Slashdot Mirror


Cameroon the New Hotbed of Malware

garg0yle writes "According to McAfee, more than a third of Cameroon domains (TLD of .cm) are infested with viruses or other not-so-fun party treats. Given that it's very easy to mis-type .com as .cm, this puts the computers of a lot of fat-fingered typists in peril. Second place on the most-infested domains list goes to China (.cn), while Hong Kong (last year's 'winner') is now comfortably middle-of-the-pack."

66 of 92 comments (clear)

  1. Mistype by Lunoria · · Score: 1, Insightful

    While I can believe that .cm is a mistype for .com, what about .co, .con, .om? They don't seem to be high risk websites. I also bet that .con is a more common mistype than .cm I also wonder whether slashdot.og is infested with viruses.

    1. Re:Mistype by DavMz · · Score: 5, Funny

      I have n "" letter n my keybard, yu insensitive cld!

    2. Re:Mistype by Anonymous Coward · · Score: 5, Informative

      what about .co, .con, .om?

      .co is Colombia, .om is Oman, but .con doesn't exist.

      They don't seem to be high risk websites.

      What is "they" in that sentence, or did you mean "TLDs" instead of "websites"?

      I also wonder whether slashdot.og is infested with viruses.

      .og doesn't exist. You might want to consult a list of TLDs before you ask a bunch of "what about" questions. Or install a robust browser and try to load the url instead of just wondering about it.

    3. Re:Mistype by tsalmark · · Score: 1

      Some one with mod points give this guy a boost, I was about to say the same thing but, it's already been said by an anon.

    4. Re:Mistype by jrumney · · Score: 4, Informative

      It depends on the policies of the registrar for those top level domains. Some countries allow free for all registration of domain names, others restrict registration to local companies and citizens only. Also many country tlds require specific sub-domains such as .com.co, which reduce the usefulness of those domains for typo-squatters.

    5. Re:Mistype by Potor · · Score: 2, Informative

      I can't remember the last time I typed "com".

      Seriously - with ctrl+enter, who needs to?

    6. Re:Mistype by Anonymous Coward · · Score: 1, Funny

      I just went there, and BUY CHEAP VIAGRA yes, it is WILL MAKE YOU 9 INCHES LARGER full of viruses. SO BIG YOU COULD PUT IT ON A BUN AND EAT IT!

    7. Re:Mistype by grcumb · · Score: 4, Informative

      While I can believe that .cm is a mistype for .com, what about .co, .con, .om? They don't seem to be high risk websites. I also bet that .con is a more common mistype than .cm

      It hardly matters. What many of the press reports (including El Reg) seem to ignore is the second most risky TLD in the world: .com.

      I'll bet you dollars to donuts that, because of the size and popularity of the TLD, .com is significantly more of a threat to the average Internet user than .cm.

      And while we're at it, how about a link to the actual report? (warning: PDF)

      --
      Crumb's Corollary: Never bring a knife to a bun fight.
    8. Re:Mistype by Anonymous Coward · · Score: 3, Funny

      .CONNNNNNNNNNNNNNN!!!!!!!

    9. Re:Mistype by icannotthinkofaname · · Score: 1

      It's a bit of a stretch for me to believe that .cm is a typo of .com. When I mistype .com, it's usually .co or .cmo. But I never just forget the o like that.

      --
      Let q be a radix > 1. I am in ur base-q, killing 10 d00ds.
    10. Re:Mistype by Antiocheian · · Score: 1

      'But wheah's the necessity? It seems an uncommonly woundabout and hopelessly wigmawolish method of getting anywheahs. Look heah now, I've got the wuhks of the mastahs -- the gweat ahchaeologists of the past. I wigh them against each othah -- balance of the disagweements -- analyze the conflicting statements -- decide which is pwobably cowwect- and come to a conclusion. That is the scientific method. At least' -- patronizingly -- 'as I see it. How insuffewably cwude it would be to go to Ahctuwus, oah to Sol, foah instance, and blundah about, when the old mastahs have covahed the gwound so much moah effectually than we could possibly hope to.'

      -- Isaac Asimov, Foundation

    11. Re:Mistype by jez9999 · · Score: 1

      .co is Colombia, .om is Oman, but .con doesn't exist.

      That's a shame, coz then we could have all the malware and phishing websites under one roof like porn is with .xxx. :-(

    12. Re:Mistype by Fred_A · · Score: 1

      Yes, I meant TLD's not webistes. (sic) I wasn't aware that .con wasn't a valid TLD . And .og was meant to be a joke.

