<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Brand Protection Blog – Domains, Anti Counterfeiting, Fraud Prevention and Security Conversations &#124; MarkMonitor</title>
	<atom:link href="http://www.markmonitor.com/mmblog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.markmonitor.com/mmblog</link>
	<description>Expert views to keep your brand ahead of threats online</description>
	<lastBuildDate>Fri, 12 Mar 2010 18:50:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>EI, EI – NO!</title>
		<link>http://www.markmonitor.com/mmblog/ei-ei-%e2%80%93-no/</link>
		<comments>http://www.markmonitor.com/mmblog/ei-ei-%e2%80%93-no/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 18:50:24 +0000</pubDate>
		<dc:creator>Elisa Cooper</dc:creator>
				<category><![CDATA[Domains]]></category>
		<category><![CDATA[ICANN]]></category>
		<category><![CDATA[gTLDs]]></category>
		<category><![CDATA[icann]]></category>
		<category><![CDATA[New gTLDs]]></category>
		<category><![CDATA[top level domains]]></category>

		<guid isPermaLink="false">http://www.markmonitor.com/mmblog/?p=225</guid>
		<description><![CDATA[For those closely following the ICANN Meeting in Nairobi this week, the EOI (Expression of Interest) model seemed like a foregone conclusion. In fact, ICANN had scheduled a webinar on March 18th to explain the process despite the complaints of the community and large-scale disagreement amongst proponents of the EOI. 
As proposed by ICANN staff, the [...]]]></description>
			<content:encoded><![CDATA[<p><span>For those closely following the ICANN Meeting in Nairobi this week, the <a href="http://www.icann.org/en/topics/new-gtlds/eoi-model-18dec09-en.pdf">EOI (Expression of Interest) model </a>seemed like a foregone conclusion. In fact, ICANN had scheduled a webinar on March 18th to explain the process despite the complaints of the community and large-scale disagreement amongst proponents of the EOI.</span><span> </span></p>
<p><span>As proposed by ICANN staff, the EOI model would have required that all entities wishing to apply for a new gTLD during the first round to submit basic information including the requested string and a fee of $55,000.</span></p>
<p><span>However, much to the collective surprise of the ICANN community, the ICANN Board voted against the proposal, citing many of the reasons noted in the <a href="http://forum.icann.org/lists/eoi-new-gtlds/msg00062.html" target="_blank">comments submitted by MarkMonitor</a>. </span></p>
<p><span>Members of the ICANN Board stated that confusion regarding the purpose of the model existed, and that moving forward with such a model would have added another two to three months to the process. Furthermore, that resources were being taken away from solving the “<a href="https://st.icann.org/new-gtld-overarching-issues/index.cgi?new_gtld_overarching_issues">underlying problems</a>” was also cited as a reason to vote against the model.</span></p>
<p><span>While the EOI was expected to provide exact information about the number of applicants expected in the first round, one of the Board Members stated that having this “extraordinary precision” was not necessary due to the fact that the “Internet is a &#8212; as a system, exhibits enormous dynamic ranges in load in every aspect.”</span></p>
<p><span>Interestingly enough, another Board Members stated that at the beginning of the week that he had planned to vote in favor of the EOI, but by the end of the week it had become apparent that a mandatory EOI did not have the consensus of the community.</span></p>
<p><span>With this result, brand rights owners and others will be able to keep their plans confidential until they are ready to apply and prepare for the application or objection process, without additional worries or early investment in the gTLD process. </span></p>
<p><span><span>So, it is without any sorrow or regret, I say RIP EOI.</span></span><span> </span><span> </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.markmonitor.com/mmblog/ei-ei-%e2%80%93-no/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>It Is There for a Reason, So Why Not Use It?</title>
		<link>http://www.markmonitor.com/mmblog/it-is-there-for-a-reason-so-why-not-use-it/</link>
		<comments>http://www.markmonitor.com/mmblog/it-is-there-for-a-reason-so-why-not-use-it/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 18:35:25 +0000</pubDate>
		<dc:creator>Elisa Cooper</dc:creator>
				<category><![CDATA[Brand Abuse]]></category>
		<category><![CDATA[Domains]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[registries]]></category>

		<guid isPermaLink="false">http://www.markmonitor.com/mmblog/?p=218</guid>
		<description><![CDATA[It seems like every week, news of yet another high-profile domain hijacking occurs. Whether it’s stolen credentials, SQL injection attacks, or even the work of disgruntled employees, the number of incidents has been on the rise. 
