kidnamedfingor Atleast he blurred it.

    • @jjprisma3d
      @jjprisma3d 2 месяца назад +26

      @@kidnamedfingor And also, whoever's chid was that. I feel bad for the parents. The person who did that shoud be ashamed.

    • @kidnamedfingor
      @kidnamedfingor 2 месяца назад +9

      @@jjprisma3d I translated the Chinese and it said that it was the dad who did it

  • @aoihitsu
    @aoihitsu Месяц назад +23

    Fun fact: my mom used to work in a kids magazine and their website domain looked like a corn site, and bc parents were angry that their kids saw corn by making typos, the mag had to give money to the other site so they would change the name 😂 thats so funny to me

  • @ExperiencersInternational
    @ExperiencersInternational 3 месяца назад +93

    It was funny seeing Goole as one of the screenshots 😂
    Had some fun with pronouncing it when driving past signs for that place on the motorway a few months ago

  • @adamn0
    @adamn0 2 месяца назад +181

    please don’t go to the website at 19:40 i wish i wasn’t curious and went to it i think you should blur out that link or remove that part of the video it’s absolutely disgusting

    • @zixea3318
      @zixea3318 2 месяца назад +33

      yeah there’s CP on there 🤢

    • @donaldud-deen7604
      @donaldud-deen7604 Месяц назад +4

      Bro whats in there?

    • @dan_loeb
      @dan_loeb Месяц назад +40

      this is one of those things where it's best not to check at all. there is a really messed up image there.

    • @tankman5783
      @tankman5783 Месяц назад +10

      ​@@dan_loebman just describe it i dont want the fbi knocking on my door

    • @dan_loeb
      @dan_loeb Месяц назад +49

      @@tankman5783 the site has c.s.a.m. material and should not have made it in to the video period. If you don't know what that means it's often called cp. if you don't know what that means, I'm not going to describe it, as it violates yt policy and should be reported and avoided.

  • @Fluttergoat
    @Fluttergoat 3 месяца назад +134

    Isn't a $32/Month virtual server absolutely overpriced and overkill for this? Maybe I just don't know enough about the program or droplets so I'd be curious if there was a genuine reason it had to be that expensive.

    • @T1C
      @T1C 3 месяца назад +13

      Probably could get by on a $5 vps

    • @tbuk8350
      @tbuk8350 2 месяца назад +6

      he could've probably done the same thing on oracle always free compute

    • @ijucr2267
      @ijucr2267 Месяц назад

      Absolutely

  • @Scootakip
    @Scootakip Месяц назад +30

    This video really is the meme of "Linux users trying to install a web browser"

  • @ricestrange
    @ricestrange 2 месяца назад +54

    The true video begins somewhere at 13:00

  • @papei.taisii
    @papei.taisii Месяц назад +19

    I have fallen for Agor,io. I wasn't scammed, but traumatised (TW: loud sound + flashing Jeff the Killer image)

    • @jiuleender7046
      @jiuleender7046 8 дней назад

      Oh you just unlocked my childhood trauma

  • @foundmedia
    @foundmedia Месяц назад +13

    hey man, i'm going to repeat what a few other commenters said, you should edit this video to remove that one "weird" website because showing the link is technically distribution of cp. NOT visiting the website myself, just relaying what other commenters saw when they visited the site out of curiousity, maybe you didn't even realize what you were looking at because you laughed it off so easily in this video.

    • @Noughtsgnik
      @Noughtsgnik 22 дня назад

      how do you know if it's cp or not

    • @venerablepoof
      @venerablepoof 9 дней назад +1

      Why would you risk it?

  • @greenockscatman
    @greenockscatman 3 месяца назад +78

    I like the raw realism of the Linux experience at 17:30

  • @cybercub4367
    @cybercub4367 3 месяца назад +239

    Please do reverse engineer that APK, we're bound to find something juicy there 😂

    • @ThinkOrchid
      @ThinkOrchid 25 дней назад

      As an indonesian, im sure that's a site to auto download an online gambling app. Mimics play store, too.

  • @circuitgamer7759
    @circuitgamer7759 3 месяца назад +14

    I would love to see you doing this more, it's just really fun to watch you have fun with it :) Also looking forward to you looking through those files :)

  • @WebDesignerAmy
    @WebDesignerAmy 3 месяца назад +16

    This was a great utility to learn about John! Def found some permutations of some domains I own and those for another creator that came up. ty!

