CAPEC 631 SoundSquatting

Draft Detailed Low Risk
Severity Medium

Description

An adversary registers a domain name that sounds the same as a trusted domain, but has a different spelling. A SoundSquatting attack takes advantage of a user's confusion of the two words to direct Internet traffic to adversary-controlled destinations. SoundSquatting does not require an attack against the trusted domain or complicated reverse engineering.

Attack Execution Flow

3

Mitigations

2

Consequences

Relationships