At the beginning of last year, MarkMonitor participated in VeriSign’s beta program to test server-level protections which were designed to [...]]]></description>
			<content:encoded><![CDATA[<p>It seems like every week, news of yet another <a title="blocked::http://techcrunch.com/2010/02/07/indian-it-giant-tata-consultancy-services-hacked/" href="http://techcrunch.com/2010/02/07/indian-it-giant-tata-consultancy-services-hacked/">high-profile domain hijacking</a> occurs. Whether it’s stolen credentials, SQL injection attacks, or even the work of disgruntled employees, the number of incidents has been on the rise. </p>
<p>At the beginning of last year, MarkMonitor participated in VeriSign’s beta program to test server-level protections which were designed to mitigate the potential for unintended domain name changes, deletions and transfers. When VeriSign finally released their <a title="blocked::http://www.verisign.com/domain-name-services/current-registrars/registry-lock/index.html" href="http://www.verisign.com/domain-name-services/current-registrars/registry-lock/index.html">Registry Locking Program</a> to all registrars, I expected to see the owners of highly trafficked sites flocking to this new offering. </p>
<p>However, after a review of the top 300 most highly trafficked sites, I was shocked to uncover that less than 10% of these valuable domains were protected using these newly available security measures. </p>
<p>So why aren’t more companies protecting themselves? </p>
<p>Given the value of these highly trafficked domains, I cannot imagine that the additional fees associated with employing this level of service are the deterrent. </p>
<p>I can only imagine that either the offering hasn’t been made widely available, or that confusion as to whether a domain is locked it to blame.</p>
<p>When it comes to domain locking, there is often quite a bit of confusion as to how to determine whether a domain is 1) “locked” within a portal, or 2) “locked” at the Registrar, or 3) “locked” at the Registry. </p>
<p>Only domains that have the following statuses are considered to be “locked” at the Registry, and cannot be modified using standard protocols. </p>
<ul>
<li>client delete prohibited</li>
<li>client transfer prohibited</li>
<li>client update prohibited</li>
<li>server delete prohibited</li>
<li>server transfer prohibited</li>
<li>server update prohibited </li>
</ul>
<p>For the owners of highly trafficked domains, I would strongly recommend adding this level of security to protect valuable domains. It is there for a reason, so why not use it?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.markmonitor.com/mmblog/it-is-there-for-a-reason-so-why-not-use-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smart Phishing for Smartphones</title>
		<link>http://www.markmonitor.com/mmblog/smart-phishing-for-smartphones/</link>
		<comments>http://www.markmonitor.com/mmblog/smart-phishing-for-smartphones/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 01:31:54 +0000</pubDate>
		<dc:creator>Fred Felman</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[smart phones]]></category>

		<guid isPermaLink="false">http://www.markmonitor.com/mmblog/?p=190</guid>
		<description><![CDATA[A common security prediction for 2010 is the continued rise of malware and phishing attacks on mobile phones. The MarkMonitor SOC recently detected an interesting twist on this theme involving a popular smartphone and the latest smart technologies used by cybercriminals. In this case, instead of compromising a smartphone to steal its information, cybercriminals used [...]]]></description>
			<content:encoded><![CDATA[<p>A common security prediction for 2010 is the continued rise of malware and phishing attacks on mobile phones. The MarkMonitor SOC recently detected an interesting twist on this theme involving a popular smartphone and the latest smart technologies used by cybercriminals. In this case, instead of compromising a smartphone to steal its information, cybercriminals used phishing techniques to clone smartphones.</p>
<p>Here&#8217;s how it works. Emails which offer a free one-year warranty extension for a popular smartphone, link to a company-branded web page. That web page asks for an email address and then smartphone serial number, IMEI number, type of phone, and capacity of phone. See below for examples of the phishing web page.</p>
<p style="text-align: center;"><img class="aligncenter" title="Smartphone Phish Web Page example" src="http://www.markmonitor.com/images/blog-articles/smartphone-screens.jpg" alt="" width="349" height="339" /></p>