  • @ThisIsJustADrillBit
    @ThisIsJustADrillBit 3 месяца назад +61

    Its such a fun rabbit hole watching malicious domains as they are registered. Weird how many of them sre hosted behind cloud flare these days... 🤔

    • @chigga5years173
      @chigga5years173 3 месяца назад

      Why does cloudflare even support them?.. I recently got an sms scam of gettimg rich easily and upon scanning and tryim7to find vulnerabilities of those scammers.. I didn't get anything

    • @PazLeBon
      @PazLeBon 3 месяца назад +2

      cos cheap hosting is slow :)

    • @chrissametrinequartz9389
      @chrissametrinequartz9389 3 месяца назад +2

      or it could also be (for whatever reason) that, thats what they are using to manage their domains or smth

  • @chri-k
    @chri-k 3 месяца назад +112

    RUclips actually owns the domain youtobe, apparently

    • @81gamer81
      @81gamer81 3 месяца назад

      you to be, is actually how its meant to bee. Monkey see monkey do. They decide what you see, and what you do

    • @FnafAcc-bg9vn
      @FnafAcc-bg9vn Месяц назад

      Oneshot

    • @Nakia11798
      @Nakia11798 11 дней назад

      Pretty sure they dont, however, own youtub.

  • @purplepeak8575
    @purplepeak8575 3 месяца назад +15

    Trying this back on Windows 95-Windows XP days is a guaranteed PC destroyer.

    • @WALLE1D1W
      @WALLE1D1W Месяц назад +1

      Funnily enough, today it's probably safe to do this on the MS-DOS based Windows 9x versions of Windows, as they're too old to be a worthwhile target for malware. All the viruses that you might encounter naturally expect XP and later. At least, according to MattKC's video on the subject.

  • @pitche
    @pitche 3 месяца назад +116

    14:33 It's an old Google UI :)
    Thx for the likes 😆

  • @blakeeey27
    @blakeeey27 2 месяца назад +10

    i love the term typosquatting sm

    • @cormarcormar
      @cormarcormar 2 месяца назад +4

      the phishers are just squattin on that typo

  • @kiwipomegranate
    @kiwipomegranate 3 месяца назад +40

    Please make a part two I wanna see more about that "live (ph)fishing game" and the Amazon typosquat hijinks

  • @uuu12343
    @uuu12343 3 месяца назад +2

    This is genuinely amazing for Typosquat monitoring and intelligence gathering

  • @Noctuu
    @Noctuu 3 месяца назад +15

    Loved this video, u should do more “unserious” funny videos, either here or on a secondary channel

  • @skelkankaos
    @skelkankaos 2 месяца назад +5

    Really enjoyed this video because it's a topic that's interesting and you let it be interesting on its own merits instead of overly sensationalizing it

  • @februalist4686
    @februalist4686 2 месяца назад +1

    WE NEED a continue of this series

  • @bokrayoomjdeed
    @bokrayoomjdeed 3 месяца назад +1

    loved this thanks JOHN ;)

  • @zixea3318
    @zixea3318 2 месяца назад +60

    Linux users typing the entirety of their computer’s code into the command line just to make a new folder: 🤬🤬🤬

    • @thesoftone
      @thesoftone 2 месяца назад +7

      ^ this user knows nothing about computers

    • @spaghetti5914
      @spaghetti5914 Месяц назад +30

      ​@@thesoftoneSalty linux user ^

    • @thesoftone
      @thesoftone Месяц назад +1

      @@spaghetti5914 ^ GIGA cope

    • @spaghetti5914
      @spaghetti5914 Месяц назад +14

      @@thesoftone This user doesn't know I'm a linux user as well ^

    • @Shoegaze-
      @Shoegaze- Месяц назад +1

      Lain pfp hating on Linux…
      Get off TikTok lol

  • @k1ngslay3r41
    @k1ngslay3r41 3 месяца назад +14

    lol I never noticed you owned a whole island of dinosaurs that's AWESOME!

  • @rocket01666
    @rocket01666 3 месяца назад +46

    Crack open that APK next PLEASE!

  • @oz_jones
    @oz_jones 3 месяца назад +9

    Youtubs - for all your Jacuzzi needs!

  • @mattnaylor29
    @mattnaylor29 3 месяца назад +11

    There is a bank in the uk called first direct. My 80+ year old family went to fist direct, it was a fisting porn site.

  • @lordvgames
    @lordvgames 3 месяца назад +1

    should do more dnstwist shenanigans, really fun to see what you find

  • @BrimmFate
    @BrimmFate 3 месяца назад +3

    Adversaries is a funny way of describing scammer. Like calling them enemies

  • @dannydetonator
    @dannydetonator 2 месяца назад +2

    As someone not well versed in IT, coding and html, i just learned a bunch of new words here. Typosquatting just made me think of my poor-ass unaccomodated seasonal-worker (initially) eurotrip.

  • @nrhowe84
    @nrhowe84 3 месяца назад +3

    That is such a cool tool, would love to see a video on what is inside that apk file. Great video keep up the great work that you do.

