frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Most parked domains now serving malicious content

https://krebsonsecurity.com/2025/12/most-parked-domains-now-serving-malicious-content/
65•bookofjoe•2h ago

Comments

excalibur•2h ago
The bit about the gmai.com mailserver is disturbing. One would imagine there are many other typo squatters with a similar setup.
imglorp•1h ago
I just checked. At least it's not answering on 25 to receive all that free typo mail. Same for gmali.com. But they could spoof the gmail login page. Not finding out.

    PORT     STATE SERVICE
    80/tcp   open  http
    443/tcp  open  https
    8080/tcp open  http-proxy
Bender•1h ago
I park mine by having no IP address, MX record is "0 ." meaning it does not receive email, the SPF record is "v=spf1 -all" and DMARC is a strict reject, CAA is 0 issue ";", BIMI is "v=BIMI1; l=; a=;". I do the same for wildcard DNS. There's probably more I should add.
ericpauley•1h ago
Indeed, this is a common practice in the broader data. It seems the linked article is filtering to resolvable+hosted domains, a subset of overall domain parking.
Bender•1h ago
Yup. That's why I am suggesting to stop that practice and just remove the IP rather than trusting the landing page someone else maintains. Or if one would like to give bots something to do point it to a multicast address or perhaps MoD/US Military address.
ericpauley•1h ago
We did a large-scale study of this phenomenon recently: https://www.cs.bu.edu/faculty/crovella/paper-archive/wung-if...

Across a broad sample of typo domains of major sites, most registered domains aren’t actually reachable, implying they are registered for defensive, legitimate, or unrelated purposes. Interestingly, the typo space on major sites is actually very sparsely registered (2% at edit distance 1), meaning that typosquatting may actually be underexploited.

moralestapia•1h ago
This just happened to me a month ago, I was waiting for a unused domain to expire. The domain was hosted on Epik (which I think is a trashy company but w/e).

About a month before expiration it somehow got renewed for 10 years, which is weird because it was not available ... and is now hosting a "get-rich-quick" scam that pretends to be a genuine Petro Canada campaign.

homebrewer•1h ago
> About a month before expiration it somehow got renewed for 10 years, which is weird because it was not available

I've seen some domain registrars auctioning off domains during the last 2-4 weeks before they expire. If nobody buys it, then it actually expires and is then released.

HWR_14•1h ago
Which registrars? I would want to avoid those.
reactordev•50m ago
At the end of the day, no matter your domain, ICANN can just take it for their VC bros. Happened to a friend of mine that owned a pretty novel domain name that a certain social media company wanted. He refused to sell. ICANN and his registrar just transferred it out from under him. Gone. See ya.
Tade0•34m ago
Wow. In light of this it's amazing that Mr. Nissan (RIP) and later his heirs managed to not only retain control of nissan.com, but regain it after it was stolen years after his passing.
ctxc•2m ago
Out of curiosity, what was the domain?
dvh•1h ago
Yesterday I received spam with link on https://storage.googleapis.com/ that redirected to some parked domain.
rickcarlino•1h ago
Hopefully “direct navigation” does not become a boogeyman like “side loading” has.
wlesieutre•1h ago
Especially when the alternative is "type the company name into google" where the top 3 results are ads and they've previously been seen to stick malware distribution sites above the legitimate company pages

This was happening for months with blender in 2022/2023, previously collected links about it here: https://news.ycombinator.com/item?id=34917701

belorn•24m ago
Their definition of parked domain is a bit odd, with "expired" domain names and typosquatting” domains. I work at a registrar and the absolutely vast majority of parked domains for us are domains owned by customers that register alternative versions, campaign, products and misspellings of their primary domain. Parked in that sense mean an almost empty zone with occasionally a default landing page, sometimes as a paid DNS service at the registrar, and sometimes as a free service (There are still registration and renewal fees).

Putting a redirect onto such domain would be a major bad faith act by the registrar and a reason to avoid that registrar at all costs. The customer is the owner of that name, has their name attached as the registrant, and generally hold some legal risk while doing so. It also goes directly against the primary reason why the customers bought the domains in the first place.

The ones that hold advertisement are generally two specific cases. One is "expired" domains which are not actually expired but where the registrar holds on to it in the hope that the old or new customer will buy it for an extra cost. The other is names which a customer or the registrar itself bought as an investment in hope to auction out. That kind of behavior was historically frowned at but is fairly common practice for a smaller number of domains. Usually you don't put redirects on those since you want to expose the fact that the domain is for sale.

So I am very confused where they got their 90% number from, but then I would not call typosquatting as parked domains if its registered by a malicious actor and used for a scam on their own servers (or hacked servers as it may be).

RankingMember•20m ago
We've unfortunately come a long (bad) way from the innocuous "backpack girl" parking pages.

For a refresher: https://i.kym-cdn.com/entries/icons/original/000/033/037/gir...