<p>Cybercriminals use the information requested on the web page to clone the smartphone for various uses, including stealing long-distance service from the subscriber or simply using a deniable, disposable smartphone for other criminal activities. In effect, the cybercriminals used phishing techniques to clone smartphones.</p>
<p>This recent attack also stands out because it utilizes some advanced technologies and suggests possible directions of future cybercriminal activity. First, the attack uses server-side logic that hides the phishing site unless it is accessed through the browser produced by the smartphone company. Second, the attack uses additional protective technology in the form of a fast-flux network, which hides the phishing site behind a dynamic network of ever-changing proxies. These two smart technologies demonstrate how cybercriminals continue to focus their efforts on making their attacks targeted, stealthy, and resilient.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.markmonitor.com/mmblog/smart-phishing-for-smartphones/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Avalanche Fast-flux and Blended Attacks</title>
		<link>http://www.markmonitor.com/mmblog/avalanche-fast-flux-and-blended-attacks/</link>
		<comments>http://www.markmonitor.com/mmblog/avalanche-fast-flux-and-blended-attacks/#comments</comments>
		<pubDate>Wed, 23 Dec 2009 18:04:42 +0000</pubDate>
		<dc:creator>Fred Felman</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.markmonitor.com/mmblog/?p=181</guid>
		<description><![CDATA[Phishing attacks have become more sophisticated with the use of fast-flux botnets as resilient attack platforms. The fast-fluxing among hundreds of compromised computers which serve as proxies for phishing sites means that detection and shutdown become more difficult.
One particular fast-flux botnet called Avalanche has received much attention in recent months as a major platform for [...]]]></description>
			<content:encoded><![CDATA[<p>Phishing attacks have become more sophisticated with the use of fast-flux botnets as resilient attack platforms. The fast-fluxing among hundreds of compromised computers which serve as proxies for phishing sites means that detection and shutdown become more difficult.</p>
<p>One particular fast-flux botnet called Avalanche has received much attention in recent months as a major platform for hosting phishing sites. What has not been discussed as much is how the distinction between phishing and malware has ceased to exist.</p>
<p>Avalanche offers a prime example of how blended attacks are launched from a fast-flux botnet platform. Arbor Networks reported earlier this month that the cybercriminal gangs behind the Avalanche botnet and the Zeus/Zbot malware have entered a partnership whereby the Zeus malware gang is using the Avalanche fast-flux botnet to launch its attacks. &#8220;We appear to be seeing one of the groups, Avalanche, promoting Zeus malware,” observed botnet security researcher Jose Nazario. &#8220;They don’t compete, and they both have good market positions, so they can grow each other.&#8221;</p>
<p>Recent blended attacks hosted on Avalanche reported this month targeted a major credit card company and a large Spanish bank operating in Latin America. Cybercriminals have teamed up their best-of-breed fast-flux and malware capabilities. MarkMonitor AntiFraud anticipated these developments with its unique preventive capabilities for preemptively detecting and shutting down fast-flux-based phishing and malware attacks.</p>
<p>More details about recent blended attacks hosted on the Avalanche platform:</p>
<p>December 11: <a href="http://news.zdnet.co.uk/security/0,1000000189,39933618,00.htm">http://news.zdnet.co.uk/security/0,1000000189,39933618,00.htm</a><br />
December 12: <a href="http://garwarner.blogspot.com/2009/12/ongoing-visa-scam-drop-zeus-zbot.html">http://garwarner.blogspot.com/2009/12/ongoing-visa-scam-drop-zeus-zbot.html</a><br />
December 22: <a href="http://garwarner.blogspot.com/2009/12/donde-se-va-avalanche-bbva-y-united.html">http://garwarner.blogspot.com/2009/12/donde-se-va-avalanche-bbva-y-united.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.markmonitor.com/mmblog/avalanche-fast-flux-and-blended-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Expressions of Interest a Requirement for New gTLDs?</title>
		<link>http://www.markmonitor.com/mmblog/expressions-of-interest-a-requirement-for-new-gtlds/</link>
		<comments>http://www.markmonitor.com/mmblog/expressions-of-interest-a-requirement-for-new-gtlds/#comments</comments>
		<pubDate>Sat, 19 Dec 2009 00:29:46 +0000</pubDate>
		<dc:creator>Elisa Cooper</dc:creator>
				<category><![CDATA[Domains]]></category>
		<category><![CDATA[ICANN]]></category>
		<category><![CDATA[gTLDs]]></category>
		<category><![CDATA[icann]]></category>
		<category><![CDATA[top level domains]]></category>