  • @half-faust
    @half-faust 2 месяца назад +4

    Ah, the eternal internet nemesis: people with the same full name as you.

  • @CainXVII
    @CainXVII 2 месяца назад

    This was great. Would have loved to see some other websites too. And what was actually in that fish file....

  • @iBridgee
    @iBridgee 3 месяца назад +22

    Who knew typosquatting could be so bizarre? 😅

  • @aidi4886
    @aidi4886 3 месяца назад

    I choose you John. Make me smart!!!

  • @AmCanTech
    @AmCanTech 2 месяца назад +7

    The site that redirects to aliexpress is likely a 3rd party that outputs their affiliate link so they earn a commission... even if you dint shop via that link directly, a refer cookie is likely stored such that if you end up shopping within X amount of time they get credit for the sale.

    • @giraffeparty0
      @giraffeparty0 27 дней назад

      their affiliate WHAT??? ik u meant link but thats an unfortunate typo lol

  • @bokrayoomjdeed
    @bokrayoomjdeed 3 месяца назад

    Hilarious maaan daamn! nice video bro really thanks.

  • @milentiusgaming
    @milentiusgaming 3 месяца назад +3

    looking forward to THE video of the breakdown of the APK, maybe there was more to the "nothing" in the empty text file....

  • @murphy2269
    @murphy2269 14 дней назад

    i have no idea what you're talking about but i love this video

  • @DerMarkus1982
    @DerMarkus1982 3 месяца назад

    Let's see if Jason will feature John Hammond in a clip compilation soon 😁

  • @Jarkabob
    @Jarkabob Месяц назад +2

    I tried that one time and got a virus 😭

  • @yewo.m
    @yewo.m 2 месяца назад +1

    This gave me "hacking in movies" vibes

  • @ownmicelio
    @ownmicelio 3 месяца назад +1

    Please do a part 2

  • @JohnDoe-bd1qe
    @JohnDoe-bd1qe 3 месяца назад +4

    Now I see the true meaning of the minor spelling mistake meme.

  • @pavi013
    @pavi013 4 дня назад

    I usually bookmark all the sites i visit daily, but obviously mistakes can happen.

  • @abdoudicko5352
    @abdoudicko5352 3 месяца назад

    You are the best

  • @lancemarchetti8673
    @lancemarchetti8673 3 месяца назад

    Brilliant

  • @ErichSchulz
    @ErichSchulz 3 месяца назад +1

    It seems to have a domain name size limit when using the web interface.

  • @thesoftone
    @thesoftone 2 месяца назад

    kinda makes me want to try live booting Kali maybe, cool vid

  • @Ramonatho
    @Ramonatho 2 месяца назад +3

    Wait. Hang on. I noticed something about that slots game with the automatic download. On the section that says "The New One" it mentions Bob Slots, a youtube channel I watch, who has never promoted this app. That means they're scraping ultra specific small slots youtubers and saying they're promoting their game. Bob isn't a big channel. This is truly weird stuff.

  • @user-cd4bx6uq1y
    @user-cd4bx6uq1y 3 месяца назад +14

    16:59 that's master Rama isn't it? The cult
    Edit: 19:41 amazing reaction

    • @monkepog3236
      @monkepog3236 2 месяца назад +8

      theres even illegal content on it, jail for at least 30 years for hosting it

  • @sucra0710
    @sucra0710 3 месяца назад +3

    Dnstwist it, bop it, pull it

  • @joebambanchannel
    @joebambanchannel 3 месяца назад

    The best,👍

  • @Nooner301
    @Nooner301 Месяц назад +1

    a little help, the live fishing page is in Indonesian, prolly trying to steal info or malware due to how many people use gambling / slot sites and apps here. 1jt is 1 million, reffering to downloads

  • @scykol
    @scykol 2 месяца назад +4

    domain expansion: typo

  • @cherno6592
    @cherno6592 2 месяца назад +2

    that fishing live game is advertising as that one gambling game or application, it on Indonesian language

  • @malka1762
    @malka1762 2 месяца назад +1

    gotta hand it to the fishing "devs", they're kinda transparent when you think abt it 😂

  • @abdelhay.
    @abdelhay. 3 месяца назад +3

    WE WANT MOOORE OF MALWARE ANALYSIS VIDEOS PLEASE.

  • @Nitroband
    @Nitroband 3 месяца назад +5

    I hope you were running a VPN, your IP Address got dropped by one of those pages.

    • @wombatpandaa9774
      @wombatpandaa9774 3 месяца назад +1

      I'm pretty sure that was the digital ocean ip and not his host

    • @Nitroband
      @Nitroband 3 месяца назад +1

      @wombatpandaa9774 Okay, that's good then!