      Which makes your comment worthwhile how, exactly ? Please refrain if you have no idea what you're talking about or take a minute to use your search engine of choice to see what the hell it is that people are talking about. As a rule geographic TLDs match the two letter country codes (as defined by ISO, see ISO-3166-1, relevant table is "alpha 2") most of the time.
      See the handy table at http://en.wikipedia.org/wiki/ISO_3166-1#Officially_assigned_code_elements or http://www.iana.org/domains/root/db/ for the real (internet-related) thing.

      I'm not an internet expert, [...]

      You don't say...
      But that's not a handicap. We all start that way, and then we learn (if we are so inclined).

      --

      May contain traces of nut.
      Made from the freshest electrons.
    13. Re:Mistype by Fred_A · · Score: 1

      I typed "Ctrl+Enter" and nothing happened.

      I want my money back !

      --

      May contain traces of nut.
      Made from the freshest electrons.
    14. Re:Mistype by tehcyder · · Score: 2, Funny

      You should be grateful you're not here where we have .co.uk addresses. You wouldn't believe the number of times I've typed in .cock and got something unexpected popping up on my monitor...

      --
      To have a right to do a thing is not at all the same as to be right in doing it
    15. Re:Mistype by halcyon1234 · · Score: 1

      ...second most risky TLD in the world: .com.

      Are you sure? Can you provide a link?

      And while we're at it, how about a link to the actual report? [mcafee.com] (warning: PDF)

      Mcafee and a PDF. Two pieces of malware from one .com site. Excellent evidence, sir.

    16. Re:Mistype by petermgreen · · Score: 1

      what about .co, .om?
      assigned to colombia and oman respectively but don't allow registrations directly under the tld so not useful for cybersquatters. .con
      doesn't exist.

      I also wonder whether slashdot.og is infested with viruses. .og doesn't exist either

      --
      note: i'm known as plugwash most places but i screwd up registering that here somehow in the past and now can't register
    17. Re:Mistype by Anonymous Coward · · Score: 1, Informative

      Sounds you got one of those keyboards left by the W Bush admin for the next president.

    18. Re:Mistype by Spazztastic · · Score: 1

      I wasn't aware that .con wasn't a valid TLD (It should be valid for the scammers).

      Really? We should dedicate a whole TLD just for scammers? Was that supposed to be a joke?

      And .og was meant to be a joke.

      Ok, I guess you did mean it as a joke if you thought that one would fly too. It went over like a lead balloon, though.

      Here's a tip from an internet professional: Do research before you make posts on a site that you can't delete or edit your comments on. If you make a mistake, reply to yourself and correct it. Otherwise people who have karma to burn will correct you, much like myself.

      --
      Posts not to be taken literally. Almost everything is sarcasm.
  2. Missing keys? by TheProphet92 · · Score: 2, Interesting

    I rarely miss the 'o' key altogether, more commonly I press a different one accidentally, like 'cpm' or 'con'.

    1. Re:Missing keys? by Anonymous Coward · · Score: 2, Funny

      shtrrf/ o jsyr ejrm o fp yjsy/

    2. Re:Missing keys? by Spad · · Score: 1

      My usual typo is .copm

  3. POLL: have you ever mistyped .cm for .com? by theNAM666 · · Score: 2, Interesting

    Really? I've never done it. Never. /me goes to point .cm to 127.0.0.1 .

  4. Wouldn't it be safer to... by Antony-Kyre · · Score: 3, Insightful

    to just block the whole Net? That way, you can't visit any website, thus avoid all websites hosting malware. Either that or have a patched, updated browser, and use smart surfing habits.

    1. Re:Wouldn't it be safer to... by mysidia · · Score: 5, Insightful

      Blocking .cm can be a helpful step, because it blocks a portion of the hostnames that (A) if you visit has a very high probability of infecting you, and (B) that an intentional visit to is unlikely.

      So you can block .cm with a notable increase in safety, with a minimal decrease in usefulnes of your internet access.

      The same could not be said of blocking the whole net. Blocking the whole net reduces the utility of your network connection, since it means you can no longer navigate to the sites that you do want to, with high probability.

    2. Re:Wouldn't it be safer to... by srussia · · Score: 2, Funny

      Blocking .cm can be a helpful step

      I live in Cameroon, you insensitive clod! But then again, malware is not at the top of my worry list... carry on then.