Classical statues were not painted horribly

https://worksinprogress.co/issue/were-classical-statues-painted-horribly/
191•bensouthwood•2h ago•93 comments

Please Just Try Htmx

http://pleasejusttryhtmx.com/
52•iNic•1h ago•28 comments

Virtualizing Nvidia HGX B200 GPUs with Open Source

https://www.ubicloud.com/blog/virtualizing-nvidia-hgx-b200-gpus-with-open-source
41•ben_s•1h ago•5 comments

Using TypeScript to Obtain One of the Rarest License Plates

https://www.jack.bio/blog/licenseplate
17•lafond•27m ago•2 comments

Are Apple gift cards safe to redeem?

https://daringfireball.net/linked/2025/12/17/are-apple-gift-cards-safe-to-redeem
83•tosh•1h ago•34 comments

Spain fines Airbnb €65M: Why the government is cracking down on illegal rentals

https://www.euronews.com/travel/2025/12/15/spain-fines-airbnb-65-million-why-the-government-is-cr...
37•robtherobber•38m ago•3 comments

Jonathan Blow has spent the past decade designing 1,400 puzzles for you

https://arstechnica.com/gaming/2025/12/jonathan-blow-has-spent-the-past-decade-designing-1400-puz...
145•furcyd•6d ago•173 comments

Slowness is a virtue

https://blog.jakobschwichtenberg.com/p/slowness-is-a-virtue
151•jakobgreenfeld•4h ago•55 comments

RCE via ND6 Router Advertisements in FreeBSD

https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc
89•weeha•7h ago•44 comments

Creating apps like Signal could be 'hostile activity' claims UK watchdog

https://www.techradar.com/vpn/vpn-privacy-security/creating-apps-like-signal-or-whatsapp-could-be...
213•donohoe•4h ago•159 comments

Show HN: A local-first memory store for LLM agents (SQLite)

https://github.com/CaviraOSS/OpenMemory
16•nullure•4d ago•3 comments

Egyptian Hieroglyphs: Lesson 1

https://www.egyptianhieroglyphs.net/egyptian-hieroglyphs/lesson-1/
119•jameslk•9h ago•43 comments

Hightouch (YC S19) Is Hiring

https://hightouch.com/careers
1•joshwget•3h ago

Gemini 3 Flash: Frontier intelligence built for speed

https://blog.google/products/gemini/gemini-3-flash/
1052•meetpateltech•22h ago•554 comments

Your job is to deliver code you have proven to work

https://simonwillison.net/2025/Dec/18/code-proven-to-work/
50•simonw•36m ago•53 comments

After ruining a treasured water resource, Iran is drying up

https://e360.yale.edu/features/iran-water-drought-dams-qanats
223•YaleE360•5h ago•166 comments

I got hacked: My Hetzner server started mining Monero

https://blog.jakesaunders.dev/my-server-started-mining-monero-this-morning/
509•jakelsaunders94•18h ago•318 comments

It's all about momentum

https://combo.cc/posts/its-all-about-momentum-innit/
81•sph•5h ago•26 comments

Show HN: X Writer – VS Code extension to post tweets from your editor

https://github.com/Jawuilp/X-writer
10•jawuilp•19h ago•5 comments

What is an elliptic curve? (2019)

https://www.johndcook.com/blog/2019/02/21/what-is-an-elliptic-curve/
108•tzury•8h ago•12 comments

Online Textbook for Braid groups and knots and tangles

https://matthematics.com/redoak/redoak.html
34•marysminefnuf•5h ago•2 comments

From profiling to kernel patch: the journey to an eBPF performance fix

https://rovarma.com/articles/from-profiling-to-kernel-patch-the-journey-to-an-ebpf-performance-fix/
17•todsacerdoti•4d ago•1 comments

Most parked domains now serving malicious content

https://krebsonsecurity.com/2025/12/most-parked-domains-now-serving-malicious-content/
65•bookofjoe•2h ago•17 comments

AI helps ship faster but it produces 1.7× more bugs

https://www.coderabbit.ai/blog/state-of-ai-vs-human-code-generation-report
50•birdculture•2h ago•54 comments

Working quickly is more important than it seems (2015)

https://jsomers.net/blog/speed-matters
220•bschne•3d ago•108 comments

Building a High-Performance OpenAPI Parser in Go

https://www.speakeasy.com/blog/building-speakeasy-openapi-go-library
32•subomi•3d ago•9 comments

The Big City; Save the Flophouses (1996)

https://www.nytimes.com/1996/01/14/magazine/the-big-city-save-the-flophouses.html
18•ChadNauseam•3d ago•4 comments

Breaking Paragraphs into Lines [pdf] (1981)

https://gwern.net/doc/design/typography/tex/1981-knuth.pdf
29•Smaug123•6d ago•6 comments

Fluent: A Localization System for Natural-Sounding Translations

https://projectfluent.org/
14•stefankuehnel•4d ago•3 comments

GitHub postponing the announced billing change for self-hosted GitHub Actions

https://twitter.com/jaredpalmer/status/2001373329811181846
111•coloneltcb•19h ago•109 comments