		<guid isPermaLink="false">http://www.markmonitor.com/mmblog/?p=174</guid>
		<description><![CDATA[Today ICANN published a draft model for soliciting Expressions of Interest for new generic top-level domains. According to the model, parties interested in submitting applications to acquire new gTLDs will be required to provide basic information about the application and a deposit of $55,000 which can be used as a credit against the full application [...]]]></description>
			<content:encoded><![CDATA[<p>Today ICANN published a draft model for soliciting Expressions of Interest for new generic top-level domains. According to the model, parties interested in submitting applications to acquire new gTLDs will be required to provide basic information about the application and a deposit of $55,000 which can be used as a credit against the full application fee of $185,000.</p>
<p><strong><strong> </strong></strong>The model is a direct result of community recommendations and is available for public comments until January 27<sup>th</sup>, 2010. Public comments can be submitted at <a title="http://www.icann.org/en/public-comment/public-comment-201001.htm#draft-eoi" href="http://www.icann.org/en/public-comment/public-comment-201001.htm#draft-eoi">http://www.icann.org/en/public-comment/public-comment-201001.htm#draft-eoi</a>.</p>
<p>Based on public comments, the ICANN Board will convene to review feedback and determine possible next steps in the first quarter of 2010.</p>
<p>Highlights of the proposed plan include:</p>
<ul>
<li>Participation in the EOI is mandatory for eligibility to submit a gTLD application in the first round. Subsequent application rounds will be open to any eligible applicants.</li>
<li>A deposit of US$55,000 is required for the EOI, and will be used as a credit against the US$185,000 evaluation fee.</li>
<li>The deposit is refundable if the New gTLD Program does not launch within a specific time period. Details will be outlined in the final EOI model.</li>
<li>Participants are notified that there may be subsequent amendments to the Draft Applicant Guidebook. It is the intention to conclude many current open issues prior to initiation of the EOI process.</li>
<li>A fully executed communications campaign, intended to ensure global awareness about the EOI, will precede the opening of the process.</li>
<li>Participants will be required to provide specific information concerning the participating entity and the requested string.</li>
<li>The participant and string information will be made public.</li>
<li>The EOI launch is conditional on the conclusion of many of the outstanding issues, for example, issues concerning vertical separation and the IDN three-character string requirements. Solutions for these and other issues are expected to be included in the Draft Applicant Guidebook, version 4.</li>
</ul>
<p>The plan as outlined by ICANN raises a number of concerns. MarkMonitor intends to submit its own comments and encourages its clients to do the same.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.markmonitor.com/mmblog/expressions-of-interest-a-requirement-for-new-gtlds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Paid Search Ads Can Lead to Fake Goods</title>
		<link>http://www.markmonitor.com/mmblog/paid-search-ads-can-lead-to-fake-goods/</link>
		<comments>http://www.markmonitor.com/mmblog/paid-search-ads-can-lead-to-fake-goods/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 17:30:30 +0000</pubDate>
		<dc:creator>Mary Roach</dc:creator>
				<category><![CDATA[Brand Abuse]]></category>
		<category><![CDATA[Counterfeit]]></category>
		<category><![CDATA[Piracy]]></category>
		<category><![CDATA[counterfeits]]></category>
		<category><![CDATA[Paid Search]]></category>
		<category><![CDATA[search engines]]></category>

		<guid isPermaLink="false">http://www.markmonitor.com/mmblog/?p=167</guid>
		<description><![CDATA[MarkMonitor recently investigated to what extent popular product searches led to websites offering counterfeit and pirated goods via paid search ads. The research examined 20 of the top 1,000 product-related searches in 2008 and focused on paid search ads across the three major search engines – Google, Yahoo! and Bing. In total, 583 unique websites [...]]]></description>
			<content:encoded><![CDATA[<p>MarkMonitor recently investigated to what extent popular product searches led to websites offering counterfeit and pirated goods via paid search ads. The research examined 20 of the top 1,000 product-related searches in 2008 and focused on paid search ads across the three major search engines – Google, Yahoo! and Bing. In total, 583 unique websites (to which the ads pointed) were analyzed.</p>
<p>So, what did we find? Roughly 17% of the paid search ads for popular consumer products – such as designer handbags and shoes, music, movies, and hi-tech gadgets – led to sites likely offering counterfeit or pirated goods. This number gets even higher for certain categories, such as “designer handbags,” where an eye-opening 32% of the paid search ads led to sites appearing to sell fake handbags.</p>
<p>Another way to stir up more ads for counterfeit or pirated goods is by adding terms like “cheap,” “discount” or “wholesale” to a product name or category. Across all 20 product searches, for example, the share of paid search ads linking to sites selling counterfeits increased from 17% to 19% when these terms were added. In the designer handbag example, the share of paid search ads linking to suspect counterfeit sites jumped from 32% to 49%.</p>
<p>From these results, it is evident that counterfeiters have mastered the art of targeting buyers looking for unbelievable deals. As such, consumers need to be that much more vigilant if they’re seeking authentic products at good prices. Brand owners also need to be cognizant of the strategies employed by fraudsters and monitor not only for the use of their trademarks or product categories as keywords, but also in conjunction with terms signaling counterfeit or pirated products.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.markmonitor.com/mmblog/paid-search-ads-can-lead-to-fake-goods/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Open Phishing Season</title>
		<link>http://www.markmonitor.com/mmblog/open-phishing-season/</link>
		<comments>http://www.markmonitor.com/mmblog/open-phishing-season/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 19:14:30 +0000</pubDate>
		<dc:creator>Fred Felman</dc:creator>
				<category><![CDATA[Brand Abuse]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.markmonitor.com/mmblog/?p=151</guid>
		<description><![CDATA[For retailers and consumers, Cyber Monday marked the beginning of the online holiday shopping season. For cybercriminals, however, it marked the opening of their winter phishing season.
Here at MarkMonitor, we are currently seeing an uptick in cybercriminal activity targeting online retailers’ brands. Linked here is an example of a phish attack involving a well-known national retailer.
Clearly, [...]]]></description>
			<content:encoded><![CDATA[<p>For retailers and consumers, Cyber Monday marked the beginning of the online holiday shopping season. For cybercriminals, however, it marked the opening of their winter phishing season.</p>
<p>Here at MarkMonitor, we are currently seeing an uptick in cybercriminal activity targeting online retailers’ brands. <a title="Retail Phishing Example" href="http://www.markmonitor.com/images/blog-articles/att6016.jpg" target="_blank">Linked here</a> is an example of a phish attack involving a well-known national retailer.</p>
<p>Clearly, brand-based phish and malware attacks such as this one, possess great potential to harm consumers. They also pose a great risk to customer trust and loyalty in your brand. As a result, the range of advice which you can give to your customers to promote safe online holiday shopping is extensive. Customers should:</p>
<ul>
<li>confirm emails from retailers which request their action through links and attachments</li>
<li>confirm retailers who are highly ranked in search engine results, but are obscure or little known</li>
<li>be wary of website download files</li>
<li>ensure an https connection when entering financial credentials into a website</li>
<li>use temporary credit card numbers</li>
<li>use up-to-date anti-virus/malware software</li>
<li>check their financial statements regularly</li>
</ul>
<p>These are all useful recommendations. Unfortunately, the consumer attitude toward security, and the preventive actions they are willing to take, depends on the convenience of those actions. Consumers choose to shop online, after all, because they value convenience over other considerations, including concern about using their credit cards online.</p>
<p>When brand-based attacks harm consumers, they damage retailers’ brands, customer relationships, and the trust which customers have in Internet channels. As a result, these attacks present a very real business problem.</p>
<p>We recommend that online retailers adopt a proactive security stance toward phish and malware. This approach should include adopting preventive measures against brand hijackings and attacks in the planning stages, quickly detecting attacks which are underway, immediately responding with layered security, and analyzing attack data to refine security strategy and tactics. By educating customers and putting in place a proactive security strategy against phish and malware attacks, retailers can ensure a more enjoyable holiday season for customers and retailers alike.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.markmonitor.com/mmblog/open-phishing-season/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Open Enrollment = Open Season for Scammers</title>
		<link>http://www.markmonitor.com/mmblog/open-enrollment-open-season-for-scammers/</link>
		<comments>http://www.markmonitor.com/mmblog/open-enrollment-open-season-for-scammers/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 22:20:06 +0000</pubDate>
		<dc:creator>Mary Roach</dc:creator>
				<category><![CDATA[Brand Abuse]]></category>
		<category><![CDATA[Brandjacking]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cybersquatting]]></category>

		<guid isPermaLink="false">http://www.markmonitor.com/mmblog/?p=147</guid>
		<description><![CDATA[You have to give scammers credit, as they are a creative bunch.  While most of us think of the annual open enrollment period for employee benefits as a non-event, scammers see it as an opportunity.  
Just last month we’ve seen suspicious sites targeting employees of some of the largest corporations.  In one particular example, a cybersquatter [...]]]></description>
			<content:encoded><![CDATA[<p>You have to give scammers credit, as they are a creative bunch.  While most of us think of the annual open enrollment period for employee benefits as a non-event, scammers see it as an opportunity.  </p>
<p>Just last month we’ve seen suspicious sites targeting employees of some of the largest corporations.  In one particular example, a cybersquatter registered a domain name that closely mimicked the open enrollment benefits page of a Fortune 500 company. To illustrate using a generic company name, the squatted domain was ‘enrollcorporation.com,’ whereas the real company benefits page resided on the subdomain ‘enroll.corporation.com.’  The cybersquatter obviously was anticipating that employees would forget to type the period in the subdomain and land on its fake site. </p>
<p>The squatted site contained numerous links to benefits-related pay-per-click sites (see <a title="enrollcorporation.com" href="http://www.markmonitor.com/images/blog-articles/enroll-corporation-site.gif" target="_blank">screenshot</a>). While it may have been the intention of the scammer to generate incremental revenue from employees who clicked through on the links, it is also very possible that the scammer was planning on changing the content to something more malicious – such as a phishing site.  We often see scammers employ this tactic to avoid any immediate takedown action and to maximize their ploys.</p>
<p>Fortunately, the Fortune 500 company in this case was actively monitoring for potential attacks on its brand and caught and remedied the situation quickly.  (The squatted domain was recovered and now redirects to the company’s real benefits page.)  If the site had gone undetected, you can just imagine the havoc this would have created if the site morphed into a phishing site and even a minute percentage of the company’s tens of thousands of employees had unknowingly landed on the site and disclosed their personal credentials.  </p>
<p>So, what’s the takeaway from this?  While most brand owners know to monitor for online scams associated with new product launches or announcements, they also need to be extra vigilant around recurring company events – such as open enrollment periods, sales events, community events, etc.  If an event is predictable, it’s very easy for scammers to devise a socially engineered scam that that preys on customers and employees’ anticipation of the event.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.markmonitor.com/mmblog/open-enrollment-open-season-for-scammers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2009 Domain Name Year In Review</title>
		<link>http://www.markmonitor.com/mmblog/2009-domain-name-year-in-review/</link>
		<comments>http://www.markmonitor.com/mmblog/2009-domain-name-year-in-review/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 21:34:40 +0000</pubDate>
		<dc:creator>Elisa Cooper</dc:creator>
				<category><![CDATA[Domains]]></category>
		<category><![CDATA[ICANN]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Trademarks]]></category>
		<category><![CDATA[gTLDs]]></category>
		<category><![CDATA[icann]]></category>
		<category><![CDATA[registries]]></category>
		<category><![CDATA[top level domains]]></category>

		<guid isPermaLink="false">http://www.markmonitor.com/mmblog/?p=129</guid>
		<description><![CDATA[To say that it’s been quite a year in the world of domain names would be an understatement. From compromised ccTLD registries, to the delay of new gTLDs, some of the events of the past year have been surprising, while others could easily have been predicted.
 
Regardless of whether you could have seen these coming, please [...]]]></description>
			<content:encoded><![CDATA[<p>To say that it’s been quite a year in the world of domain names would be an understatement. From compromised ccTLD registries, to the delay of new gTLDs, some of the events of the past year have been surprising, while others could easily have been predicted.<br />
 <br />
Regardless of whether you could have seen these coming, please find below my list of 2009’s most important domain name events…at least, as I see them. </p>
<ul>
<li><strong>10</strong> &#8211; Toys.com is sold for a staggering $5.1 million dollars.  <a href="http://news.bbc.co.uk/2/hi/technology/7923433.stm">read more  </a></li>
<li><strong>9</strong> &#8211; With 115 million current gTLDs, registration growth slows from 11% in 2008 down to 6%   in 2009.</li>
<li><strong>8</strong> &#8211; Oversee.net and SnapNames.com admit that a company executive acted as a shill bidder in the auctions of thousands of domains over a four-year period.</li>
<li><strong>7</strong> &#8211; UDRP marks its 10-year anniversary with more than 16,000 disputes and more than 10,000 domain name transfers.  <a href="http://www.markmonitor.com/mmblog/ten-years-of-udrp/">read more </a></li>
<li><strong>6 </strong>- Germany (.DE) and .BIZ announce the release of one- and two-character domain name registrations.</li>
<li><strong>5</strong> &#8211; Mexico (.MX), Tunisia (.TN) and Cameroon (.CM) announce the release of second-level domain registrations and the European Union (.EU), Bulgaria (.BG) Singapore (.SG) and .NAME announce the release of Internationalized Domain Names (IDNs).</li>
<li><strong>4</strong> &#8211; Corporate registration trends move away from the practice of registering large numbers of defensive domains as more companies adopt aggressive monitoring and policing policies.  <a href="http://www.markmonitor.com/mmblog/corporate-domain-registration-practices-in-light-of-new-gtlds/">read more </a></li>
<li><strong>3</strong> &#8211; Both registries and registrars are exploited by hackers as SQL vulnerabilities are uncovered.  <a href="http://www.markmonitor.com/mmblog/domain-name-registries-must-do-more-to-protect-highly-trafficked-domains/">read more  </a></li>
<li><strong>2</strong> &#8211; ICANN’s IDN Fast Track process is approved and applications for Top-Level Internationalized Country Codes are accepted.  <a href="http://www.markmonitor.com/mmblog/a-sigh-of-relief-for-brand-owners-not-so-fast/">read more</a> </li>
<li><strong>1</strong> &#8211; The launch of ICANN’s new gTLD program is delayed as commitments to addressing and resolving overarching issues related to trademark protection, stability and security, malicious conduct and economic demand are made.  <a href="http://www.markmonitor.com/mmblog/icann-defends-plans-for-new-tlds-but-launch-date-to-likely-slip/">read more</a> </li>
</ul>
<p>So what can we expect in 2010?<br />
 <br />
While I don’t have a crystal ball, I expect to see the launch of a number of the Top-Level Internationalized Country Code extensions in the first half of next year. Corporations should begin planning now by identifying non-Latin trademark portfolios so that they are prepared as Sunrise periods begin.<br />
 <br />
I also anticipate that we will see a final version of the new gTLD Guidebook by the end of next year. I would encourage companies to actively participate with ICANN in relation to the new gTLD process and in particular with the development of rights protection mechanisms. Again, although there is a delay in the process, companies should continue to move down a path of due diligence to determine the right approach – whether it’s to focus solely on defensive measures or to apply for a custom TLD.</p>
<p>We’ll continue to see liberalizations of ccTLDs. However, we may also start seeing the introduction of new, more stringent requirements on ccTLDs which were once unrestricted or minimally restricted in an effort to reduce criminal activity.<br />
 <br />
Although I am hopeful that we’ve seen the last of these registry and registrar security breaches, I am sure that we’ll continue to see the efforts of hackers rearing their ugly heads.<br />
 <br />
While 2009 was certainly a year to remember, I think that 2010 will bring even bigger changes and bigger challenges.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.markmonitor.com/mmblog/2009-domain-name-year-in-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Sigh of Relief for Brand Owners…Not So .Fast</title>
		<link>http://www.markmonitor.com/mmblog/a-sigh-of-relief-for-brand-owners-not-so-fast/</link>
		<comments>http://www.markmonitor.com/mmblog/a-sigh-of-relief-for-brand-owners-not-so-fast/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 19:14:20 +0000</pubDate>
		<dc:creator>Elisa Cooper</dc:creator>
				<category><![CDATA[ICANN]]></category>
		<category><![CDATA[Domains]]></category>
		<category><![CDATA[icann]]></category>
		<category><![CDATA[IDN]]></category>
		<category><![CDATA[New gTLDs]]></category>
		<category><![CDATA[top level domains]]></category>
		<category><![CDATA[trademark]]></category>

		<guid isPermaLink="false">http://www.markmonitor.com/mmblog/?p=120</guid>
		<description><![CDATA[All indications from the ICANN meetings in Seoul are that significant delays for the release of new gTLDs (Generic Top Level Domains) are expected.
According to Rod Beckstrom, ICANN’s CEO, new gTLDs will be made available when, “we&#8217;ve adequately addressed the important issues that are on the table.” These important issues include efforts to address malicious [...]]]></description>
			<content:encoded><![CDATA[<p>All indications from the ICANN meetings in Seoul are that significant delays for the release of new gTLDs (Generic Top Level Domains) are expected.</p>
<p>According to Rod Beckstrom, ICANN’s CEO, new gTLDs will be made available when, “we&#8217;ve adequately addressed the important issues that are on the table.” These important issues include efforts to address malicious conduct, root scaling, economic analysis, trademark protections, and vertical separation as related to the new gTLDs.</p>
<p>Consequently, no timelines for the launch of new gTLDs have been released. ICANN had most recently stated that the application period would begin in the second half of 2010.</p>
<p>While companies who have been building business plans around the launch of new gTLDs are up in arms, brand owners should take comfort in knowing that additional work will be completed to ensure that adequate rights protection mechanisms are implemented prior to the launch of new gTLDs.</p>
<p>However, while it looks like the gTLD Express is slowing down a bit so that adequate protections can be incorporated into the process, the IDN ccTLD Train (Internationalized Country Code Top Level Domain Names) is full steam ahead and nearing its destination. After years of research, development and market demand, starting on November 16th, ccTLD registry managers will be allowed to submit applications to operate TLDs in native character sets representing their respective country or territory names. To date, 25 countries including China, Japan and the Russian Federation have expressed interest in participating.</p>
<p>Although brand owners may not have to worry about the launch of new gTLDs next year, understanding how, where, and what to register in these new ccTLD IDNs will present a host of new issues – many of which have been overshadowed until now by the anticipated launch of the new gTLDs.</p>
<p>As with similar types of launches in the past, many of these ccTLD registries may allow for special “Sunrise” and “Grandfather” periods so that owners of trademarks and existing IDNs are given priority over others to register exact matches in the new offerings. While registration periods for these new IDN ccTLDs will likely not occur before the second half of next year, brand owners should consider preparing now by reviewing international trademark portfolio holdings and identifying important brands that should be promoted and protected.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.markmonitor.com/mmblog/a-sigh-of-relief-for-brand-owners-not-so-fast/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