  • @iesx_imchocomint
    @iesx_imchocomint 24 дня назад +1

    The 19:40 website is now safe to go to. It now redirects to a gambling site.

  • @scrungles7853
    @scrungles7853 2 месяца назад +4

    I have no idea what you're talking about, nice!

  • @The_hot_blue_fire_guy
    @The_hot_blue_fire_guy 3 месяца назад +1

    Is there a program like that website detecting thing for people who use normal operating system like windows or Mac OS and not those hacker OSs like Linux. You know, normal software for normal people that actually exist in the real world.

  • @mattsadventureswithart5764
    @mattsadventureswithart5764 3 месяца назад +1

    Based on the one guy I met with that first name, its pronounced "Mar cheen" with the "mar" being the same as "mark" without the k, and "cheen" being the same as "cheese", with an n instead of the z sound.

  • @MFoster392
    @MFoster392 3 месяца назад +1

    Very Cool :)

  • @shakinspider
    @shakinspider 27 дней назад +1

    You just committed a federal crime by not blurring out the links to some of these websites

  • @Ilikeflowers22
    @Ilikeflowers22 2 месяца назад +1

    Unrelated, but i really like your hair :)

  • @stefanjohansson2373
    @stefanjohansson2373 3 месяца назад +3

    16:50 Never seen this?!

  • @purplesam2609
    @purplesam2609 2 месяца назад +1

    I wanted to go to the SpongeBob website as an 8 year old kid on my grandma's laptop and I found a site with a photo of some random man with a typo

  • @iwasneverjoebiden
    @iwasneverjoebiden Месяц назад

    good video

  • @oussemabenayech2345
    @oussemabenayech2345 3 месяца назад +7

    every jhon hammond should get into a fight and see who will earn the name

    • @PazLeBon
      @PazLeBon 3 месяца назад

      not a fight, even a dummy can win a fight

  • @harrylumsdon6773
    @harrylumsdon6773 3 месяца назад

    Chrome and edge has the safe search option??

  • @v.adithya1768
    @v.adithya1768 3 месяца назад

    Hi, When i run the --phash command, I get this error even though selenium is already present in /usr/lib/python3/dist-packages
    dnstwist: error: missing Selenium Webdriver

  • @SilentOnion
    @SilentOnion 2 месяца назад

    14:33 is not really "strange" google its just the old design from like the late 2000s.

  • @UltimatePerfection
    @UltimatePerfection 3 месяца назад

    Marcin is (roughly) pronounced as Martzin.

  • @pollywops9242
    @pollywops9242 3 месяца назад

    Super useful tool

  • @gurukuappannadora8982
    @gurukuappannadora8982 3 месяца назад

    Excellent stuff but we are missing actually what you are explaining kindly explain your experience in slow motion I feel it something like something that computation is going here

  • @powmod
    @powmod 17 дней назад

    13:50 I would guess they are redirect domains. Google owns a lot of its homonyms.

  • @rob-890
    @rob-890 3 месяца назад +1

    He's doing the thing where he repeats synonyms over and over again 😂😂😂😂

  • @soloriyeovin5011
    @soloriyeovin5011 Месяц назад

    very fun

  • @liviaw
    @liviaw Месяц назад +1

    That Fishing Live Game is probably targeted and/or made by Indonesians. “1jt” means “1 million”. Just thought I’d share this

  • @PegasusEpsilon
    @PegasusEpsilon Месяц назад

    "sudo" is short for "do as superuser" - "sue due", not "sue dough" - sudo is not a martial art.

  • @davidetl8241
    @davidetl8241 3 месяца назад

    Cool

  • @TrulyChxse
    @TrulyChxse Месяц назад

    Nice

  • @methical__
    @methical__ 3 месяца назад

    Interesting you don't know plesk, is this a europe hosting thing?

  • @Steve60638
    @Steve60638 2 месяца назад

    1jt+ means 1 million plus.

  • @Breecheesegeez
    @Breecheesegeez 2 месяца назад

    i've seen roblox typosquatting websites before

  • @doyouknowkeplertwentytwob4032
    @doyouknowkeplertwentytwob4032 Месяц назад +2

    holy shit it’s alex yiik

  • @megafoxatron3rd521
    @megafoxatron3rd521 3 месяца назад +1

    the guy can't figure that google is one of the top searches without doing a google search

  • @YTInnovativeSolution
    @YTInnovativeSolution 3 месяца назад +2

    Daily Dose of Internet is one of the best channels ever made. Thanks for your daily dose Mr. H.

  • @gamernikan
    @gamernikan 3 месяца назад

    cool (there is not your ip at 15:48)