      --
      Set your phasers on "funky"!
    3. Re:Wouldn't it be safer to... by water-and-sewer · · Score: 1

      Seriously, do away with it and go back to gopherspace. No viruses there, probably. The WWW is overrated.

      --
      If this were Usenet, I'd killfile the lot of you.
  5. .com default by feedayeen · · Score: 3, Informative

    Most modern browsers insert .com automatically if no top level domain exist in the URL.

  6. I am Naga Eboko, exchange student from Cameroon. by fucket · · Score: 4, Funny

    Beef jerky time.

  7. No, I don't think it is by 93+Escort+Wagon · · Score: 3, Interesting

    Given that it's very easy to mis-type .com as .cm, ...

    I can safely say I've never done this. I've made other errors - such as ending up in Estonia's (.ee) web space on occasion, since I work in an electrical engineering department. But I can't believe leaving out the "o" from ".com" is particularly easy or at all common.

    Now if you wanted to talk about Colombia (.co) being a frequent typo for .com domains, then I might find it more believable. I have done that on rare occasions.

    --
    #DeleteChrome
    1. Re:No, I don't think it is by trawg · · Score: 1

      I can safely say I've never done this. I've made other errors - such as ending up in Estonia's (.ee) web space on occasion, since I work in an electrical engineering department. But I can't believe leaving out the "o" from ".com" is particularly easy or at all common.

      I can't figure out how you think ending up at a domain ending in .ee because you're an electrical engineer is less weird than mistyping .com

    2. Re:No, I don't think it is by imakemusic · · Score: 1

      So missing the m key, or not pressing it hard enough is logical but missing out the o is just crazy talk?

      I guess that makes sense...if you have a particularly weak index finger.

      --
      Brain surgery - it's not rocket science!
    3. Re:No, I don't think it is by BetterSense · · Score: 1

      I always seem to type c.om, but maybe it's because I type dvorak. My mistakes are different.

  8. Yes, but... by InspectorxGadget · · Score: 4, Funny

    ...they make those delightful coconut cookies. I think we can forgive them.

    1. Re:Yes, but... by Opportunist · · Score: 5, Funny

      Hate to break it to you, but those ain't coconut cookies that they sent to your browser...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  9. Auto-Correcting Domains by cshbell · · Score: 1

    It's water under the bridge, but in hindsight, it would have been better to not create the alternate TLDs .cm, .co. While I'm at it, tell me there's a good reason we have augmented reality iPhones and 60 MPG cars but not web browsers that autocorrect non-existent TLDs.

    Seriously, why doesn't every browser have a "I don't live in Cameroon or Colombia; auto-correct .cm and .co to .com, don't warn me when doing it, and don't bother me about this again" option? (I know, I know, .hosts and/or Firefox extensions. Still.)

    1. Re:Auto-Correcting Domains by MichaelSmith · · Score: 4, Funny

      I knew a guy called Teh but unfortunately Microsoft tools auto correct that to The.

    2. Re:Auto-Correcting Domains by syousef · · Score: 1

      I knew a guy called Teh but unfortunately Microsoft tools auto correct that to The.

      Clearly he should change his name. I'd like to suggest Meh.

      --
      These posts express my own personal views, not those of my employer
    3. Re:Auto-Correcting Domains by Tynin · · Score: 3, Insightful

      Maybe because it is a world wide web, and some people who live in the US may not have as limited of interests as you?

  10. stuck key by wizardforce · · Score: 2, Insightful

    typing *.cm instead of .com is as simple as having an o key that gets stuck occasionally and not noticing the typo. All it takes is a keyboard that needs a good cleaning and a user that isn't paying enough attention.

    --
    Sigs are too short to say anything truly profound so read the above post instead.
    1. Re:stuck key by daveime · · Score: 1

      typing *.cm instead of .cm is as simple as having an key that gets stuck ccasinally and nt nticing the typ. All it takes is a keybard that needs a good cleaning and a user that isn't paying enough attentin.

      FTFY ;-)

  11. OpenDNS has an option to fix this by robbak · · Score: 3, Informative

    Opendns has an option to automatically 'correct' .cm requests to .com, which I always turn on. If Cameroon does not want people doing this, then it would have to police it's domain closely, instead of using it as a cash cow.

    --
    Prediction for end of Universe #42: Fencepost error in Quantum_bogosort.cpp
    1. Re:OpenDNS has an option to fix this by Anonymous Coward · · Score: 1, Informative

      OpenDNS also rewrites NXDOMAINS to host advertisements.

      Why do people keep spamming this service like it doesn't suck?

    2. Re:OpenDNS has an option to fix this by QuoteMstr · · Score: 1

      OpenDNS really is an abomination unto the Domain Naming System as bad as any ISP's NXDOMAIN redirection.

      But IOKIYFTM --- It's Okay If You're Fighting The Man

      (Or have a PR department that creates that impression.)

    3. Re:OpenDNS has an option to fix this by shentino · · Score: 1

      Because it's opt-in and doesn't hijack your DNS unless you tell it to?

      I don't use it myself though sicne I run bind and do my own DNS caching.

    4. Re:OpenDNS has an option to fix this by KazW · · Score: 1

      OpenDNS breaks the DNS standard, as it returns a search page for non-existent domains, there was actually a /. article about sites doing this not too long ago. Lastly, not to mention, you're letting a 3rd party track almost 100% of your net activity.

      In closing, "smart" DNS is a dumb decision, even for dumb people.

      --
      Geeks don't grock information, they grep it.
    5. Re:OpenDNS has an option to fix this by dissy · · Score: 1

      OpenDNS breaks the DNS standard, as it returns a search page for non-existent domains, there was actually a /. article about sites doing this not too long ago.

      That is an option that can be turned on and off to your own desire.
      Just uncheck the checkbox on your preferences page and it will not rewrite nxdomain.

      FYI, most people like that feature. For the rest, who either don't like it, or do like it but for technical reasons can not have it, you can just not enable it.

      Lastly, not to mention, you're letting a 3rd party track almost 100% of your net activity.

      You say that like it is only true when using opendns and not true all other times.

      All you are doing is changing 3rd party from your ISP into opendns, so in those cases that option is always there.
      And no, it does not matter if you run your own DNS server, since it needs to get records from some upstream service too...

      I can understand not trusting your ISP (some ISPs simply have proven themselves untrustworthy), but I don't see why you would trust ICANN that much more than OpenDNS. ICANN has done some really rotten things too (Including rewritting NXDOMAIN but without any option to disable it!)

    6. Re:OpenDNS has an option to fix this by gad_zuki! · · Score: 1

      On top of it there's nothing open about them. No source, no open development, community, etc. Its just a company that tracks people and breaks NXDOMAIN. Man, is running bind on something so hard? There's even a pretty nice dumbed down GUI windows port called Treewalk.

    7. Re:OpenDNS has an option to fix this by forerunner403 · · Score: 1

      Yeah, this option is definitely a life saver.

    8. Re:OpenDNS has an option to fix this by RocketRabbit · · Score: 1

      You and the four other people using OpenDNS must really be sitting pretty.

  12. Cameroon is in Africa! by mi · · Score: 1, Informative

    I hereby denounce this article — and the pseudo-statistics in it — as racist!

    Gebyy zl nff!..

    --
    In Soviet Washington the swamp drains you.
  13. Re:POLL: have you ever mistyped .cm for .com? by Opportunist · · Score: 1

    I prolly shouldn't do that, this machine I'd point to is full of current malware.

    (if I'm on my analysis machine, that is...)

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  14. Is omitting a letter really a problem? by Opportunist · · Score: 1

    If so, change keyboards.

    I see the real threat in letters getting mixed up (which probably does not matter so much in 3 letter TLDs, since I don't know of a cmo or ogr TLD) or a typo (.con, .prg), which also usually don't really result in anything damaging. .cm being mistyped as .cn might be a problem, though. But then again, it's like missing the flood to reach the drought, so...

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  15. In any case... by BrokenHalo · · Score: 3, Insightful

    In any case, if (as the article claims) one third of Cameroon domains host malware, the implication is that two thirds don't. I would be very curious to know what percentage of US domains host malware.

    Regardless of the answer, the appropriate response is to use a robust browser and block individual sites, not block out whole nations. Otherwise one might just as well move to China.

  16. To that I'll add by Sycraft-fu · · Score: 3, Informative

    That different nations treat their TLDs differently. Some sell them to anyone who wants one. You can register them as long as you are willing to pay whatever fee it is they ask. The .tv domain is one such domain. Others make the domains available, but only to people or organizations that meet certain requirements like citizenship. Canada (.ca) would be one like that. Any Canadian can have a .ca domain if they are willing to pay for it, but non-Canadians can't buy one. Still others only use their domain for government or internal functions. The .us domain was like that at one time. You could get it only as an entity like a county government or a high school or something (it is now open for registration). Finally some countries simply don't do anything with their TLD, it just isn't used at all and there's no way to get it.

    So just because a TLD exists, doesn't mean it can be used for any given purposes.

    1. Re:To that I'll add by dissy · · Score: 1

      Reminds me of the time I tried to get an Antarctica domain (.aq), and the first email I got back stated "Sorry, to register you must live on the ice"

      As for the history of the .us cctld, even back in the late 80s, one could register a subdomain out of it being an individual (and it was free too! Then again, so was .com)

      However they did have and enforce a strict organizational structure.
      From what I recall, you had to get [something].county.state.us
      Later they opened it up more, but was still state/group sectioned at the second level, IE blah.k12.us for a school. These days for the right price anyone can get a blah.us

      I also had a Canadian .ca domain, but the admin contact was my mailing address in Canada instead of my US one. So I think resident was the only requirement, not citizen.
      That or they just had poor checking of citizenship back then ;}

  17. The world is infected! Buy our stuff! by tjstork · · Score: 1

    Let's get real and understand that the real purpose of providing this "information" is marketing. It is there to reinforce the message that the world is hopelessly infected with computer viruses and you absolutely MUST have the offerings of McAffee and other anti-virus software vendors. I'm not even sure why anyone would believe it is true.

    --
    This is my sig.
    1. Re:The world is infected! Buy our stuff! by dskzero · · Score: 1

      So you are arguing that it's better to avoid antivirus completely?

      --
      Oblivion Awaits
    2. Re:The world is infected! Buy our stuff! by aBaldrich · · Score: 1

      So you are arguing that it's better to avoid antivirus completely?

      There is hope beyond McAffee. Repent and convert to Linux.

      --
      In soviet russia the government regulates the companies.
    3. Re:The world is infected! Buy our stuff! by dskzero · · Score: 1

      I don't need to convert to anything. I'd rather use NOD32 and continue my windows ways that haven't failed me. Sorry. :)

      --
      Oblivion Awaits
  18. Always one rotten apple by hesaigo999ca · · Score: 1

    There will always be a worst and best in this category, as in anything you do in life. The problem is when it is deliberately set to that which happens to be .cm (which could be a mistype for many people)...if you think of whether this was intentional on the hackers part, you better believe it.

    It could be any of the countries that have domains, and have no real talent for programming websites, but in the end,
    you have to wonder, most are hosted on regular ISPs that offer the .cm extension, so should they not be partially responsible too, for at least quick testing the sites vulnerability with a tool or something....and if they find anything, the website owners are responsible to fix it, or get their vulnerable or compromised websites taken down.

    That's just my 2 cents though

  19. Re:I am Naga Eboko, exchange student from Cameroon by NevarMore · · Score: 1

    HAPPY CHRISTMAS!

  20. Re:POLL: have you ever mistyped .cm for .com? by Nimey · · Score: 1

    Once just recently - I was holding my infant daughter so had to type one-handed.

    OpenDNS caught the error and warned me away from a malware site. Don't remember where I was going at the time.

    --
    Hail Eris, full of mischief...

    E pluribus sanguinem
  21. Is there an easy way......? by jameskojiro · · Score: 1

    To block any top level domain? I mean like an entry in the hosts file, etc.....

    --
    Tsukasa: All I really want, is to be left alone...
    1. Re:Is there an easy way......? by gad_zuki! · · Score: 1

      Nope, a host file is static and wont support and wildcards like *.cm.

      You can run bind and play with the configuration or you can set your firewall to not let you make connections to cameroon's netblocks. That's assuming the cm stuff is actually hosted there. If not then you need to block via DNS.

      # Country: CAMEROON
      # ISO Code: CM
      # Total Networks: 16
      # Total Subnets: 100,864
      41.92.128.0/17
      41.190.224.0/22
      41.191.100.0/22
      41.202.192.0/19
      41.204.64.0/19
      41.205.0.0/19
      41.205.64.0/19
      41.211.96.0/19
      41.216.176.0/20
      41.217.128.0/19
      41.223.28.0/22
      193.17.215.0/24
      195.24.192.0/19
      195.234.120.0/22
      196.3.90.0/24
      196.202.232.0/21

      http://www.countryipblocks.net/country-blocks/select-formats/

  22. Wow, another reference to Cameroon! by motherpusbucket · · Score: 1

    I have not heard that country mentioned since Eddie Murphy disguised himself as an exchange student from Cameroon in 'Trading Places' back in the 80's.

    --
    "You can't really dust for vomit" --Nigel Tufnel