Typosquatter danger?

Hi-

I’m running WINXP PRO SP2.

I visited wXw.cocmast.net by typo. In the 10 seconds the page was open in Firefox, all my tabs closed and Firefox displayed the Oops we lost your tabs screen.

Concerned, I checked for files that had been modified within that minute on my hard drives with XP search, and NTuser.dat and its associated text file had both been modified.

Thoroughly weirded out by this, I immediately did a system restore to be on the safe side. What gives, did something happen? If so, did system restore do me any good?

Avast was silent throughout, btw.

Thanks

Please ‘modify’ your post change the URL from http to hXXp or www to wXw, to break the link and avoid accidental exposure to suspect sites, thanks.

Update:

OK I was able to visit the site using firefox, with NoScript and RequestPolicy add-ons; I got no alerts by avast, or firefox safe browsing or WOT; I also didn’t suffer none of my tabs closed.

A brief look at the home page didn’t see anything suspect.

Given the name, I see what site a typo might end up gaining traffic to it, comcast.com might easily become cocmast in a typo but I doubt you would be confused that is was comcast.com and that would be more suspect.

It’s seen clean by Dr. Web… but can we trust it?

Hi DavidR,

Check this link there for malcoded script which is difficult for the reason given below *:

link - hxtp://s16.sitemeter.com/js/counter.js?site=s16a1bible which is a 403. Forbidden.Directory Listing Denied * This Virtual Directory does not allow contents to be listed. (Level: 1) Url checked: (script source) hxtp://s16.sitemeter.com/js/counter.js?site=s16a1bible Zeroiframes detected on this site: 0 No ad codes identified polonus

Welcome to the forums, griffac. :slight_smile:

You should be using SP3 that has been available for more than a year. It provides better security to XP.


I was trying to type comcast.net, to access webmail

thanks for looking into this.

hope it was just a coincidence.

thanks for the welcome. re sp3, i installed it back then but suffered some problems with programs. as a result, i rolled it back. i might try again, seeing it’s been so long. thanks for the reminder.