Interesting People mailing list archives

Bah bah phooey -- content cookie and typo exploring


From: Dave Farber <dave () farber net>
Date: Wed, 17 Sep 2003 09:47:14 -0400

What have those id..ts done !! djf


Delivered-To: dfarber+ () ux13 sp cs cmu edu
Date: Wed, 17 Sep 2003 08:19:18 -0400
From: Seth Finkelstein <sethf () sethf com>
Subject: Re: more on Verisign - content cookie and typo exploring
To: Dave Farber <dave () farber net>
Cc: Gene Gaines <gene.gaines () gainesgroup com>

Gene Gaines wrote:
>Did you notice that the above indirectly implies you give Verisign
>authorization to do content filtering for you? Gosh. That is yet
>another legal notice, at
>http://sitefinder.verisign.com/preferences.jsp?cookie=1&ru=/lpc
>
>If you access that page, Verisign automatically places a cookie and
>sets "Partial filtering".

        That cookie apparently controls which domains are suggested
for the typosquatting, and the results of the search engine. It can
have the three values 'nofilter', 'moderate', 'strict'.

        I've been investigating the squat-suggestion algorithm, seeing
if there's a notable pattern. Accessing the redirect page directly,
with specific arguments, means one can even see what would happen if
they squatted existing domains. For example, for "farber.net", it
corrects it to (on all three settings):

"www.barber.net,www.farber.com,www.farrer.net,www.karber.net"

        Some domains seem to return results which are not constant,
i.e. reloading the page changes which squat-suggested domains are
displayed. I don't think it's an advertising rotation, but the
behavior is similar to that practice.

        I've written a little program to examine this, available at:
"Verisign Typosquatter Explorer"
http://sethf.com/domains/verisquat/

--
Seth Finkelstein  Consulting Programmer  sethf () sethf com  http://sethf.com
Anticensorware Investigations - http://sethf.com/anticensorware/
Seth Finkelstein's Infothought blog - http://sethf.com/infothought/blog/

-------------------------------------
You are subscribed as interesting-people () lists elistx com
To manage your subscription, go to
 http://v2.listbox.com/member/?listname=ip

Archives at: http://www.interesting-people.org/archives/interesting-people/


Current thread: