Cameroon the New Hotbed of Malware 92
garg0yle writes "According to McAfee, more than a third of Cameroon domains (TLD of .cm) are infested with viruses or other not-so-fun party treats. Given that it's very easy to mis-type .com as .cm, this puts the computers of a lot of fat-fingered typists in peril. Second place on the most-infested domains list goes to China (.cn), while Hong Kong (last year's 'winner') is now comfortably middle-of-the-pack."
Mistype (Score:1, Insightful)
Re:Mistype (Score:5, Funny)
I have n "" letter n my keybard, yu insensitive cld!
Re: (Score:1, Informative)
Sounds you got one of those keyboards left by the W Bush admin for the next president.
Re:Mistype (Score:5, Informative)
What is "they" in that sentence, or did you mean "TLDs" instead of "websites"?
.og doesn't exist. You might want to consult a list of TLDs before you ask a bunch of "what about" questions. Or install a robust browser and try to load the url instead of just wondering about it.
Re: (Score:2)
Re: (Score:2)
Yes, I meant TLD's not webistes. (sic) I wasn't aware that .con wasn't a valid TLD . And .og was meant to be a joke.
Which makes your comment worthwhile how, exactly ? Please refrain if you have no idea what you're talking about or take a minute to use your search engine of choice to see what the hell it is that people are talking about. As a rule geographic TLDs match the two letter country codes (as defined by ISO, see ISO-3166-1, relevant table is "alpha 2") most of the time.
See the handy table at http://en.wikipedia.org/wiki/ISO_3166-1#Officially_assigned_code_elements [wikipedia.org] or http://www.iana.org/domains/root/db/ [iana.org] for the r
Re: (Score:2)
I wasn't aware that .con wasn't a valid TLD (It should be valid for the scammers).
Really? We should dedicate a whole TLD just for scammers? Was that supposed to be a joke?
And .og was meant to be a joke.
Ok, I guess you did mean it as a joke if you thought that one would fly too. It went over like a lead balloon, though.
Here's a tip from an internet professional: Do research before you make posts on a site that you can't delete or edit your comments on. If you make a mistake, reply to yourself and correct it. Otherwise people who have karma to burn will correct you, much like myself.
Re: (Score:3, Funny)
.CONNNNNNNNNNNNNNN!!!!!!!
To that I'll add (Score:4, Informative)
That different nations treat their TLDs differently. Some sell them to anyone who wants one. You can register them as long as you are willing to pay whatever fee it is they ask. The .tv domain is one such domain. Others make the domains available, but only to people or organizations that meet certain requirements like citizenship. Canada (.ca) would be one like that. Any Canadian can have a .ca domain if they are willing to pay for it, but non-Canadians can't buy one. Still others only use their domain for government or internal functions. The .us domain was like that at one time. You could get it only as an entity like a county government or a high school or something (it is now open for registration). Finally some countries simply don't do anything with their TLD, it just isn't used at all and there's no way to get it.
So just because a TLD exists, doesn't mean it can be used for any given purposes.
Re: (Score:1)
Reminds me of the time I tried to get an Antarctica domain (.aq), and the first email I got back stated "Sorry, to register you must live on the ice"
As for the history of the .us cctld, even back in the late 80s, one could register a subdomain out of it being an individual (and it was free too! Then again, so was .com)
However they did have and enforce a strict organizational structure.
From what I recall, you had to get [something].county.state.us
Later they opened it up more, but was still state/group sect
Re: (Score:2)
'But wheah's the necessity? It seems an uncommonly woundabout and hopelessly wigmawolish method of getting anywheahs. Look heah now, I've got the wuhks of the mastahs -- the gweat ahchaeologists of the past. I wigh them against each othah -- balance of the disagweements -- analyze the conflicting statements -- decide which is pwobably cowwect- and come to a conclusion. That is the scientific method. At least' -- patronizingly -- 'as I see it. How insuffewably cwude it would be to go to Ahctuwus, oah to Sol, foah instance, and blundah about, when the old mastahs have covahed the gwound so much moah effectually than we could possibly hope to.'
-- Isaac Asimov, Foundation
Re: (Score:2)
.co is Colombia, .om is Oman, but .con doesn't exist.
That's a shame, coz then we could have all the malware and phishing websites under one roof like porn is with .xxx. :-(
Re:Mistype (Score:5, Informative)
In any case... (Score:3, Insightful)
Regardless of the answer, the appropriate response is to use a robust browser and block individual sites, not block out whole nations. Otherwise one might just as well move to China.
Re: (Score:3, Informative)
I can't remember the last time I typed "com".
Seriously - with ctrl+enter, who needs to?
Re: (Score:2)
I typed "Ctrl+Enter" and nothing happened.
I want my money back !
Re: (Score:3, Funny)
Re: (Score:1, Funny)
I just went there, and BUY CHEAP VIAGRA yes, it is WILL MAKE YOU 9 INCHES LARGER full of viruses. SO BIG YOU COULD PUT IT ON A BUN AND EAT IT!
Re:Mistype (Score:5, Informative)
While I can believe that .cm is a mistype for .com, what about .co, .con, .om? They don't seem to be high risk websites. I also bet that .con is a more common mistype than .cm
It hardly matters. What many of the press reports (including El Reg) seem to ignore is the second most risky TLD in the world: .com.
I'll bet you dollars to donuts that, because of the size and popularity of the TLD, .com is significantly more of a threat to the average Internet user than .cm.
And while we're at it, how about a link to the actual report [mcafee.com]? (warning: PDF)
Re: (Score:1, Offtopic)
And while we're at it, how about a link to the actual report [mcafee.com]? (warning: PDF)
Do people really still fear PDFs? I can't believe Acrobat Reader is still so utterly utterly broken out of the box when every single other PDF reader will open a PDF more or less instantaneously.
Re: (Score:2)
Are you sure? Can you provide a link?
Mcafee and a PDF. Two pieces of malware from one .com site. Excellent evidence, sir.
Re: (Score:1)
It's a bit of a stretch for me to believe that .cm is a typo of .com. When I mistype .com, it's usually .co or .cmo. But I never just forget the o like that.
Re: (Score:2)
what about .co, .om? .con
assigned to colombia and oman respectively but don't allow registrations directly under the tld so not useful for cybersquatters.
doesn't exist.
I also wonder whether slashdot.og is infested with viruses. .og doesn't exist either
Missing keys? (Score:2, Interesting)
Re: (Score:2, Funny)
Re: (Score:2)
My usual typo is .copm
POLL: have you ever mistyped .cm for .com? (Score:3, Interesting)
Really? I've never done it. Never. /me goes to point .cm to 127.0.0.1 .
Re: (Score:2)
I prolly shouldn't do that, this machine I'd point to is full of current malware.
(if I'm on my analysis machine, that is...)
Re: (Score:2)
Once just recently - I was holding my infant daughter so had to type one-handed.
OpenDNS caught the error and warned me away from a malware site. Don't remember where I was going at the time.
Wouldn't it be safer to... (Score:4, Insightful)
to just block the whole Net? That way, you can't visit any website, thus avoid all websites hosting malware. Either that or have a patched, updated browser, and use smart surfing habits.
Re:Wouldn't it be safer to... (Score:5, Insightful)
Blocking .cm can be a helpful step, because it blocks a portion of the hostnames that (A) if you visit has a very high probability of infecting you, and (B) that an intentional visit to is unlikely.
So you can block .cm with a notable increase in safety, with a minimal decrease in usefulnes of your internet access.
The same could not be said of blocking the whole net. Blocking the whole net reduces the utility of your network connection, since it means you can no longer navigate to the sites that you do want to, with high probability.
Re: (Score:3, Funny)
Blocking .cm can be a helpful step
I live in Cameroon, you insensitive clod! But then again, malware is not at the top of my worry list... carry on then.
Re: (Score:2)
Seriously, do away with it and go back to gopherspace. No viruses there, probably. The WWW is overrated.
.com default (Score:3, Informative)
I am Naga Eboko, exchange student from Cameroon. (Score:4, Funny)
Re: (Score:2)
HAPPY CHRISTMAS!
No, I don't think it is (Score:4, Interesting)
Given that it's very easy to mis-type .com as .cm, ...
I can safely say I've never done this. I've made other errors - such as ending up in Estonia's (.ee) web space on occasion, since I work in an electrical engineering department. But I can't believe leaving out the "o" from ".com" is particularly easy or at all common.
Now if you wanted to talk about Colombia (.co) being a frequent typo for .com domains, then I might find it more believable. I have done that on rare occasions.
Re: (Score:2)
I can safely say I've never done this. I've made other errors - such as ending up in Estonia's (.ee) web space on occasion, since I work in an electrical engineering department. But I can't believe leaving out the "o" from ".com" is particularly easy or at all common.
I can't figure out how you think ending up at a domain ending in .ee because you're an electrical engineer is less weird than mistyping .com
Re: (Score:1)
So missing the m key, or not pressing it hard enough is logical but missing out the o is just crazy talk?
I guess that makes sense...if you have a particularly weak index finger.
Re: (Score:1)
Yes, but... (Score:4, Funny)
...they make those delightful coconut cookies. I think we can forgive them.
Re:Yes, but... (Score:5, Funny)
Hate to break it to you, but those ain't coconut cookies that they sent to your browser...
Auto-Correcting Domains (Score:1)
It's water under the bridge, but in hindsight, it would have been better to not create the alternate TLDs .cm, .co. While I'm at it, tell me there's a good reason we have augmented reality iPhones and 60 MPG cars but not web browsers that autocorrect non-existent TLDs.
Seriously, why doesn't every browser have a "I don't live in Cameroon or Colombia; auto-correct .cm and .co to .com, don't warn me when doing it, and don't bother me about this again" option? (I know, I know, .hosts and/or Firefox extensions.
Re:Auto-Correcting Domains (Score:5, Funny)
I knew a guy called Teh but unfortunately Microsoft tools auto correct that to The.
Re: (Score:2)
I knew a guy called Teh but unfortunately Microsoft tools auto correct that to The.
Clearly he should change his name. I'd like to suggest Meh.
Re:Auto-Correcting Domains (Score:4, Insightful)
stuck key (Score:3, Insightful)
typing *.cm instead of .com is as simple as having an o key that gets stuck occasionally and not noticing the typo. All it takes is a keyboard that needs a good cleaning and a user that isn't paying enough attention.
Re: (Score:2)
typing *.cm instead of .cm is as simple as having an key that gets stuck ccasinally and nt nticing the typ. All it takes is a keybard that needs a good cleaning and a user that isn't paying enough attentin.
FTFY ;-)
No, it comes from.... (Score:1)
.pron links
OpenDNS has an option to fix this (Score:4, Informative)
Opendns has an option to automatically 'correct' .cm requests to .com, which I always turn on. If Cameroon does not want people doing this, then it would have to police it's domain closely, instead of using it as a cash cow.
Re: (Score:1, Informative)
OpenDNS also rewrites NXDOMAINS to host advertisements.
Why do people keep spamming this service like it doesn't suck?
Re: (Score:2)
OpenDNS really is an abomination unto the Domain Naming System as bad as any ISP's NXDOMAIN redirection.
But IOKIYFTM --- It's Okay If You're Fighting The Man
(Or have a PR department that creates that impression.)
Re: (Score:2)
Because it's opt-in and doesn't hijack your DNS unless you tell it to?
I don't use it myself though sicne I run bind and do my own DNS caching.
Re: (Score:2)
On top of it there's nothing open about them. No source, no open development, community, etc. Its just a company that tracks people and breaks NXDOMAIN. Man, is running bind on something so hard? There's even a pretty nice dumbed down GUI windows port called Treewalk.
Re: (Score:1)
In closing, "smart" DNS is a dumb decision, even for dumb people.
Re: (Score:2)
OpenDNS breaks the DNS standard, as it returns a search page for non-existent domains, there was actually a /. article about sites doing this not too long ago.
That is an option that can be turned on and off to your own desire.
Just uncheck the checkbox on your preferences page and it will not rewrite nxdomain.
FYI, most people like that feature. For the rest, who either don't like it, or do like it but for technical reasons can not have it, you can just not enable it.
Lastly, not to mention, you're letting
Re: (Score:1)
Re: (Score:1)
You and the four other people using OpenDNS must really be sitting pretty.
Cameroon is in Africa! (Score:2, Informative)
I hereby denounce this article — and the pseudo-statistics in it — as racist!
Gebyy zl nff!..
Is omitting a letter really a problem? (Score:2)
If so, change keyboards.
I see the real threat in letters getting mixed up (which probably does not matter so much in 3 letter TLDs, since I don't know of a cmo or ogr TLD) or a typo (.con, .prg), which also usually don't really result in anything damaging. .cm being mistyped as .cn might be a problem, though. But then again, it's like missing the flood to reach the drought, so...
The world is infected! Buy our stuff! (Score:1)
Let's get real and understand that the real purpose of providing this "information" is marketing. It is there to reinforce the message that the world is hopelessly infected with computer viruses and you absolutely MUST have the offerings of McAffee and other anti-virus software vendors. I'm not even sure why anyone would believe it is true.
Re: (Score:1)
Re: (Score:1)
So you are arguing that it's better to avoid antivirus completely?
There is hope beyond McAffee. Repent and convert to Linux.
Re: (Score:1)
Always one rotten apple (Score:2)
There will always be a worst and best in this category, as in anything you do in life. The problem is when it is deliberately set to that which happens to be .cm (which could be a mistype for many people)...if you think of whether this was intentional on the hackers part, you better believe it.
It could be any of the countries that have domains, and have no real talent for programming websites, but in the end, .cm extension, so should they not
you have to wonder, most are hosted on regular ISPs that offer the
Is there an easy way......? (Score:2)
To block any top level domain? I mean like an entry in the hosts file, etc.....
Re: (Score:2)
Nope, a host file is static and wont support and wildcards like *.cm.
You can run bind and play with the configuration or you can set your firewall to not let you make connections to cameroon's netblocks. That's assuming the cm stuff is actually hosted there. If not then you need to block via DNS.
# Country: CAMEROON
# ISO Code: CM
# Total Networks: 16
# Total Subnets: 100,864
41.92.128.0/17
41.190.224.0/22
41.191.100.0/22
41.202.192.0/19
41.204.64.0/19
41.205.0.0/19
41.205.64.0/19
41.211.96.0/19
41.216.176.0/20
41.217.1
Wow, another reference to Cameroon! (Score:1)